Report - vbc.exe

UPX Malicious Library PE File PE32
ScreenShot
Created 2021.10.15 09:46 Machine s1_win7_x6402
Filename vbc.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
4
Behavior Score
1.6
ZERO API file : malware
VT API (file) 14 detected (malicious, high confidence, Save, ZelphiCO, XGW@aGcUbUpi, Eldorado, EQAC, Unsafe, Score, Sabsik, BScope, Noon, Static AI, Suspicious PE)
md5 09a2d9ea4a18f01aff698b8cfc98a87e
sha256 99cdf3421923232c160c5075af3bf8620df65bd59cf99cc341f17a58e1eeb4f2
ssdeep 12288:ZV17shYPLAsHSU8Qrn47tremr8bP/xz4Hrh+MBtI+BfZ8fQO:ZfwYxHSyMreg0P94HdtBZ8I
imphash 978fa6788aee75614efce16a9b593468
impfuzzy 192:f34nG1OoIibuuArSUvK9YqoaqyKeSPOQXj:f3t1FAA9ezPOQT
  Network IP location

Signature (4cnts)

Level Description
watch Communicates with host for which no DNS query was performed
watch File has been identified by 14 AntiVirus engines on VirusTotal as malicious
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (4cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
172.67.188.154 US CLOUDFLARENET 172.67.188.154 clean

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x49017c DeleteCriticalSection
 0x490180 LeaveCriticalSection
 0x490184 EnterCriticalSection
 0x490188 InitializeCriticalSection
 0x49018c VirtualFree
 0x490190 VirtualAlloc
 0x490194 LocalFree
 0x490198 LocalAlloc
 0x49019c GetVersion
 0x4901a0 GetCurrentThreadId
 0x4901a4 InterlockedDecrement
 0x4901a8 InterlockedIncrement
 0x4901ac VirtualQuery
 0x4901b0 WideCharToMultiByte
 0x4901b4 MultiByteToWideChar
 0x4901b8 lstrlenA
 0x4901bc lstrcpynA
 0x4901c0 LoadLibraryExA
 0x4901c4 GetThreadLocale
 0x4901c8 GetStartupInfoA
 0x4901cc GetProcAddress
 0x4901d0 GetModuleHandleA
 0x4901d4 GetModuleFileNameA
 0x4901d8 GetLocaleInfoA
 0x4901dc GetCommandLineA
 0x4901e0 FreeLibrary
 0x4901e4 FindFirstFileA
 0x4901e8 FindClose
 0x4901ec ExitProcess
 0x4901f0 WriteFile
 0x4901f4 UnhandledExceptionFilter
 0x4901f8 RtlUnwind
 0x4901fc RaiseException
 0x490200 GetStdHandle
user32.dll
 0x490208 GetKeyboardType
 0x49020c LoadStringA
 0x490210 MessageBoxA
 0x490214 CharNextA
advapi32.dll
 0x49021c RegQueryValueExA
 0x490220 RegOpenKeyExA
 0x490224 RegCloseKey
oleaut32.dll
 0x49022c SysFreeString
 0x490230 SysReAllocStringLen
 0x490234 SysAllocStringLen
kernel32.dll
 0x49023c TlsSetValue
 0x490240 TlsGetValue
 0x490244 LocalAlloc
 0x490248 GetModuleHandleA
advapi32.dll
 0x490250 RegQueryValueExA
 0x490254 RegOpenKeyExA
 0x490258 RegCloseKey
kernel32.dll
 0x490260 lstrcpyA
 0x490264 WriteFile
 0x490268 WaitForSingleObject
 0x49026c VirtualQuery
 0x490270 VirtualProtect
 0x490274 VirtualAlloc
 0x490278 Sleep
 0x49027c SizeofResource
 0x490280 SetThreadLocale
 0x490284 SetFilePointer
 0x490288 SetEvent
 0x49028c SetErrorMode
 0x490290 SetEndOfFile
 0x490294 ResetEvent
 0x490298 ReadFile
 0x49029c MultiByteToWideChar
 0x4902a0 MulDiv
 0x4902a4 LockResource
 0x4902a8 LoadResource
 0x4902ac LoadLibraryA
 0x4902b0 LeaveCriticalSection
 0x4902b4 InitializeCriticalSection
 0x4902b8 GlobalUnlock
 0x4902bc GlobalSize
 0x4902c0 GlobalReAlloc
 0x4902c4 GlobalHandle
 0x4902c8 GlobalLock
 0x4902cc GlobalFree
 0x4902d0 GlobalFindAtomA
 0x4902d4 GlobalDeleteAtom
 0x4902d8 GlobalAlloc
 0x4902dc GlobalAddAtomA
 0x4902e0 GetVersionExA
 0x4902e4 GetVersion
 0x4902e8 GetUserDefaultLCID
 0x4902ec GetTickCount
 0x4902f0 GetThreadLocale
 0x4902f4 GetSystemInfo
 0x4902f8 GetStringTypeExA
 0x4902fc GetStdHandle
 0x490300 GetProcAddress
 0x490304 GetModuleHandleA
 0x490308 GetModuleFileNameA
 0x49030c GetLocaleInfoA
 0x490310 GetLocalTime
 0x490314 GetLastError
 0x490318 GetFullPathNameA
 0x49031c GetDiskFreeSpaceA
 0x490320 GetDateFormatA
 0x490324 GetCurrentThreadId
 0x490328 GetCurrentProcessId
 0x49032c GetCurrentProcess
 0x490330 GetCPInfo
 0x490334 GetACP
 0x490338 FreeResource
 0x49033c InterlockedExchange
 0x490340 FreeLibrary
 0x490344 FormatMessageA
 0x490348 FlushInstructionCache
 0x49034c FindResourceA
 0x490350 EnumCalendarInfoA
 0x490354 EnterCriticalSection
 0x490358 DeleteCriticalSection
 0x49035c CreateThread
 0x490360 CreateFileA
 0x490364 CreateEventA
 0x490368 CompareStringA
 0x49036c CloseHandle
version.dll
 0x490374 VerQueryValueA
 0x490378 GetFileVersionInfoSizeA
 0x49037c GetFileVersionInfoA
gdi32.dll
 0x490384 UnrealizeObject
 0x490388 StretchBlt
 0x49038c SetWindowOrgEx
 0x490390 SetWinMetaFileBits
 0x490394 SetViewportOrgEx
 0x490398 SetTextColor
 0x49039c SetStretchBltMode
 0x4903a0 SetROP2
 0x4903a4 SetPixel
 0x4903a8 SetEnhMetaFileBits
 0x4903ac SetDIBColorTable
 0x4903b0 SetBrushOrgEx
 0x4903b4 SetBkMode
 0x4903b8 SetBkColor
 0x4903bc SelectPalette
 0x4903c0 SelectObject
 0x4903c4 SaveDC
 0x4903c8 RestoreDC
 0x4903cc Rectangle
 0x4903d0 RectVisible
 0x4903d4 RealizePalette
 0x4903d8 Polyline
 0x4903dc PlayEnhMetaFile
 0x4903e0 PatBlt
 0x4903e4 MoveToEx
 0x4903e8 MaskBlt
 0x4903ec LineTo
 0x4903f0 IntersectClipRect
 0x4903f4 GetWindowOrgEx
 0x4903f8 GetWinMetaFileBits
 0x4903fc GetTextMetricsA
 0x490400 GetTextExtentPoint32A
 0x490404 GetTextAlign
 0x490408 GetSystemPaletteEntries
 0x49040c GetStockObject
 0x490410 GetRgnBox
 0x490414 GetROP2
 0x490418 GetPolyFillMode
 0x49041c GetPixelFormat
 0x490420 GetPixel
 0x490424 GetPaletteEntries
 0x490428 GetObjectA
 0x49042c GetMapMode
 0x490430 GetGraphicsMode
 0x490434 GetEnhMetaFilePaletteEntries
 0x490438 GetEnhMetaFileHeader
 0x49043c GetEnhMetaFileDescriptionA
 0x490440 GetEnhMetaFileBits
 0x490444 GetDeviceCaps
 0x490448 GetDIBits
 0x49044c GetDIBColorTable
 0x490450 GetDCOrgEx
 0x490454 GetDCPenColor
 0x490458 GetDCBrushColor
 0x49045c GetCurrentPositionEx
 0x490460 GetClipBox
 0x490464 GetBrushOrgEx
 0x490468 GetBkMode
 0x49046c GetBkColor
 0x490470 GetBitmapBits
 0x490474 GdiFlush
 0x490478 ExcludeClipRect
 0x49047c DeleteObject
 0x490480 DeleteEnhMetaFile
 0x490484 DeleteDC
 0x490488 CreateSolidBrush
 0x49048c CreateRectRgn
 0x490490 CreatePenIndirect
 0x490494 CreatePen
 0x490498 CreatePalette
 0x49049c CreateHalftonePalette
 0x4904a0 CreateFontIndirectA
 0x4904a4 CreateEnhMetaFileA
 0x4904a8 CreateDIBitmap
 0x4904ac CreateDIBSection
 0x4904b0 CreateCompatibleDC
 0x4904b4 CreateCompatibleBitmap
 0x4904b8 CreateBrushIndirect
 0x4904bc CreateBitmap
 0x4904c0 CopyEnhMetaFileA
 0x4904c4 CombineRgn
 0x4904c8 CloseEnhMetaFile
 0x4904cc BitBlt
user32.dll
 0x4904d4 CreateWindowExA
 0x4904d8 WindowFromPoint
 0x4904dc WinHelpA
 0x4904e0 WaitMessage
 0x4904e4 ValidateRect
 0x4904e8 UpdateWindow
 0x4904ec UnregisterClassA
 0x4904f0 UnhookWindowsHookEx
 0x4904f4 TranslateMessage
 0x4904f8 TranslateMDISysAccel
 0x4904fc TrackPopupMenu
 0x490500 SystemParametersInfoA
 0x490504 ShowWindow
 0x490508 ShowScrollBar
 0x49050c ShowOwnedPopups
 0x490510 ShowCursor
 0x490514 SetWindowsHookExA
 0x490518 SetWindowTextA
 0x49051c SetWindowPos
 0x490520 SetWindowPlacement
 0x490524 SetWindowLongA
 0x490528 SetTimer
 0x49052c SetScrollRange
 0x490530 SetScrollPos
 0x490534 SetScrollInfo
 0x490538 SetRect
 0x49053c SetPropA
 0x490540 SetParent
 0x490544 SetMenuItemInfoA
 0x490548 SetMenu
 0x49054c SetForegroundWindow
 0x490550 SetFocus
 0x490554 SetCursor
 0x490558 SetClassLongA
 0x49055c SetCapture
 0x490560 SetActiveWindow
 0x490564 SendMessageA
 0x490568 ScrollWindow
 0x49056c ScreenToClient
 0x490570 RemovePropA
 0x490574 RemoveMenu
 0x490578 ReleaseDC
 0x49057c ReleaseCapture
 0x490580 RegisterWindowMessageA
 0x490584 RegisterClipboardFormatA
 0x490588 RegisterClassA
 0x49058c RedrawWindow
 0x490590 PtInRect
 0x490594 PostQuitMessage
 0x490598 PostMessageA
 0x49059c PeekMessageA
 0x4905a0 OffsetRect
 0x4905a4 OemToCharA
 0x4905a8 MessageBoxA
 0x4905ac MessageBeep
 0x4905b0 MapWindowPoints
 0x4905b4 MapVirtualKeyA
 0x4905b8 LoadStringA
 0x4905bc LoadKeyboardLayoutA
 0x4905c0 LoadIconA
 0x4905c4 LoadCursorA
 0x4905c8 LoadBitmapA
 0x4905cc KillTimer
 0x4905d0 IsZoomed
 0x4905d4 IsWindowVisible
 0x4905d8 IsWindowEnabled
 0x4905dc IsWindow
 0x4905e0 IsRectEmpty
 0x4905e4 IsIconic
 0x4905e8 IsDialogMessageA
 0x4905ec IsChild
 0x4905f0 InvalidateRect
 0x4905f4 IntersectRect
 0x4905f8 InsertMenuItemA
 0x4905fc InsertMenuA
 0x490600 InflateRect
 0x490604 GetWindowThreadProcessId
 0x490608 GetWindowTextA
 0x49060c GetWindowRect
 0x490610 GetWindowPlacement
 0x490614 GetWindowLongA
 0x490618 GetWindowDC
 0x49061c GetTopWindow
 0x490620 GetSystemMetrics
 0x490624 GetSystemMenu
 0x490628 GetSysColorBrush
 0x49062c GetSysColor
 0x490630 GetSubMenu
 0x490634 GetScrollRange
 0x490638 GetScrollPos
 0x49063c GetScrollInfo
 0x490640 GetPropA
 0x490644 GetParent
 0x490648 GetWindow
 0x49064c GetMessageTime
 0x490650 GetMenuStringA
 0x490654 GetMenuState
 0x490658 GetMenuItemInfoA
 0x49065c GetMenuItemID
 0x490660 GetMenuItemCount
 0x490664 GetMenu
 0x490668 GetLastActivePopup
 0x49066c GetKeyboardState
 0x490670 GetKeyboardLayoutList
 0x490674 GetKeyboardLayout
 0x490678 GetKeyState
 0x49067c GetKeyNameTextA
 0x490680 GetIconInfo
 0x490684 GetForegroundWindow
 0x490688 GetFocus
 0x49068c GetDlgItem
 0x490690 GetDesktopWindow
 0x490694 GetDCEx
 0x490698 GetDC
 0x49069c GetCursorPos
 0x4906a0 GetCursor
 0x4906a4 GetClipboardData
 0x4906a8 GetClientRect
 0x4906ac GetClassNameA
 0x4906b0 GetClassInfoA
 0x4906b4 GetCapture
 0x4906b8 GetActiveWindow
 0x4906bc FrameRect
 0x4906c0 FindWindowA
 0x4906c4 FillRect
 0x4906c8 EqualRect
 0x4906cc EnumWindows
 0x4906d0 EnumThreadWindows
 0x4906d4 EndPaint
 0x4906d8 EnableWindow
 0x4906dc EnableScrollBar
 0x4906e0 EnableMenuItem
 0x4906e4 DrawTextA
 0x4906e8 DrawMenuBar
 0x4906ec DrawIconEx
 0x4906f0 DrawIcon
 0x4906f4 DrawFrameControl
 0x4906f8 DrawFocusRect
 0x4906fc DrawEdge
 0x490700 DispatchMessageA
 0x490704 DestroyWindow
 0x490708 DestroyMenu
 0x49070c DestroyIcon
 0x490710 DestroyCursor
 0x490714 DeleteMenu
 0x490718 DefWindowProcA
 0x49071c DefMDIChildProcA
 0x490720 DefFrameProcA
 0x490724 CreatePopupMenu
 0x490728 CreateMenu
 0x49072c CreateIcon
 0x490730 ClientToScreen
 0x490734 CheckMenuItem
 0x490738 CallWindowProcA
 0x49073c CallNextHookEx
 0x490740 BeginPaint
 0x490744 CharNextA
 0x490748 CharLowerBuffA
 0x49074c CharLowerA
 0x490750 CharToOemA
 0x490754 AdjustWindowRectEx
 0x490758 ActivateKeyboardLayout
kernel32.dll
 0x490760 Sleep
oleaut32.dll
 0x490768 SafeArrayPtrOfIndex
 0x49076c SafeArrayGetUBound
 0x490770 SafeArrayGetLBound
 0x490774 SafeArrayCreate
 0x490778 VariantChangeType
 0x49077c VariantCopy
 0x490780 VariantClear
 0x490784 VariantInit
ole32.dll
 0x49078c CreateStreamOnHGlobal
 0x490790 IsAccelerator
 0x490794 OleDraw
 0x490798 OleSetMenuDescriptor
 0x49079c CoCreateInstance
 0x4907a0 CoGetClassObject
 0x4907a4 CoUninitialize
 0x4907a8 CoInitialize
 0x4907ac IsEqualGUID
oleaut32.dll
 0x4907b4 GetErrorInfo
 0x4907b8 SysFreeString
comctl32.dll
 0x4907c0 ImageList_SetIconSize
 0x4907c4 ImageList_GetIconSize
 0x4907c8 ImageList_Write
 0x4907cc ImageList_Read
 0x4907d0 ImageList_GetDragImage
 0x4907d4 ImageList_DragShowNolock
 0x4907d8 ImageList_SetDragCursorImage
 0x4907dc ImageList_DragMove
 0x4907e0 ImageList_DragLeave
 0x4907e4 ImageList_DragEnter
 0x4907e8 ImageList_EndDrag
 0x4907ec ImageList_BeginDrag
 0x4907f0 ImageList_Remove
 0x4907f4 ImageList_DrawEx
 0x4907f8 ImageList_Replace
 0x4907fc ImageList_Draw
 0x490800 ImageList_GetBkColor
 0x490804 ImageList_SetBkColor
 0x490808 ImageList_ReplaceIcon
 0x49080c ImageList_Add
 0x490810 ImageList_SetImageCount
 0x490814 ImageList_GetImageCount
 0x490818 ImageList_Destroy
 0x49081c ImageList_Create
 0x490820 InitCommonControls
comdlg32.dll
 0x490828 GetSaveFileNameA
 0x49082c GetOpenFileNameA
winhttp
 0x490834 WinHttpCheckPlatform
mf
 0x49083c MFCreate3GPMediaSink

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure