s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-17a364d3c81945062507876f302ba37b119c72f5603b8f6cac4de6a1009becbf high

📛 Threat Title

Unknown: 17a364d3c81945062507876f302ba37b119c72f5603b8f6cac4de6a1009becbf.vbs

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: unknown. Size: 2791610 bytes. Tags: 45-133-174-90. Reporter: JAMESWT_WT. First seen: 2026-05-14 07:33:06.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 17a364d3c81945062507876f302ba37b119c72f5603b8f6cac4de6a1009becbf VT 14 / 75 1 feed

IOC database

Type
hash_sha256
Value
17a364d3c81945062507876f302ba37b119c72f5603b8f6cac4de6a1009becbf
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 14 of 75 VirusTotal vendors

VendorVerdictDetection
Antiy-AVL malicious Trojan/Script.Agent
Avira malicious TR/Malware
Cynet malicious Malicious (score: 99)
Fortinet malicious VBS/Agent.QCG!tr
Ikarus malicious Trojan-Downloader.JS.Func0
Lionic malicious Trojan.CSV.Generic.4!c
McAfeeD malicious Trojan:Script/Remcos.AW!1
Microsoft malicious Trojan:Win32/Ravartar!rfn
MicroWorld-eScan malicious Trojan.Generic.39954128
Symantec malicious Trojan.Gen.NPE
Tencent malicious Win32.Trojan-Downloader.Downloader.Njgl
Varist malicious VBS/Agent.CRE
VirIT malicious Trojan.VBS.Agent.JQO
Xcitium malicious Malware@#198u7nfc7fle2

Details From VirusTotal

Basic Properties
MD5230febab9e7ac2c16a582bce626d1c54
SHA-18c2d492e10f05d8c061cb5863f28559ac639dc80
SHA-25617a364d3c81945062507876f302ba37b119c72f5603b8f6cac4de6a1009becbf
SSDEEP96:pEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEL:C+/XS+
TLSHT111D5C5B7B214A3E85D44FB1AD44EFCC0CA14AB54F933642EE9FC0D546DC471E6CA18AA
File typeCSV
File type tagcsv
File extensioncsv
MagicCSV text
File size2.7 MB
History
First seen on VirusTotal2026-05-12 11:44 UTC
Last submission2026-05-12 11:44 UTC
Last analysis2026-05-20 09:01 UTC
Last modified on VirusTotal2026-05-20 11:09 UTC
Known Names
  • 17a364d3c81945062507876f302ba37b119c72f5603b8f6cac4de6a1009becbf.vbs
  • bache.vbs
hash_md5 230febab9e7ac2c16a582bce626d1c54 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/230febab9e7ac2c16a582bce626d1c54
2 feeds

IOC database

Type
hash_md5
Value
230febab9e7ac2c16a582bce626d1c54
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/230febab9e7ac2c16a582bce626d1c54

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: unknown. Size: 2791610 bytes. Tags: 45-133-174-90. Reporter: JAMESWT_WT. First seen: 2026-05-14 07:33:06.

Remediations (10)

  • web:forums.tomshardware.com

    Question Sporadic BSOD screens appear shortly after "Virtualization-based security... is enabled due to VBS registry configuration" appears in Event Viewer ?

  • web:knowledge.broadcom.com

    As a general best practice, we recommend you test the mitigation with your applications prior to deploying in production environments. Nested virtualization and Microsoft Virtualization-Based Security (VBS): Our testing showed a significant performance impact when applied to nested virtualized environments on ESXi.

  • web:learn.microsoft.com

    If compatibility issues occur, see Troubleshooting for remediation steps. Memory integrity is a Virtualization-based security (VBS) feature available in Windows. Memory integrity and VBS improve the threat model of Windows and provide stronger protections against malware trying to exploit the Windows kernel.

  • web:superuser.com

    Does the Microsoft update for BlackLotus mitigation SKUSiPolicy.p7b require Memory Integrity to be on and working in the Security Center?

  • web:support.microsoft.com

    This mitigation is enabled by default. On these systems, the VBS-protected encryption keys are bound to the default-enabled boot session VBS CI policy and will only unseal if the matching CI policy version is being enforced.

  • web:windowsforum.com

    In an important update released just recently, Microsoft has addressed the critical Virtualization-Based Security (VBS) vulnerability dubbed CVE-2024-21302, a flaw that could potentially allow attackers to downgrade modern Windows operating systems without user awareness. This significant security issue was publicly disclosed on August 14, 2024, coinciding with Microsoft's monthly Patch ...

  • web:www.17track.net

    ALL IN ONE GLOBAL PACKAGE TRACKING Track global packages, eCommerce orders, and air cargo from 3300+ carriers and 190+ airlines, covering China and beyond. Start tracking USPS, DHL, FedEx, Canada Post, Deutsche Post, AliExpress, eBay, etc across web, mobile apps, and Shopify stores with 17TRACK!

  • web:www.elevenforum.com

    Summary Microsoft was made aware of a vulnerability in Windows that allows an attacker with administrator privileges to replace updated Windows system files that have older versions, opening the door for an attacker to reintroduce vulnerabilities to Virtualization-based security (VBS). Rollback of these binaries might allow an attacker to circumvent VBS security features and exfiltrate data ...

  • web:www.forbes.com

    WhatsApp users need to pay close attention following the latest attack warning from Microsoft. Here's what you need to know.

  • web:www.unknowncheats.me

    I NEED HELP! PLEASE! Winver: WINDOWS 11 22H2 First time testing HVCI/VBS ON, all is ON, impost mode full. I'm using my own method, not a vulnerable dr

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.