Our call: Is hvnc-client (1).exe safe?Malicious
Unsigned executable named 'hvnc-client' flagged by tier-1 engine Symantec; HVNC is a known remote-access trojan.
- 3 of 75 antivirus engines flagged the file, including Bkav and CrowdStrike.Observed · Antivirus analysis
- The hash has been submitted 1 time from 1 source.Derived · Saved report facts
861b9d48c0f408ad5f…082e781af1Recommended next actions
Before running
Do not run it. Delete this file from the device, then empty the Recycle Bin or Trash.
If you already ran it
Disconnect from the internet, start a full or offline antivirus scan, then secure important accounts from a clean device.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete3 of 75 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
3 of 75 antivirus engines flagged the file, including Bkav and CrowdStrike.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The file is named 'hvnc-client (1).exe' and flagged by Symantec (tier-1) as 'ML.Attribute.HighConfidence'. HVNC (Hidden VNC) is a known remote-access trojan used in targeted attacks. The combination of the malicious filename, tier-1 detection, unsigned status, and rare-new prevalence indicates a likely malicious payload.
The filename 'hvnc-client' is a strong adversarial signal — HVNC tools are remote-access trojans actively deployed in attacks. Symantec, a tier-1 engine, flagged the sample with a machine-learning confidence label. While the detection is generic rather than a named family signature, it is not a low-trust-only false positive (tier1Malicious=1, onlyLowTrustFlagging=false). The file is unsigned, has zero reputation, and is rare-new (1 submission, 0 days old), with no signer history to provide legitimacy. PE analysis shows normal entropy and no packing, consistent with a straightforward compiled RAT. The absence of sandbox data and external intel hits is expected for a newly submitted file and does not override the filename + tier-1 detection combination.
What We Detected
The file is named 'hvnc-client (1).exe' and flagged by Symantec (tier-1 antivirus engine) as 'ML.Attribute.HighConfidence'. HVNC (Hidden VNC) is a known remote-access trojan tool used in targeted attacks to gain unauthorized remote control of compromised systems.
Threat Behavior
HVNC tools typically establish a hidden remote desktop session, allowing attackers to interact with the victim's desktop without visible indicators. The file is unsigned and has zero reputation, with no legitimate publisher backing. It is rare and newly submitted (1 submission, 0 days old), suggesting either a fresh variant or a newly discovered sample. PE analysis shows normal entropy and no packing, consistent with a straightforward compiled executable.
What To Do Now
Do not execute this file. If it was downloaded or received unexpectedly, delete it immediately. If it has already been executed, isolate the affected system from the network and perform a full malware scan. Review system logs for unauthorized remote access attempts or suspicious network connections. Consider consulting your security team or a professional incident responder if compromise is suspected.
Where this verdict could be wrong5 caveats
- Symantec's detection is a generic ML-based label ('ML.Attribute.HighConfidence') rather than a named family signature, which could indicate heuristic overfitting rather than confirmed malware.
- Only 1 tier-1 engine flagged the sample; a stronger consensus (≥3 tier-1 engines) would be more definitive.
- No sandbox execution data, no contacted malicious hosts, no dropped children — runtime behaviour is unknown, though this is expected for a newly submitted file.
- No external intel hits (YARA, CIRCL, MalwareBazaar) — could reflect limited research coverage of this specific HVNC variant rather than absence of malice.
- If the filename is user-controlled or the file was renamed by the submitter, the 'hvnc-client' label may not reflect the actual payload; however, the tier-1 detection stands independently.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- PE entropy normal (2.15–6.29 across sections) — not heavily obfuscated
- No packing detected — straightforward compiled executable
- No high-entropy code sections — consistent with standard compilation
- Filename explicitly names 'hvnc-client' — a known remote-access trojan tool
- Tier-1 engine (Symantec) flagged the sample as malicious
- File is unsigned with zero reputation and no signer history
- Rare-new prevalence (1 submission, 0 days old) — likely a fresh or newly discovered variant
- No legitimate publisher or trusted certificate backing the executable
Treat this file as malicious and do not execute. If encountered in your environment, isolate the affected system, delete the file, and perform a full malware scan. Review system logs for unauthorized remote access or suspicious network activity.
Behavior
Plain-English impact first, then the observed runtime evidence.
Threat context
How remote-access malware works
This opens a secret 'back door' into your computer. Once it's running, an attacker can control your PC from anywhere — see your screen, read your files, switch on your webcam, install more malware, or use your machine to attack others.
Bottom line:It's built to stay hidden and keep that connection open for as long as possible.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
Category: rat
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
3 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. 3 antivirus detections make that low prevalence materially relevant, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- hvnc-client (1).exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 1.1 MB
- Last analyzed
- Jun 12, 2026, 7:50 PM UTC
861b9d48c0f408ad5f6a3e1da68a1a3795472e311e01efd31b9eb2082e781af1Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
Don't run this file. Delete this file from the device, then empty the Recycle Bin or Trash.
If you already ran it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
If you typed any passwords while it was open, change them from a device you trust.
Get a fresh copy from the developer's official site or an official app store.