VacuumTube.exe threat report

MD5 6a9163e4df7a9c94d1b3b385c46ca8bd
Latest seen 2025-12-29 23:01:59 (5 months ago)
First seen 2025-12-29 23:01:59 (5 months ago)
Size 194 MB
Publisher shy
Product VacuumTube

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Spy.InfoStealer. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Spy.InfoStealer
Recommended action
Scan and remove
Last analysis
2025-12-29 23:01:59 (5 months ago)
File hash
6a9163e4df7a9c94d1b3b385c46ca8bd
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Spy.InfoStealer.

Timeline

First seen 2025-12-29 23:01:59 (5 months ago); latest analysis 2025-12-29 23:01:59 (5 months ago).

Publisher context

Company metadata: shy. Product metadata: VacuumTube.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

VacuumTube.exe is a Windows file recorded in the ThreatInfo database. It is associated with VacuumTube. The reported company name is shy. The current detection status is Spy.InfoStealer, based on the latest analysis from 2025-12-29 23:01:59 (5 months ago).

If VacuumTube.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Spy.InfoStealer.

Product Name: VacuumTube
Company Name: shy
MD5: 6a9163e4df7a9c94d1b3b385c46ca8bd
Size: 194 MB
First Published: 2025-12-29 23:01:59 (5 months ago)
Latest Published: 2025-12-29 23:01:59 (5 months ago)
Status: Spy.InfoStealer (on last analysis)
Analysis Date: 2025-12-29 23:01:59 (5 months ago)
VacuumTube.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%sysdrive%\portable

ThreatInfo has observed VacuumTube.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Germany with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for VacuumTube.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

VacuumTube.exe is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x04c1eda0

PE Sections:

Name Size of data MD5
.text 163837952 2ef152bdffa44a2a61a49e32ba33a931
.rdata 32975360 0483aac3e6013739be9403c59ce70af3
.data 831488 1225b737dcb62a5f468ebd7b177e0629
.pdata 4955136 8b5c91ad960d879d0a88ca5306f148d4
.fptable 512 bf619eac0cdf3f68d496ea9344137e8b
.rodata 4608 c642bc1527b5873b6dbf56c4a87d20cb
.tls 2048 fd0f553aa73e49c4ee9d4e1e39ef5175
CPADinfo 512 60d3ea61d541c9be2e845d2787fb9574
LZMADEC 4608 05e9eab8428a551a281ab278073669fa
_RDATA 512 a8e5f2d07df92b39aece7254accda718
malloc_h 512 f4e6c5fa42506c7c5786bea452abd6cc
prot 512 bf619eac0cdf3f68d496ea9344137e8b
.rsrc 113664 8549eed950879b49470af437497f1aa1
.reloc 1038848 29cd4beca71bd3d35e01a57468ab63dc

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: