Created 2021.04.28 09:57 Machine s1_win7_x6402
Filename vbc.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
Behavior Score
ZERO API file : malware
VT API (file) 48 detected (AIDetect, malware1, malicious, high confidence, GenericKD, GenericKDZ, Unsafe, Save, Ranumbot, ZexaF, zuX@aC7f9gkO, Kryptik, Eldorado, Attribute, HighConfidence, HKOR, CrypterX, Noon, Obscure, CLOUD, mrwhy@0, Lockbit, R + Mal, GandCrypt, Static AI, Malicious PE, hrogz, ai score=100, kcloud, Glupteba, 1L1P37C, score, CoinMiner, R417847, R002C0RDQ21, Auto, HKPA, GdSda, confidence, 100%)
md5 cd4a716b2886b9d6609b4e00c97964f0
sha256 91fa1797421a3393289ae3892d128158ca3a16efd453be49e0c38d5891deefba
ssdeep 12288:cm9enLXQpjT7iBQks1IftmqxL5v06QtHpa:xMXQlyBQJ7Kv06QtJa
imphash 7992f385465c3a91784159b680857f5e
impfuzzy 48:QXKdBUO+0p/Bbnkd7qXpjEBOCfGQ0cvl8uucjYNZehKp6l:QXKdBV+0weZjEbfGQ0cvlccjweK0
Level Description
danger File has been identified by 48 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
watch Tries to unhook Windows functions monitored by Cuckoo
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer
info This executable has a PDB path

Level Name Description Collection
danger Trojan_Win32_Glupteba_1_Zero Trojan Win32 Glupteba binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check Signature Zero binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info HasDebugData DebugData Check binaries (upload)
info HasOverlay Overlay Check binaries (upload)
info IsPacked Entropy Check binaries (upload)
info IsWindowsGUI (no description) binaries (upload)
info win_files_operation Affect private profile binaries (upload)
info win_mutex Create or check mutex binaries (upload)

IAT(Import Address Table) Library

