🔧 AI Nachrichten DistroWatch Weekly, Issue 1188(31.08.2026 um 03:21 Uhr)
🐧 Linux TippsDistribution Release: Grml 2026.09(04.09.2026 um 01:39 Uhr)
🔧 ProgrammierungDistribution Release: Talos Linux 1.14.0(04.09.2026 um 11:06 Uhr)
🐧 Linux TippsDistribution Release: Zenwalk GNU Linux Current-260905(05.09.2026 um 22:05 Uhr)
🔧 AI Nachrichten DistroWatch Weekly, Issue 1189(07.09.2026 um 02:18 Uhr)
🐧 Linux TippsSecurity: Denial of Service in grpcurl (Fedora)(12.09.2026 um 00:28 Uhr)
🐧 Linux TippsSecurity: Denial of Service in syncthing (Fedora)(12.09.2026 um 00:28 Uhr)
🐧 Linux TippsSecurity: Mehrere Probleme in darktable (Fedora)(12.09.2026 um 00:28 Uhr)
🐧 Linux TippsSecurity: Mehrere Probleme in kamailio (Debian)(12.09.2026 um 00:28 Uhr)
🔧 AI Nachrichten DistroWatch Weekly, Issue 1188(31.08.2026 um 03:21 Uhr)
🐧 Linux TippsDistribution Release: Grml 2026.09(04.09.2026 um 01:39 Uhr)
🔧 ProgrammierungDistribution Release: Talos Linux 1.14.0(04.09.2026 um 11:06 Uhr)
🐧 Linux TippsDistribution Release: Zenwalk GNU Linux Current-260905(05.09.2026 um 22:05 Uhr)
🔧 AI Nachrichten DistroWatch Weekly, Issue 1189(07.09.2026 um 02:18 Uhr)
🐧 Linux TippsSecurity: Denial of Service in grpcurl (Fedora)(12.09.2026 um 00:28 Uhr)
🐧 Linux TippsSecurity: Denial of Service in syncthing (Fedora)(12.09.2026 um 00:28 Uhr)
🐧 Linux TippsSecurity: Mehrere Probleme in darktable (Fedora)(12.09.2026 um 00:28 Uhr)
🐧 Linux TippsSecurity: Mehrere Probleme in kamailio (Debian)(12.09.2026 um 00:28 Uhr)

⚠️ Malware / Trojaner / Viren 🕛 vor 1 Jahr 9 Min Lesezeit SECURITY-FEED
0

Research that builds detections

↗ Quelle (blog.virustotal.com)
🔬 IoC Intelligence (10 Indikatoren erkannt)
14d886517fff2cc8955844b252c985ab59f2f95b2849002778f03a8f07eb8aefEDB3046610020EE614B5B81B0439895EA731372E6F6978CE25617AE01B143351FCCB961AE76D9E600A558D2D0225ED43466876F453563A272ADB5D568670ECA98D805E7ECAA5A2E18C92B6D3C947DF931460E2E6D7F8ECA4240B7C78FA619D15c9f9f193409217f73cc976ad078c6f8bf65d3aabcf5fad3e5a47536d47aa6761e96a0c1bc5f720d7f0a53f72e5bb424163c943c24a437b1065957a79f5872675+2 weitere
🗣️ Stimme:
📑 Inhaltsübersicht
📺
blog.virustotal.com




Note:
You can view the full content of the blog into VirusTotal, as well as ways in which for SOCs and IRs teams), and we have also shown how those who can use it too.

But there's another really cool way to use VirusTotal - for people who build detections and those who are doing research. We want to show everyone how we use VirusTotal in our work. Hopefully, this will be helpful and also give people ideas for new ways to use it themselves.

To explain our process, we used examples of samples that we found in recent campaigns. These caught our attention due to some behaviors that had not been identified by public detection rules in the community. For that reason we have created two Sigma rules to share with the community, but if you want to get all the details about how we identified it and started our research, go to our repository. This can save time and effort, as well as provide insight into previously observed samples that can be further researched.

A different approach would be to instead look for malicious files that are not detected by existing Sigma rules, since they can uncover novel methodologies and provide new opportunities for detection creation.

One approach is to hunt for files that are flagged by at least five different AV vendors, were recently uploaded within the last month, have sandbox execution (in order to view their behavior), and which have not triggered any Crowdsourced Sigma rules.

p:5+ have:behavior fs:30d+ not have:sigma

This initial query can be adapted to incorporate additional filters that the researcher may find relevant. These could include modifiers to identify for example, the presence of the PowerShell process in the list of executed processes (behavior_created_processes:powershell.exe), filtering results to only include documents (type:document), or identifying communication with services like Pastebin (behavior_network:pastebin.com).

Another way to go is to look at files that have been flagged by at least five AV’s and were tested in either Zenbox or CAPE. These sandboxes often have great logs produced by Sysmon, which are really useful for figuring out how to spot these threats. Again, we'd want to focus on files uploaded in the last month that haven't triggered any Sigma rules. This gives us a good starting point for building new detection rules.

p:5+ (sandbox_name:"CAPE Sandbox" or sandbox_name:"Zenbox") fs:30d+ not have:sigma

Lastly, another idea is to look for files that have not triggered many high severity detections from the Sigma Crowdsourced rules, as these can be more evasive. Specifically, we will look for samples with zero critical, high or medium alerts - and no more than two low severity ones.

p:5+ have:behavior fs:30d+ sigma_critical:0 sigma_high:0 sigma_medium:0 sigma_low:2-

With these queries, we can start investigating some samples that may be interesting to create detection rules.


Our detections for the community


Our approach helps us identify behaviors that seem interesting and worth focusing on.

title: Detect The Execution Of More.com And Vbc.exe Related to Lummac Stealer
id: 19b3806e-46f2-4b4c-9337-e3d8653245ea
status: experimental
description: Detects the execution of more.com and vbc.exe in the process tree. This behaviors was observed by a set of samples related to Lummac Stealer. The Lummac payload is injected into the vbc.exe process.
references:
- https://www.virustotal.com/gui/file/14d886517fff2cc8955844b252c985ab59f2f95b2849002778f03a8f07eb8aef
- https://strontic.github.io/xcyclopedia/library/more.com-EDB3046610020EE614B5B81B0439895E.html
- https://strontic.github.io/xcyclopedia/library/vbc.exe-A731372E6F6978CE25617AE01B143351.html
author: Joseliyo Sanchez, @Joseliyo_Jstnk
date: 2024-11-14
tags:
- attack.defense-evasion
- attack.t1055
logsource:
category: process_creation
product: windows
detection:
# VT Query: behaviour_processes:"C:\\Windows\\SysWOW64\\more.com" behaviour_processes:"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe"
selection_parent:
ParentImage|endswith: '\more.com'
selection_child:
- Image|endswith: '\vbc.exe'
- OriginalFileName: 'vbc.exe'
condition: all of selection_*
falsepositives:
- Unknown
level: high

Sysmon event for: Detect The Execution Of More.com And Vbc.exe Related to Lummac Stealer



{
"System": {
"Provider": {
"Guid": "{5770385F-C22A-43E0-BF4C-06F5698FFBD9}",
"Name": "Microsoft-Windows-Sysmon"
},
"EventID": 1,
"Version": 5,
"Level": 4,
"Task": 1,
"Opcode": 0,
"Keywords": "0x8000000000000000",
"TimeCreated": {
"SystemTime": "2024-11-26T16:23:05.132539500Z"
},
"EventRecordID": 692861,
"Correlation": {},
"Execution": {
"ProcessID": 2396,
"ThreadID": 3116
},
"Channel": "Microsoft-Windows-Sysmon/Operational",
"Computer": "DESKTOP-B0T93D6",
"Security": {
"UserID": "S-1-5-18"
}
},
"EventData": {
"RuleName": "-",
"UtcTime": "2024-11-26 16:23:05.064",
"ProcessGuid": "{C784477D-F5E9-6745-6006-000000003F00}",
"ProcessId": 4184,
"Image": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe",
"FileVersion": "14.8.3761.0",
"Description": "Visual Basic Command Line Compiler",
"Product": "Microsoft® .NET Framework",
"Company": "Microsoft Corporation",
"OriginalFileName": "vbc.exe",
"CommandLine": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe",
"CurrentDirectory": "C:\\Users\\george\\AppData\\Roaming\\comlocal\\RUYCLAXYVMFJ\\",
"User": "DESKTOP-B0T93D6\\george",
"LogonGuid": "{C784477D-9D9B-66FF-6E87-050000000000}",
"LogonId": "0x5876e",
"TerminalSessionId": 1,
"IntegrityLevel": "High",
"Hashes": {
"SHA1": "61F4D9A9EE38DBC72E840B3624520CF31A3A8653",
"MD5": "FCCB961AE76D9E600A558D2D0225ED43",
"SHA256": "466876F453563A272ADB5D568670ECA98D805E7ECAA5A2E18C92B6D3C947DF93",
"IMPHASH": "1460E2E6D7F8ECA4240B7C78FA619D15"
},
"ParentProcessGuid": "{C784477D-F5D4-6745-5E06-000000003F00}",
"ParentProcessId": 6572,
"ParentImage": "C:\\Windows\\SysWOW64\\more.com",
"ParentCommandLine": "C:\\Windows\\SysWOW64\\more.com",
"ParentUser": "DESKTOP-B0T93D6\\george"
}
}

File Creation Related To RAT Clients



Sigma rule on GitHub:


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf blog.virustotal.com.
↗ Original-Artikel auf blog.virustotal.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
7 Quellen
Künstliche Intelligenz: USA und China planen angeblich Gespräche über KI-Sicherheit
1 Quelle
GPT-6 Astra vs Claude Fable 5.1: Der große Wettlauf um die stärkste KI – gegen alle Bedenken
1 Quelle
Windows 11: Microsoft streicht kurzfristig lokale PC-zu-PC-Migration in Windows Backup
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Research that builds detections

Thematisch verwandte Begriffe: Research, that, builds, detections · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...