_vbhjllk.exe

Click Start Media

The file _vbhjllk.exe has been detected as malware by 1 anti-virus scanner. The file has been seen being downloaded from filecdn2.vlc.cc.
Publisher:
Click Start Media  (signed and verified)

Product:
Click Start Media

Version:
15.7.1.8591

MD5:
e3bde031ffcfc1c71849a96ae9cb21c6

SHA-1:
c000b0780b87f5b10d78f299c09531b6b61c17db

SHA-256:
9ce1adc798306a180941fc23032fd6d103d85e16e1f178d7a9fe9a213402a33b

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/24/2024 6:18:28 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
15.12.1.23

File size:
1.2 MB (1,235,752 bytes)

Product version:
15.7.1.8591

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\_vbhjllk.exe.part

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
11/6/2015 6:06:38 PM

Valid to:
11/6/2016 6:06:38 PM

Subject:
CN=Click Start Media, O=Click Start Media, L=Oakland, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
008B1BC042761E6262

File PE Metadata
Compilation timestamp:
11/1/2014 8:20:03 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:ENkWzXQVT/kYeDR+n2vNzqQ9ZsPoS388YaRr1oIylQuRohPdQocgb531SR:icV1el+n2v78PbYir53Pdxhl1U

Entry address:
0x1DBB

Entry point:
E8, C0, C0, 00, 00, E9, E4, B8, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, 3C, 51, 41, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 56, 8B, 74, 24, 08, 68, 00, 01, 00, 00, 6A, 01, 56, E8, 6C, B8, 00, 00, 33, C0, 89, 46, 21, 89, 46, 25, 89, 46, 29, 89, 46, 2D, 89, 46, 31, 89, 46, 35, 6A, 41, 89, 46, 39, 8D, 46, 3E, 6A, 00, 50, E8, 48, B8, 00, 00, 68, 00, 01, 00, 00, C6, 46, 09, 03, C6, 46, 20, 03, C6, 46, 0D, 02, 8B, 74, 24, 28, 68, FF, 00, 00, 00, 56, E8, 28, B8, 00, 00, B0, 0A, 88, 46, 41...
 
[+]

Entropy:
7.9813  (probably packed)

Code size:
54 KB (55,296 bytes)

The file _vbhjllk.exe has been seen being distributed by the following URL.

Remove _vbhjllk.exe - Powered by Reason Core Security