AVOX SYBIL.vst3 threat report

MD5 cbcc7ef2f4e6c04112f3addcbce59ec0
Latest seen 2023-04-16 23:25:45 (3 years ago)
First seen 2023-04-16 23:25:45 (3 years ago)
Size 13 MB
Publisher Antares
Product Sybil

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Trojan.Heur!. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Trojan.Heur!
Recommended action
Scan and remove
Last analysis
2023-04-16 23:25:45 (3 years ago)
File hash
cbcc7ef2f4e6c04112f3addcbce59ec0
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Trojan.Heur!.

Timeline

First seen 2023-04-16 23:25:45 (3 years ago); latest analysis 2023-04-16 23:25:45 (3 years ago).

Publisher context

Company metadata: Antares. Product metadata: Sybil.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

AVOX SYBIL.vst3 is a Windows file recorded in the ThreatInfo database. It is associated with Sybil. The reported company name is Antares. The current detection status is Trojan.Heur!, based on the latest analysis from 2023-04-16 23:25:45 (3 years ago).

If AVOX SYBIL.vst3 appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Heur!.

Product Name: Sybil
Company Name: Antares
MD5: cbcc7ef2f4e6c04112f3addcbce59ec0
Size: 13 MB
First Published: 2023-04-16 23:25:45 (3 years ago)
Latest Published: 2023-04-16 23:25:45 (3 years ago)
Status: Trojan.Heur! (on last analysis)
Analysis Date: 2023-04-16 23:25:45 (3 years ago)
AVOX SYBIL.vst3 detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%commondir%\vst3

ThreatInfo has observed AVOX SYBIL.vst3 in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 100.0%

The most common operating system signal for AVOX SYBIL.vst3 is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

AVOX SYBIL.vst3 is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000180000000
Entry Address: 0x00b95600

PE Sections:

Name Size of data MD5
__wibu00 2968576 2b9e8b358d17dad35f2110dea68b0bfd
__wibu01 2048 560fd452d66332f557480dd18359589d
__wibu02 8323072 05a06f3e9f2f2b8102401c34586e4c0a
__wibu03 81920 7eb222c6a5482dc8734aac21c0da650a
__wibu04 146944 60c554860d3c75055120bb8871febd57
__wibu05 512 9a1f656c721c95bc5159449037c7b7c0
.rsrc 1536 9f36d4b0fe2830bbd5525595e1ba6404
__wibu06 35328 e9adcee5f29bd2ef079a0df7109f58d3
__wibu07 1978368 c93d79c6a15b51590f91877c8df98efd
__wibu08 68608 095c8026ffcb2722775fcd9a82f505ad
__wibu09 10752 b1ae8dec8e784f65ce2dd655859dbbc4
__wibu0a 512 8bab545e48dd16eaf46ab16c5f4263a4
__wibu0b 62464 bdea81d8b4d8b956614eb1a530fa73fe
__wibu0c 246784 11c39c7c22748d63af343b144ab7953f

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: