Report - vbc.exe

PE File PE32
ScreenShot
Created 2021.08.26 08:33 Machine s1_win7_x6401
Filename vbc.exe
Type PE32 executable (console) Intel 80386, for MS Windows
AI Score
8
Behavior Score
8.6
ZERO API file : clean
VT API (file) 40 detected (AIDetect, malware2, Androm, malicious, high confidence, nuZ@aO30kxji, AgentTesla, TrojanPSW, Lokibot, ZexaF, Kryptik, Eldorado, HMFG, USMANHP21, utcn, Static AI, Suspicious PE, GenericKD, ai score=100, kcloud, 1V9N73W, score, BScope, CLASSIC, confidence)
md5 7a2484277599f27801079f9bbda665c1
sha256 60697f7c17c442322eea32ac41ee4d4e152e61fcff29079f4522cfa8de122c71
ssdeep 3072:riCuxk8o8iH7WyeLmKraSpzGmXTS3tZozdcQobfICn9DKHAwomU+3K11ma1farvh:riQPdHG1dTsZWkIkKHAwoU3KFGSDWJO0
imphash 35807dcde258f88fa3ce5c21adc607fb
impfuzzy 6:+TaupKx5XtSRMvblJfG4yRlbb7Rfg/QKRn:VucJFpG4qpfg9Rn
  Network IP location

Signature (19cnts)

Level Description
danger File has been identified by 40 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
watch Harvests credentials from local email clients
watch Harvests credentials from local FTP client softwares
watch Harvests information related to installed instant messenger clients
watch Putty Files
watch Used NtSetContextThread to modify a thread in a remote process indicative of process injection
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Moves the original executable to a new location
notice Performs some HTTP requests
notice Sends data using the HTTP POST Method
notice Steals private information from local Internet browsers
info Checks amount of memory in system
info Collects information to fingerprint the system (MachineGuid
info One or more processes crashed
info Queries for the computername
info Tries to locate where the browsers are installed

Rules (2cnts)

Level Name Description Collection
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (3cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://65.21.223.84/~t/i.html/m9vo3uzZGXz0z Unknown 65.21.223.84 4356 mailcious
51.89.96.41 FR OVH SAS 51.89.96.41 clean
65.21.223.84 Unknown 65.21.223.84 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x402098 EnumTimeFormatsW
 0x40209c GetConsoleOutputCP
 0x4020a0 GetLastError
 0x4020a4 GetModuleHandleW
 0x4020a8 GetProcessHeap
 0x4020ac GetStdHandle
 0x4020b0 HeapAlloc
 0x4020b4 HeapFree
 0x4020b8 LocalFree
 0x4020bc VirtualProtect
 0x4020c0 WideCharToMultiByte
 0x4020c4 WriteConsoleW
 0x4020c8 WriteFile
USER32.dll
 0x4020d0 LoadStringW

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure