Report - vbc.exe

Admin Tool (Sysinternals etc ...) UPX Malicious Library PE File PE32
ScreenShot
Created 2021.10.14 15:19 Machine s1_win7_x6402
Filename vbc.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
6
Behavior Score
1.0
ZERO API file : malware
VT API (file) 16 detected (malicious, high confidence, Artemis, Unsafe, kcloud, Sabsik, ZelphiCO, 9GW@aGR2mjei, BScope, Noon, Generic@ML, RDML, qRZtUoiYH58wFqRX2Kpiw, EQAC)
md5 2292debf2685fda1410be586bd7d25b1
sha256 90e1eac40edda005fffadbb1d16c652d16e685f8f4cf7375eb6ac928222c3a1c
ssdeep 12288:GrHeuodar6Dd3m4aS9FCZXhGiX1d0uVrLGaDOdJ4NUTI94rv4lprmi:GDe0W1m4aVNTc9jOiI2rqpm
imphash 33ef3fa8cfca6640b4d180caba182c91
impfuzzy 192:f34j8d1yTuKJbuuaxSUvK9yeooqyho7CPbOQvuD2:f3l1ytaq9MOPbOQ2a
  Network IP location

Signature (3cnts)

Level Description
watch File has been identified by 16 AntiVirus engines on VirusTotal as malicious
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (5cnts)

Level Name Description Collection
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x4bd1a4 DeleteCriticalSection
 0x4bd1a8 LeaveCriticalSection
 0x4bd1ac EnterCriticalSection
 0x4bd1b0 InitializeCriticalSection
 0x4bd1b4 VirtualFree
 0x4bd1b8 VirtualAlloc
 0x4bd1bc LocalFree
 0x4bd1c0 LocalAlloc
 0x4bd1c4 GetVersion
 0x4bd1c8 GetCurrentThreadId
 0x4bd1cc InterlockedDecrement
 0x4bd1d0 InterlockedIncrement
 0x4bd1d4 VirtualQuery
 0x4bd1d8 WideCharToMultiByte
 0x4bd1dc MultiByteToWideChar
 0x4bd1e0 lstrlenA
 0x4bd1e4 lstrcpynA
 0x4bd1e8 LoadLibraryExA
 0x4bd1ec GetThreadLocale
 0x4bd1f0 GetStartupInfoA
 0x4bd1f4 GetProcAddress
 0x4bd1f8 GetModuleHandleA
 0x4bd1fc GetModuleFileNameA
 0x4bd200 GetLocaleInfoA
 0x4bd204 GetCommandLineA
 0x4bd208 FreeLibrary
 0x4bd20c FindFirstFileA
 0x4bd210 FindClose
 0x4bd214 ExitProcess
 0x4bd218 WriteFile
 0x4bd21c UnhandledExceptionFilter
 0x4bd220 RtlUnwind
 0x4bd224 RaiseException
 0x4bd228 GetStdHandle
user32.dll
 0x4bd230 GetKeyboardType
 0x4bd234 LoadStringA
 0x4bd238 MessageBoxA
 0x4bd23c CharNextA
advapi32.dll
 0x4bd244 RegQueryValueExA
 0x4bd248 RegOpenKeyExA
 0x4bd24c RegCloseKey
oleaut32.dll
 0x4bd254 SysFreeString
 0x4bd258 SysReAllocStringLen
 0x4bd25c SysAllocStringLen
kernel32.dll
 0x4bd264 TlsSetValue
 0x4bd268 TlsGetValue
 0x4bd26c LocalAlloc
 0x4bd270 GetModuleHandleA
advapi32.dll
 0x4bd278 RegQueryValueExA
 0x4bd27c RegOpenKeyExA
 0x4bd280 RegCloseKey
kernel32.dll
 0x4bd288 lstrcpyA
 0x4bd28c WriteFile
 0x4bd290 WaitForSingleObject
 0x4bd294 VirtualQuery
 0x4bd298 VirtualProtect
 0x4bd29c VirtualAlloc
 0x4bd2a0 Sleep
 0x4bd2a4 SizeofResource
 0x4bd2a8 SetThreadLocale
 0x4bd2ac SetFilePointer
 0x4bd2b0 SetEvent
 0x4bd2b4 SetErrorMode
 0x4bd2b8 SetEndOfFile
 0x4bd2bc ResetEvent
 0x4bd2c0 ReadFile
 0x4bd2c4 MultiByteToWideChar
 0x4bd2c8 MulDiv
 0x4bd2cc LockResource
 0x4bd2d0 LoadResource
 0x4bd2d4 LoadLibraryA
 0x4bd2d8 LeaveCriticalSection
 0x4bd2dc InitializeCriticalSection
 0x4bd2e0 GlobalUnlock
 0x4bd2e4 GlobalReAlloc
 0x4bd2e8 GlobalHandle
 0x4bd2ec GlobalLock
 0x4bd2f0 GlobalFree
 0x4bd2f4 GlobalFindAtomA
 0x4bd2f8 GlobalDeleteAtom
 0x4bd2fc GlobalAlloc
 0x4bd300 GlobalAddAtomA
 0x4bd304 GetVersionExA
 0x4bd308 GetVersion
 0x4bd30c GetTickCount
 0x4bd310 GetThreadLocale
 0x4bd314 GetSystemInfo
 0x4bd318 GetStringTypeExA
 0x4bd31c GetStdHandle
 0x4bd320 GetProfileStringA
 0x4bd324 GetProcAddress
 0x4bd328 GetModuleHandleA
 0x4bd32c GetModuleFileNameA
 0x4bd330 GetLocaleInfoA
 0x4bd334 GetLocalTime
 0x4bd338 GetLastError
 0x4bd33c GetFullPathNameA
 0x4bd340 GetDiskFreeSpaceA
 0x4bd344 GetDateFormatA
 0x4bd348 GetCurrentThreadId
 0x4bd34c GetCurrentProcessId
 0x4bd350 GetCurrentProcess
 0x4bd354 GetComputerNameA
 0x4bd358 GetCPInfo
 0x4bd35c GetACP
 0x4bd360 FreeResource
 0x4bd364 InterlockedExchange
 0x4bd368 FreeLibrary
 0x4bd36c FormatMessageA
 0x4bd370 FlushInstructionCache
 0x4bd374 FindResourceA
 0x4bd378 FindFirstFileA
 0x4bd37c FindClose
 0x4bd380 FileTimeToLocalFileTime
 0x4bd384 FileTimeToDosDateTime
 0x4bd388 EnumCalendarInfoA
 0x4bd38c EnterCriticalSection
 0x4bd390 DeleteFileA
 0x4bd394 DeleteCriticalSection
 0x4bd398 CreateThread
 0x4bd39c CreateFileA
 0x4bd3a0 CreateEventA
 0x4bd3a4 CompareStringA
 0x4bd3a8 CloseHandle
version.dll
 0x4bd3b0 VerQueryValueA
 0x4bd3b4 GetFileVersionInfoSizeA
 0x4bd3b8 GetFileVersionInfoA
gdi32.dll
 0x4bd3c0 UnrealizeObject
 0x4bd3c4 StretchBlt
 0x4bd3c8 StartPage
 0x4bd3cc StartDocA
 0x4bd3d0 SetWindowOrgEx
 0x4bd3d4 SetWinMetaFileBits
 0x4bd3d8 SetViewportOrgEx
 0x4bd3dc SetTextColor
 0x4bd3e0 SetStretchBltMode
 0x4bd3e4 SetROP2
 0x4bd3e8 SetPixel
 0x4bd3ec SetMapMode
 0x4bd3f0 SetEnhMetaFileBits
 0x4bd3f4 SetDIBColorTable
 0x4bd3f8 SetBrushOrgEx
 0x4bd3fc SetBkMode
 0x4bd400 SetBkColor
 0x4bd404 SetAbortProc
 0x4bd408 SelectPalette
 0x4bd40c SelectObject
 0x4bd410 SelectClipRgn
 0x4bd414 SaveDC
 0x4bd418 RestoreDC
 0x4bd41c Rectangle
 0x4bd420 RectVisible
 0x4bd424 RealizePalette
 0x4bd428 Polyline
 0x4bd42c Polygon
 0x4bd430 PlayEnhMetaFile
 0x4bd434 PatBlt
 0x4bd438 MoveToEx
 0x4bd43c MaskBlt
 0x4bd440 LineTo
 0x4bd444 IntersectClipRect
 0x4bd448 GetWindowOrgEx
 0x4bd44c GetWinMetaFileBits
 0x4bd450 GetTextMetricsA
 0x4bd454 GetTextExtentPointA
 0x4bd458 GetTextExtentPoint32A
 0x4bd45c GetTextAlign
 0x4bd460 GetSystemPaletteEntries
 0x4bd464 GetStockObject
 0x4bd468 GetROP2
 0x4bd46c GetPolyFillMode
 0x4bd470 GetPixelFormat
 0x4bd474 GetPixel
 0x4bd478 GetPaletteEntries
 0x4bd47c GetObjectA
 0x4bd480 GetMapMode
 0x4bd484 GetGraphicsMode
 0x4bd488 GetEnhMetaFilePaletteEntries
 0x4bd48c GetEnhMetaFileHeader
 0x4bd490 GetEnhMetaFileBits
 0x4bd494 GetDeviceCaps
 0x4bd498 GetDIBits
 0x4bd49c GetDIBColorTable
 0x4bd4a0 GetDCOrgEx
 0x4bd4a4 GetDCPenColor
 0x4bd4a8 GetCurrentPositionEx
 0x4bd4ac GetClipBox
 0x4bd4b0 GetBrushOrgEx
 0x4bd4b4 GetBkMode
 0x4bd4b8 GetBkColor
 0x4bd4bc GetBitmapBits
 0x4bd4c0 GdiFlush
 0x4bd4c4 ExtTextOutA
 0x4bd4c8 ExcludeClipRect
 0x4bd4cc EndPage
 0x4bd4d0 EndDoc
 0x4bd4d4 DeleteObject
 0x4bd4d8 DeleteEnhMetaFile
 0x4bd4dc DeleteDC
 0x4bd4e0 CreateSolidBrush
 0x4bd4e4 CreatePenIndirect
 0x4bd4e8 CreatePalette
 0x4bd4ec CreateICA
 0x4bd4f0 CreateHalftonePalette
 0x4bd4f4 CreateFontIndirectA
 0x4bd4f8 CreateDIBitmap
 0x4bd4fc CreateDIBSection
 0x4bd500 CreateDCA
 0x4bd504 CreateCompatibleDC
 0x4bd508 CreateCompatibleBitmap
 0x4bd50c CreateBrushIndirect
 0x4bd510 CreateBitmap
 0x4bd514 CopyEnhMetaFileA
 0x4bd518 BitBlt
user32.dll
 0x4bd520 CreateWindowExA
 0x4bd524 WindowFromPoint
 0x4bd528 WinHelpA
 0x4bd52c WaitMessage
 0x4bd530 UpdateWindow
 0x4bd534 UnregisterClassA
 0x4bd538 UnhookWindowsHookEx
 0x4bd53c TranslateMessage
 0x4bd540 TranslateMDISysAccel
 0x4bd544 TrackPopupMenu
 0x4bd548 SystemParametersInfoA
 0x4bd54c ShowWindow
 0x4bd550 ShowScrollBar
 0x4bd554 ShowOwnedPopups
 0x4bd558 ShowCursor
 0x4bd55c ShowCaret
 0x4bd560 SetWindowsHookExA
 0x4bd564 SetWindowTextA
 0x4bd568 SetWindowPos
 0x4bd56c SetWindowPlacement
 0x4bd570 SetWindowLongA
 0x4bd574 SetTimer
 0x4bd578 SetScrollRange
 0x4bd57c SetScrollPos
 0x4bd580 SetScrollInfo
 0x4bd584 SetRect
 0x4bd588 SetPropA
 0x4bd58c SetParent
 0x4bd590 SetMenuItemInfoA
 0x4bd594 SetMenu
 0x4bd598 SetForegroundWindow
 0x4bd59c SetFocus
 0x4bd5a0 SetCursor
 0x4bd5a4 SetClipboardData
 0x4bd5a8 SetClassLongA
 0x4bd5ac SetCapture
 0x4bd5b0 SetActiveWindow
 0x4bd5b4 SendMessageA
 0x4bd5b8 ScrollWindow
 0x4bd5bc ScreenToClient
 0x4bd5c0 RemovePropA
 0x4bd5c4 RemoveMenu
 0x4bd5c8 ReleaseDC
 0x4bd5cc ReleaseCapture
 0x4bd5d0 RegisterWindowMessageA
 0x4bd5d4 RegisterClipboardFormatA
 0x4bd5d8 RegisterClassA
 0x4bd5dc RedrawWindow
 0x4bd5e0 PtInRect
 0x4bd5e4 PostQuitMessage
 0x4bd5e8 PostMessageA
 0x4bd5ec PeekMessageA
 0x4bd5f0 OpenClipboard
 0x4bd5f4 OffsetRect
 0x4bd5f8 OemToCharA
 0x4bd5fc MessageBoxA
 0x4bd600 MessageBeep
 0x4bd604 MapWindowPoints
 0x4bd608 MapVirtualKeyA
 0x4bd60c LoadStringA
 0x4bd610 LoadKeyboardLayoutA
 0x4bd614 LoadIconA
 0x4bd618 LoadCursorA
 0x4bd61c LoadBitmapA
 0x4bd620 KillTimer
 0x4bd624 IsZoomed
 0x4bd628 IsWindowVisible
 0x4bd62c IsWindowEnabled
 0x4bd630 IsWindow
 0x4bd634 IsRectEmpty
 0x4bd638 IsIconic
 0x4bd63c IsDialogMessageA
 0x4bd640 IsChild
 0x4bd644 InvalidateRect
 0x4bd648 IntersectRect
 0x4bd64c InsertMenuItemA
 0x4bd650 InsertMenuA
 0x4bd654 InflateRect
 0x4bd658 HideCaret
 0x4bd65c GetWindowThreadProcessId
 0x4bd660 GetWindowTextA
 0x4bd664 GetWindowRect
 0x4bd668 GetWindowPlacement
 0x4bd66c GetWindowLongA
 0x4bd670 GetWindowDC
 0x4bd674 GetUpdateRect
 0x4bd678 GetTopWindow
 0x4bd67c GetSystemMetrics
 0x4bd680 GetSystemMenu
 0x4bd684 GetSysColorBrush
 0x4bd688 GetSysColor
 0x4bd68c GetSubMenu
 0x4bd690 GetScrollRange
 0x4bd694 GetScrollPos
 0x4bd698 GetScrollInfo
 0x4bd69c GetPropA
 0x4bd6a0 GetParent
 0x4bd6a4 GetWindow
 0x4bd6a8 GetMenuStringA
 0x4bd6ac GetMenuState
 0x4bd6b0 GetMenuItemInfoA
 0x4bd6b4 GetMenuItemID
 0x4bd6b8 GetMenuItemCount
 0x4bd6bc GetMenu
 0x4bd6c0 GetLastActivePopup
 0x4bd6c4 GetKeyboardState
 0x4bd6c8 GetKeyboardLayoutList
 0x4bd6cc GetKeyboardLayout
 0x4bd6d0 GetKeyState
 0x4bd6d4 GetKeyNameTextA
 0x4bd6d8 GetIconInfo
 0x4bd6dc GetForegroundWindow
 0x4bd6e0 GetFocus
 0x4bd6e4 GetDlgItem
 0x4bd6e8 GetDesktopWindow
 0x4bd6ec GetDCEx
 0x4bd6f0 GetDC
 0x4bd6f4 GetCursorPos
 0x4bd6f8 GetCursor
 0x4bd6fc GetClipboardData
 0x4bd700 GetClientRect
 0x4bd704 GetClassNameA
 0x4bd708 GetClassInfoA
 0x4bd70c GetCapture
 0x4bd710 GetActiveWindow
 0x4bd714 FrameRect
 0x4bd718 FindWindowA
 0x4bd71c FillRect
 0x4bd720 EqualRect
 0x4bd724 EnumWindows
 0x4bd728 EnumThreadWindows
 0x4bd72c EndPaint
 0x4bd730 EnableWindow
 0x4bd734 EnableScrollBar
 0x4bd738 EnableMenuItem
 0x4bd73c EmptyClipboard
 0x4bd740 DrawTextA
 0x4bd744 DrawStateA
 0x4bd748 DrawMenuBar
 0x4bd74c DrawIconEx
 0x4bd750 DrawIcon
 0x4bd754 DrawFrameControl
 0x4bd758 DrawFocusRect
 0x4bd75c DrawEdge
 0x4bd760 DispatchMessageA
 0x4bd764 DestroyWindow
 0x4bd768 DestroyMenu
 0x4bd76c DestroyIcon
 0x4bd770 DestroyCursor
 0x4bd774 DeleteMenu
 0x4bd778 DefWindowProcA
 0x4bd77c DefMDIChildProcA
 0x4bd780 DefFrameProcA
 0x4bd784 CreatePopupMenu
 0x4bd788 CreateMenu
 0x4bd78c CreateIcon
 0x4bd790 CloseClipboard
 0x4bd794 ClientToScreen
 0x4bd798 CheckMenuItem
 0x4bd79c CallWindowProcA
 0x4bd7a0 CallNextHookEx
 0x4bd7a4 BeginPaint
 0x4bd7a8 CharNextA
 0x4bd7ac CharLowerBuffA
 0x4bd7b0 CharLowerA
 0x4bd7b4 CharUpperBuffA
 0x4bd7b8 CharToOemA
 0x4bd7bc AdjustWindowRectEx
 0x4bd7c0 ActivateKeyboardLayout
kernel32.dll
 0x4bd7c8 Sleep
oleaut32.dll
 0x4bd7d0 SafeArrayPtrOfIndex
 0x4bd7d4 SafeArrayPutElement
 0x4bd7d8 SafeArrayGetElement
 0x4bd7dc SafeArrayUnaccessData
 0x4bd7e0 SafeArrayAccessData
 0x4bd7e4 SafeArrayGetUBound
 0x4bd7e8 SafeArrayGetLBound
 0x4bd7ec SafeArrayCreate
 0x4bd7f0 VariantChangeType
 0x4bd7f4 VariantCopyInd
 0x4bd7f8 VariantCopy
 0x4bd7fc VariantClear
 0x4bd800 VariantInit
ole32.dll
 0x4bd808 CoTaskMemFree
 0x4bd80c ProgIDFromCLSID
 0x4bd810 StringFromCLSID
 0x4bd814 CoCreateInstance
 0x4bd818 CoUninitialize
 0x4bd81c CoInitialize
 0x4bd820 IsEqualGUID
oleaut32.dll
 0x4bd828 GetErrorInfo
 0x4bd82c GetActiveObject
 0x4bd830 SysFreeString
comctl32.dll
 0x4bd838 ImageList_SetIconSize
 0x4bd83c ImageList_GetIconSize
 0x4bd840 ImageList_Write
 0x4bd844 ImageList_Read
 0x4bd848 ImageList_GetDragImage
 0x4bd84c ImageList_DragShowNolock
 0x4bd850 ImageList_SetDragCursorImage
 0x4bd854 ImageList_DragMove
 0x4bd858 ImageList_DragLeave
 0x4bd85c ImageList_DragEnter
 0x4bd860 ImageList_EndDrag
 0x4bd864 ImageList_BeginDrag
 0x4bd868 ImageList_Remove
 0x4bd86c ImageList_DrawEx
 0x4bd870 ImageList_Replace
 0x4bd874 ImageList_Draw
 0x4bd878 ImageList_GetBkColor
 0x4bd87c ImageList_SetBkColor
 0x4bd880 ImageList_ReplaceIcon
 0x4bd884 ImageList_Add
 0x4bd888 ImageList_SetImageCount
 0x4bd88c ImageList_GetImageCount
 0x4bd890 ImageList_Destroy
 0x4bd894 ImageList_Create
 0x4bd898 InitCommonControls
winspool.drv
 0x4bd8a0 OpenPrinterA
 0x4bd8a4 EnumPrintersA
 0x4bd8a8 DocumentPropertiesA
 0x4bd8ac ClosePrinter
comdlg32.dll
 0x4bd8b4 GetSaveFileNameA
 0x4bd8b8 GetOpenFileNameA
winmm.dll
 0x4bd8c0 sndPlaySoundA
mf
 0x4bd8c8 MFCreate3GPMediaSink
winhttp
 0x4bd8d0 WinHttpCheckPlatform

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure