Summary | ZeroBOX

vbc.exe

Malicious Library OS Processor Check PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6402 Sept. 3, 2021, 9:11 a.m. Sept. 3, 2021, 9:21 a.m.
Size 211.5KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 2f66472775a1d52a7aa5c54e4f50160b
SHA256 bf31b12fa0ba232eb07eed27f004f9c34695ecc3eb4a5270b89f8abb519a059b
CRC32 58A2AB61
ssdeep 6144:DgEfD/i1lkemVTt+ASZNaEz2lsS+QwyqquVy:pmet+fNi+0+
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
img.neko.airforce 167.172.239.151
IP Address Status Action
164.124.101.2 Active Moloch
167.172.239.151 Active Moloch

section .gfids
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 564
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00433000
process_handle: 0xffffffff
1 0 0
section {u'size_of_data': u'0x00001c00', u'virtual_address': u'0x00036000', u'entropy': 7.479997875798977, u'name': u'.rsrc', u'virtual_size': u'0x00001a88'} entropy 7.4799978758 description A section with a high entropy has been found
Lionic Trojan.Multi.Generic.4!c
FireEye Generic.mg.2f66472775a1d52a
Cylance Unsafe
CrowdStrike win/malicious_confidence_100% (W)
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Win32/TrojanDownloader.Agent.FVK
APEX Malicious
Paloalto generic.ml
Kaspersky UDS:DangerousObject.Multi.Generic
Sophos Mal/Generic-R
McAfee-GW-Edition BehavesLike.Win32.Generic.dm
Jiangmin AdWare.Generic.tpvr
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Microsoft Trojan:Win32/Formbook!ml
Cynet Malicious (score: 100)
McAfee RDN/Generic.dx
VBA32 suspected of Trojan.Downloader.gen
Malwarebytes Malware.AI.1615674986
SentinelOne Static AI - Suspicious PE
eGambit Unsafe.AI_Score_99%
BitDefenderTheta Gen:NN.ZexaF.34126.nuW@aixJHJli
MaxSecure Trojan.Malware.300983.susgen