Report - vbc.exe

Admin Tool (Sysinternals etc ...) Malicious Library UPX PE File PE32
ScreenShot
Created 2021.11.05 09:39 Machine s1_win7_x6401
Filename vbc.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
6
Behavior Score
3.2
ZERO API file : clean
VT API (file) 14 detected (Delf, AABX, Malicious, FileRepMalware, orqex@0, susgen, Phonzy, Artemis, BScope, Noon, Static AI, Suspicious PE, EPWN)
md5 ab47f89cf986d9e52822873e0052e7d4
sha256 f4097221e19342e5b91103161eb7aaec277ff47ea694a86b92f7574be7959cc7
ssdeep 12288:JmF8ukZ1BjH652L9a3ZV6ImC/KGaIEfrcSjzMYIO3pxhOtFuhe3CL+NdJydmf:JywJjf9QVOg6zZ3nheu8swJ
imphash a909072c8ac1c865a094bf6cee9a4d60
impfuzzy 192:f3Pm8k1sTu/PbuuaxSUvK9yeooqyRo72POQRuDP:f3+1swaq9MwPOQMz
  Network IP location

Signature (8cnts)

Level Description
watch File has been identified by 14 AntiVirus engines on VirusTotal as malicious
watch Network activity contains more than one unique useragent
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Performs some HTTP requests
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (5cnts)

Level Name Description Collection
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (7cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=13&ct=1636072606&rver=7.3.6962.0&wp=MBI_SSL_SHARED&wreply=https:%2F%2Fonedrive.live.com%2Fdownload%3Fcid%3D92B2EF722ED2FA89%26resid%3D92B2EF722ED2FA89%2521117%26authkey%3DAL8-gdX92sl2g5g&lc=1033&id=2502 SG MICROSOFT-CORP-MSN-AS-BLOCK 20.190.163.21 clean
https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=13&ct=1636072608&rver=7.3.6962.0&wp=MBI_SSL_SHARED&wreply=https:%2F%2Fonedrive.live.com%2Fdownload%3Fcid%3D92B2EF722ED2FA89%26resid%3D92B2EF722ED2FA89%2521117%26authkey%3DAL8-gdX92sl2g5g&lc=1033&id=2502 SG MICROSOFT-CORP-MSN-AS-BLOCK 20.190.163.21 clean
https://onedrive.live.com/download?cid=92B2EF722ED2FA89&resid=92B2EF722ED2FA89%21117&authkey=AL8-gdX92sl2g5g US MICROSOFT-CORP-MSN-AS-BLOCK 13.107.42.13 clean
login.live.com SG MICROSOFT-CORP-MSN-AS-BLOCK 40.126.35.128 clean
onedrive.live.com US MICROSOFT-CORP-MSN-AS-BLOCK 13.107.42.13 mailcious
20.190.163.21 SG MICROSOFT-CORP-MSN-AS-BLOCK 20.190.163.21 clean
13.107.42.13 US MICROSOFT-CORP-MSN-AS-BLOCK 13.107.42.13 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x49917c DeleteCriticalSection
 0x499180 LeaveCriticalSection
 0x499184 EnterCriticalSection
 0x499188 InitializeCriticalSection
 0x49918c VirtualFree
 0x499190 VirtualAlloc
 0x499194 LocalFree
 0x499198 LocalAlloc
 0x49919c GetVersion
 0x4991a0 GetCurrentThreadId
 0x4991a4 InterlockedDecrement
 0x4991a8 InterlockedIncrement
 0x4991ac VirtualQuery
 0x4991b0 WideCharToMultiByte
 0x4991b4 MultiByteToWideChar
 0x4991b8 lstrlenA
 0x4991bc lstrcpynA
 0x4991c0 LoadLibraryExA
 0x4991c4 GetThreadLocale
 0x4991c8 GetStartupInfoA
 0x4991cc GetProcAddress
 0x4991d0 GetModuleHandleA
 0x4991d4 GetModuleFileNameA
 0x4991d8 GetLocaleInfoA
 0x4991dc GetCommandLineA
 0x4991e0 FreeLibrary
 0x4991e4 FindFirstFileA
 0x4991e8 FindClose
 0x4991ec ExitProcess
 0x4991f0 WriteFile
 0x4991f4 UnhandledExceptionFilter
 0x4991f8 RtlUnwind
 0x4991fc RaiseException
 0x499200 GetStdHandle
user32.dll
 0x499208 GetKeyboardType
 0x49920c LoadStringA
 0x499210 MessageBoxA
 0x499214 CharNextA
advapi32.dll
 0x49921c RegQueryValueExA
 0x499220 RegOpenKeyExA
 0x499224 RegCloseKey
oleaut32.dll
 0x49922c SysFreeString
 0x499230 SysReAllocStringLen
 0x499234 SysAllocStringLen
kernel32.dll
 0x49923c TlsSetValue
 0x499240 TlsGetValue
 0x499244 LocalAlloc
 0x499248 GetModuleHandleA
advapi32.dll
 0x499250 RegQueryValueExA
 0x499254 RegOpenKeyExA
 0x499258 RegCloseKey
kernel32.dll
 0x499260 lstrcpyA
 0x499264 lstrcmpiA
 0x499268 WriteFile
 0x49926c WaitForSingleObject
 0x499270 VirtualQuery
 0x499274 VirtualProtect
 0x499278 VirtualAlloc
 0x49927c Sleep
 0x499280 SizeofResource
 0x499284 SetThreadLocale
 0x499288 SetFilePointer
 0x49928c SetEvent
 0x499290 SetErrorMode
 0x499294 SetEndOfFile
 0x499298 ResetEvent
 0x49929c ReadFile
 0x4992a0 MulDiv
 0x4992a4 LockResource
 0x4992a8 LoadResource
 0x4992ac LoadLibraryW
 0x4992b0 LoadLibraryA
 0x4992b4 LeaveCriticalSection
 0x4992b8 InitializeCriticalSection
 0x4992bc GlobalUnlock
 0x4992c0 GlobalReAlloc
 0x4992c4 GlobalHandle
 0x4992c8 GlobalLock
 0x4992cc GlobalFree
 0x4992d0 GlobalFindAtomA
 0x4992d4 GlobalDeleteAtom
 0x4992d8 GlobalAlloc
 0x4992dc GlobalAddAtomA
 0x4992e0 GetVersionExA
 0x4992e4 GetVersion
 0x4992e8 GetTickCount
 0x4992ec GetThreadLocale
 0x4992f0 GetSystemInfo
 0x4992f4 GetStringTypeExA
 0x4992f8 GetStdHandle
 0x4992fc GetProfileStringA
 0x499300 GetProcAddress
 0x499304 GetModuleHandleA
 0x499308 GetModuleFileNameA
 0x49930c GetLocaleInfoA
 0x499310 GetLocalTime
 0x499314 GetLastError
 0x499318 GetFullPathNameA
 0x49931c GetDiskFreeSpaceA
 0x499320 GetDateFormatA
 0x499324 GetCurrentThreadId
 0x499328 GetCurrentProcessId
 0x49932c GetCPInfo
 0x499330 GetACP
 0x499334 FreeResource
 0x499338 InterlockedExchange
 0x49933c FreeLibrary
 0x499340 FormatMessageA
 0x499344 FindResourceA
 0x499348 FindFirstFileA
 0x49934c FindClose
 0x499350 FileTimeToLocalFileTime
 0x499354 FileTimeToDosDateTime
 0x499358 EnumCalendarInfoA
 0x49935c EnterCriticalSection
 0x499360 DeleteFileA
 0x499364 DeleteCriticalSection
 0x499368 CreateThread
 0x49936c CreateFileA
 0x499370 CreateEventA
 0x499374 CompareStringA
 0x499378 CloseHandle
version.dll
 0x499380 VerQueryValueA
 0x499384 GetFileVersionInfoSizeA
 0x499388 GetFileVersionInfoA
gdi32.dll
 0x499390 UnrealizeObject
 0x499394 StretchBlt
 0x499398 StartPage
 0x49939c StartDocA
 0x4993a0 SetWindowOrgEx
 0x4993a4 SetWinMetaFileBits
 0x4993a8 SetViewportOrgEx
 0x4993ac SetTextColor
 0x4993b0 SetStretchBltMode
 0x4993b4 SetROP2
 0x4993b8 SetPixel
 0x4993bc SetMapMode
 0x4993c0 SetEnhMetaFileBits
 0x4993c4 SetDIBColorTable
 0x4993c8 SetBrushOrgEx
 0x4993cc SetBkMode
 0x4993d0 SetBkColor
 0x4993d4 SetAbortProc
 0x4993d8 SelectPalette
 0x4993dc SelectObject
 0x4993e0 SelectClipRgn
 0x4993e4 SaveDC
 0x4993e8 RestoreDC
 0x4993ec Rectangle
 0x4993f0 RectVisible
 0x4993f4 RealizePalette
 0x4993f8 Polyline
 0x4993fc Polygon
 0x499400 PlayEnhMetaFile
 0x499404 PatBlt
 0x499408 MoveToEx
 0x49940c MaskBlt
 0x499410 LineTo
 0x499414 IntersectClipRect
 0x499418 GetWindowOrgEx
 0x49941c GetWinMetaFileBits
 0x499420 GetTextMetricsA
 0x499424 GetTextExtentPointA
 0x499428 GetTextExtentPoint32A
 0x49942c GetSystemPaletteEntries
 0x499430 GetStockObject
 0x499434 GetPixel
 0x499438 GetPaletteEntries
 0x49943c GetObjectA
 0x499440 GetEnhMetaFilePaletteEntries
 0x499444 GetEnhMetaFileHeader
 0x499448 GetEnhMetaFileBits
 0x49944c GetDeviceCaps
 0x499450 GetDIBits
 0x499454 GetDIBColorTable
 0x499458 GetDCOrgEx
 0x49945c GetCurrentPositionEx
 0x499460 GetClipBox
 0x499464 GetBrushOrgEx
 0x499468 GetBitmapBits
 0x49946c GdiFlush
 0x499470 ExcludeClipRect
 0x499474 EndPage
 0x499478 EndDoc
 0x49947c DeleteObject
 0x499480 DeleteEnhMetaFile
 0x499484 DeleteDC
 0x499488 CreateSolidBrush
 0x49948c CreatePenIndirect
 0x499490 CreatePalette
 0x499494 CreateICA
 0x499498 CreateHalftonePalette
 0x49949c CreateFontIndirectA
 0x4994a0 CreateDIBitmap
 0x4994a4 CreateDIBSection
 0x4994a8 CreateDCA
 0x4994ac CreateCompatibleDC
 0x4994b0 CreateCompatibleBitmap
 0x4994b4 CreateBrushIndirect
 0x4994b8 CreateBitmap
 0x4994bc CopyEnhMetaFileA
 0x4994c0 BitBlt
user32.dll
 0x4994c8 CreateWindowExA
 0x4994cc WindowFromPoint
 0x4994d0 WinHelpA
 0x4994d4 WaitMessage
 0x4994d8 UpdateWindow
 0x4994dc UnregisterClassA
 0x4994e0 UnhookWindowsHookEx
 0x4994e4 TranslateMessage
 0x4994e8 TranslateMDISysAccel
 0x4994ec TrackPopupMenu
 0x4994f0 SystemParametersInfoA
 0x4994f4 ShowWindow
 0x4994f8 ShowScrollBar
 0x4994fc ShowOwnedPopups
 0x499500 ShowCursor
 0x499504 ShowCaret
 0x499508 SetWindowsHookExA
 0x49950c SetWindowTextA
 0x499510 SetWindowPos
 0x499514 SetWindowPlacement
 0x499518 SetWindowLongA
 0x49951c SetTimer
 0x499520 SetScrollRange
 0x499524 SetScrollPos
 0x499528 SetScrollInfo
 0x49952c SetRect
 0x499530 SetPropA
 0x499534 SetParent
 0x499538 SetMenuItemInfoA
 0x49953c SetMenu
 0x499540 SetForegroundWindow
 0x499544 SetFocus
 0x499548 SetCursor
 0x49954c SetClipboardData
 0x499550 SetClassLongA
 0x499554 SetCapture
 0x499558 SetActiveWindow
 0x49955c SendMessageA
 0x499560 ScrollWindow
 0x499564 ScreenToClient
 0x499568 RemovePropA
 0x49956c RemoveMenu
 0x499570 ReleaseDC
 0x499574 ReleaseCapture
 0x499578 RegisterWindowMessageA
 0x49957c RegisterClipboardFormatA
 0x499580 RegisterClassA
 0x499584 RedrawWindow
 0x499588 PtInRect
 0x49958c PostQuitMessage
 0x499590 PostMessageA
 0x499594 PeekMessageA
 0x499598 OpenClipboard
 0x49959c OffsetRect
 0x4995a0 OemToCharA
 0x4995a4 MessageBoxA
 0x4995a8 MessageBeep
 0x4995ac MapWindowPoints
 0x4995b0 MapVirtualKeyA
 0x4995b4 LoadStringA
 0x4995b8 LoadKeyboardLayoutA
 0x4995bc LoadIconA
 0x4995c0 LoadCursorA
 0x4995c4 LoadBitmapA
 0x4995c8 KillTimer
 0x4995cc IsZoomed
 0x4995d0 IsWindowVisible
 0x4995d4 IsWindowEnabled
 0x4995d8 IsWindow
 0x4995dc IsRectEmpty
 0x4995e0 IsIconic
 0x4995e4 IsDialogMessageA
 0x4995e8 IsChild
 0x4995ec InvalidateRect
 0x4995f0 IntersectRect
 0x4995f4 InsertMenuItemA
 0x4995f8 InsertMenuA
 0x4995fc InflateRect
 0x499600 HideCaret
 0x499604 GetWindowThreadProcessId
 0x499608 GetWindowTextA
 0x49960c GetWindowRect
 0x499610 GetWindowPlacement
 0x499614 GetWindowLongA
 0x499618 GetWindowDC
 0x49961c GetUpdateRect
 0x499620 GetTopWindow
 0x499624 GetSystemMetrics
 0x499628 GetSystemMenu
 0x49962c GetSysColorBrush
 0x499630 GetSysColor
 0x499634 GetSubMenu
 0x499638 GetScrollRange
 0x49963c GetScrollPos
 0x499640 GetScrollInfo
 0x499644 GetPropA
 0x499648 GetParent
 0x49964c GetWindow
 0x499650 GetMenuStringA
 0x499654 GetMenuState
 0x499658 GetMenuItemInfoA
 0x49965c GetMenuItemID
 0x499660 GetMenuItemCount
 0x499664 GetMenu
 0x499668 GetLastActivePopup
 0x49966c GetKeyboardState
 0x499670 GetKeyboardLayoutList
 0x499674 GetKeyboardLayout
 0x499678 GetKeyState
 0x49967c GetKeyNameTextA
 0x499680 GetIconInfo
 0x499684 GetForegroundWindow
 0x499688 GetFocus
 0x49968c GetDlgItem
 0x499690 GetDesktopWindow
 0x499694 GetDCEx
 0x499698 GetDC
 0x49969c GetCursorPos
 0x4996a0 GetCursor
 0x4996a4 GetClipboardData
 0x4996a8 GetClientRect
 0x4996ac GetClassNameA
 0x4996b0 GetClassInfoA
 0x4996b4 GetCapture
 0x4996b8 GetActiveWindow
 0x4996bc FrameRect
 0x4996c0 FindWindowA
 0x4996c4 FillRect
 0x4996c8 EqualRect
 0x4996cc EnumWindows
 0x4996d0 EnumThreadWindows
 0x4996d4 EndPaint
 0x4996d8 EnableWindow
 0x4996dc EnableScrollBar
 0x4996e0 EnableMenuItem
 0x4996e4 EmptyClipboard
 0x4996e8 DrawTextA
 0x4996ec DrawStateA
 0x4996f0 DrawMenuBar
 0x4996f4 DrawIconEx
 0x4996f8 DrawIcon
 0x4996fc DrawFrameControl
 0x499700 DrawEdge
 0x499704 DispatchMessageA
 0x499708 DestroyWindow
 0x49970c DestroyMenu
 0x499710 DestroyIcon
 0x499714 DestroyCursor
 0x499718 DeleteMenu
 0x49971c DefWindowProcA
 0x499720 DefMDIChildProcA
 0x499724 DefFrameProcA
 0x499728 CreatePopupMenu
 0x49972c CreateMenu
 0x499730 CreateIcon
 0x499734 CloseClipboard
 0x499738 ClientToScreen
 0x49973c CheckMenuItem
 0x499740 CallWindowProcA
 0x499744 CallNextHookEx
 0x499748 BeginPaint
 0x49974c CharNextA
 0x499750 CharLowerBuffA
 0x499754 CharLowerA
 0x499758 CharUpperBuffA
 0x49975c CharToOemA
 0x499760 AdjustWindowRectEx
 0x499764 ActivateKeyboardLayout
kernel32.dll
 0x49976c Sleep
oleaut32.dll
 0x499774 SafeArrayPtrOfIndex
 0x499778 SafeArrayGetUBound
 0x49977c SafeArrayGetLBound
 0x499780 SafeArrayCreate
 0x499784 VariantChangeType
 0x499788 VariantCopy
 0x49978c VariantClear
 0x499790 VariantInit
comctl32.dll
 0x499798 ImageList_SetIconSize
 0x49979c ImageList_GetIconSize
 0x4997a0 ImageList_Write
 0x4997a4 ImageList_Read
 0x4997a8 ImageList_GetDragImage
 0x4997ac ImageList_DragShowNolock
 0x4997b0 ImageList_SetDragCursorImage
 0x4997b4 ImageList_DragMove
 0x4997b8 ImageList_DragLeave
 0x4997bc ImageList_DragEnter
 0x4997c0 ImageList_EndDrag
 0x4997c4 ImageList_BeginDrag
 0x4997c8 ImageList_Remove
 0x4997cc ImageList_DrawEx
 0x4997d0 ImageList_Replace
 0x4997d4 ImageList_Draw
 0x4997d8 ImageList_GetBkColor
 0x4997dc ImageList_SetBkColor
 0x4997e0 ImageList_ReplaceIcon
 0x4997e4 ImageList_Add
 0x4997e8 ImageList_SetImageCount
 0x4997ec ImageList_GetImageCount
 0x4997f0 ImageList_Destroy
 0x4997f4 ImageList_Create
 0x4997f8 InitCommonControls
winspool.drv
 0x499800 OpenPrinterA
 0x499804 EnumPrintersA
 0x499808 DocumentPropertiesA
 0x49980c ClosePrinter
shell32.dll
 0x499814 ShellExecuteA
comdlg32.dll
 0x49981c GetSaveFileNameA
 0x499820 GetOpenFileNameA
winmm.dll
 0x499828 sndPlaySoundA
rasapi32
 0x499830 RasDialA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure