Summary | ZeroBOX

vbc.exe

PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6402 Aug. 4, 2021, 9:23 a.m. Aug. 4, 2021, 9:37 a.m.
Size 177.3KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ecc19a6e75196aba87b243737d5fd361
SHA256 13fdc7878c5cdbdb1853fbfd15558014a9c64d7d45fde52088e61c6b8c0beae7
CRC32 0A5204CF
ssdeep 3072:eZIIeZuHs6psb4gdiJ0h5mnmwDCjpsZIDyIP:aia5pCqC5mnmwvMyIP
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

name RT_VERSION language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_TRADITIONAL offset 0x00025270 size 0x000001e8
section {u'size_of_data': u'0x00022000', u'virtual_address': u'0x00001000', u'entropy': 7.008381545069816, u'name': u'.text', u'virtual_size': u'0x0002144c'} entropy 7.00838154507 description A section with a high entropy has been found
entropy 0.809523809524 description Overall entropy of this PE file is high
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
FireEye Generic.mg.ecc19a6e75196aba
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
Cybereason malicious.23c100
BitDefenderTheta Gen:NN.ZevbaF.34058.lm1@aiKRcqkb
Symantec Packed.Generic.575
APEX Malicious
Kaspersky UDS:Trojan.Win32.Mucc
Microsoft Trojan:Win32/Tnega!ml
Yandex Trojan.GenAsa!6IHGaceYThA
Ikarus Trojan.Inject
eGambit Unsafe.AI_Score_89%
MaxSecure Trojan.Malware.300983.susgen