Report - vbc.exe

CryptBot PE32 PE File
ScreenShot
Created 2021.07.30 15:06 Machine s1_win7_x6401
Filename vbc.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
7
Behavior Score
2.2
ZERO API file : malware
VT API (file) 21 detected (AIDetect, malware1, malicious, high confidence, Artemis, Save, VBKrypt, Eldorado, EPVN, Vebzenpak, agdc, Wacapew, GenAsa, 5wnZ8amFQDs, Static AI, Malicious PE, Unsafe, Score, ZevbaF, im0@ayhPhYaG, confidence, HwMA4iQA)
md5 c85ee9fe0a4d346432307651cb4357a1
sha256 b9677a659f448378a905926188cf5bb05937016d65ad16cf1210817e909324f0
ssdeep 1536:pfm9nt/fJxs+BBBBBBBBBBBNQ6pAqnxoJpqQXRm8WSPHPKh22JCFEHmqpxGoEoQO:Knt/RxpYqnxcpqH8n5qaC/xtTys/Dn
imphash 73b8cec9d966d2100b9daa6840b6cd9b
impfuzzy 12:nTBROfVy/dqWSk9b6T1n9fOJTSFN/rL6lDee4:n9AfVyQlTT/ESFNI6
  Network IP location

Signature (5cnts)

Level Description
warning File has been identified by 21 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks amount of memory in system

Rules (3cnts)

Level Name Description Collection
danger CryptBot_IN CryptBot binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

MSVBVM60.DLL
 0x401000 _CIcos
 0x401004 _adj_fptan
 0x401008 _adj_fdiv_m64
 0x40100c _adj_fprem1
 0x401010 __vbaHresultCheckObj
 0x401014 _adj_fdiv_m32
 0x401018 _adj_fdiv_m16i
 0x40101c _adj_fdivr_m16i
 0x401020 _CIsin
 0x401024 __vbaChkstk
 0x401028 EVENT_SINK_AddRef
 0x40102c _adj_fpatan
 0x401030 EVENT_SINK_Release
 0x401034 _CIsqrt
 0x401038 EVENT_SINK_QueryInterface
 0x40103c __vbaExceptHandler
 0x401040 _adj_fprem
 0x401044 _adj_fdivr_m64
 0x401048 __vbaFPException
 0x40104c _CIlog
 0x401050 _adj_fdiv_m32i
 0x401054 _adj_fdivr_m32i
 0x401058 _adj_fdivr_m32
 0x40105c _adj_fdiv_r
 0x401060 None
 0x401064 _CIatan
 0x401068 _allmul
 0x40106c _CItan
 0x401070 _CIexp

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure