Report - vbc.exe

PE File PE32
ScreenShot
Created 2021.08.04 10:29 Machine s1_win7_x6403
Filename vbc.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
6
Behavior Score
1.4
ZERO API file : malware
VT API (file) 15 detected (AIDetect, malware1, malicious, high confidence, Unsafe, Save, ZevbaF, lm1@aiKRcqkb, Mucc, Tnega, GenAsa, 6IHGaceYThA, Score, susgen)
md5 ecc19a6e75196aba87b243737d5fd361
sha256 13fdc7878c5cdbdb1853fbfd15558014a9c64d7d45fde52088e61c6b8c0beae7
ssdeep 3072:eZIIeZuHs6psb4gdiJ0h5mnmwDCjpsZIDyIP:aia5pCqC5mnmwvMyIP
imphash 1c73a47427cc41d9442154c68931bd16
impfuzzy 12:nTBROfsdfeWSk9b6T1n9fOJTSFNw1HO5rL6lDee4:n9AfuelTT/ESFNwf6
  Network IP location

Signature (3cnts)

Level Description
watch File has been identified by 15 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
notice The binary likely contains encrypted or compressed data indicative of a packer

Rules (2cnts)

Level Name Description Collection
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

MSVBVM60.DLL
 0x401000 _CIcos
 0x401004 _adj_fptan
 0x401008 _adj_fdiv_m64
 0x40100c _adj_fprem1
 0x401010 _adj_fdiv_m32
 0x401014 _adj_fdiv_m16i
 0x401018 _adj_fdivr_m16i
 0x40101c None
 0x401020 _CIsin
 0x401024 __vbaChkstk
 0x401028 EVENT_SINK_AddRef
 0x40102c _adj_fpatan
 0x401030 EVENT_SINK_Release
 0x401034 _CIsqrt
 0x401038 EVENT_SINK_QueryInterface
 0x40103c __vbaExceptHandler
 0x401040 _adj_fprem
 0x401044 _adj_fdivr_m64
 0x401048 __vbaFPException
 0x40104c _CIlog
 0x401050 __vbaErrorOverflow
 0x401054 _adj_fdiv_m32i
 0x401058 _adj_fdivr_m32i
 0x40105c _adj_fdivr_m32
 0x401060 _adj_fdiv_r
 0x401064 None
 0x401068 _CIatan
 0x40106c _allmul
 0x401070 _CItan
 0x401074 _CIexp

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure