Report - vbc.exe

Generic Malware PE32 PE File
ScreenShot
Created 2021.07.21 10:36 Machine s1_win7_x6401
Filename vbc.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
6
Behavior Score
2.2
ZERO API file : malware
VT API (file) 31 detected (AIDetect, malware1, Malicious, high confidence, GenericKD, Unsafe, Save, ZevbaF, hm0@a8nAdfhG, LQKY, GenKryptik, FHRK, VEBZENPAK, USMANGK21, FileRepMalware, Static AI, Malicious PE, kcloud, Wacatac, score, ai score=99, susgen, confidence)
md5 c8feb9d53b567cd1bfb0e59cf7d26bc2
sha256 642a0df15a9b8e3124d638e755f0bdbacd0d1c3ff01b59b36213a190a5e5645a
ssdeep 1536:/bjX1R6rHR+Gz6YsFdVfKcLe0NMDfuoFVHYGokXYtvcOOfgrJZ+R6rHJXdb:jjX1yH1HErzwmoFtoZtkJgrCyHJXd
imphash 5c4d602843f54570889588b32f7af650
impfuzzy 12:nTBROfsdqWSk9b6T1n9fOJTSFN/rL6lDee4:n9Af1lTT/ESFNI6
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 31 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice The binary likely contains encrypted or compressed data indicative of a packer

Rules (3cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

MSVBVM60.DLL
 0x401000 _CIcos
 0x401004 _adj_fptan
 0x401008 _adj_fdiv_m64
 0x40100c _adj_fprem1
 0x401010 _adj_fdiv_m32
 0x401014 _adj_fdiv_m16i
 0x401018 _adj_fdivr_m16i
 0x40101c _CIsin
 0x401020 __vbaChkstk
 0x401024 EVENT_SINK_AddRef
 0x401028 _adj_fpatan
 0x40102c EVENT_SINK_Release
 0x401030 _CIsqrt
 0x401034 EVENT_SINK_QueryInterface
 0x401038 __vbaExceptHandler
 0x40103c _adj_fprem
 0x401040 _adj_fdivr_m64
 0x401044 __vbaFPException
 0x401048 _CIlog
 0x40104c _adj_fdiv_m32i
 0x401050 _adj_fdivr_m32i
 0x401054 _adj_fdivr_m32
 0x401058 _adj_fdiv_r
 0x40105c None
 0x401060 _CIatan
 0x401064 _allmul
 0x401068 _CItan
 0x40106c _CIexp

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure