Report - vbc.exe

UPX PE File PE32
ScreenShot
Created 2021.10.05 09:41 Machine s1_win7_x6401
Filename vbc.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
2
Behavior Score
2.2
ZERO API file : clean
VT API (file) 46 detected (AIDetect, malware1, Mucc, malicious, high confidence, score, GenericKD, Save, confidence, a variant of Generik, IDJMLUZ, Nekark, jcktda, deano, kcloud, Fareit, ai score=88, TScope, Unsafe, R011C0PIT21, AvsArher, bTx33N, Static AI, Malicious PE, Behavior, ZevbaF, im0@aW3kL6bi)
md5 0f73289ff5a72fd093fd215e9f60b0d7
sha256 bbe723629dde9645172e5d1dbf2cd5b252b6c91e589296db86990453f329cb3f
ssdeep 1536:Duc1rbKPbr3viCXvG7kBhn5Pr4EPRpaIaRk412ROSMJpIPRUg:VnKH3viCXOoBhnBr4VRt1WtlRUg
imphash 84354178604622e0a5b23c227959c589
impfuzzy 24:n9wwzwgOSwOVy8xO3u93Wmrlxr1Sxg3GbloT/EWFNIzsTG5XD+JTSwMSwC:nqwzwgPweRxO3u93Nhxr1Sxg3GbaTNFH
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 46 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
info Checks amount of memory in system

Rules (3cnts)

Level Name Description Collection
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

MSVBVM60.DLL
 0x401000 _CIcos
 0x401004 _adj_fptan
 0x401008 __vbaFreeVar
 0x40100c __vbaFreeVarList
 0x401010 _adj_fdiv_m64
 0x401014 __vbaFreeObjList
 0x401018 _adj_fprem1
 0x40101c __vbaHresultCheckObj
 0x401020 _adj_fdiv_m32
 0x401024 __vbaAryDestruct
 0x401028 None
 0x40102c __vbaObjSet
 0x401030 __vbaOnError
 0x401034 _adj_fdiv_m16i
 0x401038 __vbaObjSetAddref
 0x40103c _adj_fdivr_m16i
 0x401040 None
 0x401044 __vbaFpR8
 0x401048 _CIsin
 0x40104c __vbaChkstk
 0x401050 EVENT_SINK_AddRef
 0x401054 __vbaGenerateBoundsError
 0x401058 __vbaStrCmp
 0x40105c __vbaAryConstruct2
 0x401060 __vbaObjVar
 0x401064 _adj_fpatan
 0x401068 None
 0x40106c __vbaLateIdCallLd
 0x401070 None
 0x401074 EVENT_SINK_Release
 0x401078 _CIsqrt
 0x40107c EVENT_SINK_QueryInterface
 0x401080 __vbaExceptHandler
 0x401084 _adj_fprem
 0x401088 _adj_fdivr_m64
 0x40108c None
 0x401090 __vbaFPException
 0x401094 None
 0x401098 _CIlog
 0x40109c __vbaErrorOverflow
 0x4010a0 __vbaNew2
 0x4010a4 None
 0x4010a8 _adj_fdiv_m32i
 0x4010ac _adj_fdivr_m32i
 0x4010b0 None
 0x4010b4 _adj_fdivr_m32
 0x4010b8 _adj_fdiv_r
 0x4010bc None
 0x4010c0 None
 0x4010c4 __vbaI4Var
 0x4010c8 __vbaFpI4
 0x4010cc _CIatan
 0x4010d0 __vbaStrMove
 0x4010d4 _allmul
 0x4010d8 _CItan
 0x4010dc _CIexp
 0x4010e0 __vbaFreeObj
 0x4010e4 __vbaFreeStr

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure