🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🪟 Windows TippsSetting up live captions stuck in Windows 11(14.09.2026 um 16:31 Uhr)
🕵️ SicherheitslückenBurn Out, Or Fade Away(14.09.2026 um 14:25 Uhr)
🪟 Windows TippsWindows 11's latest update broke my speakers, and I'm not alone(14.09.2026 um 18:54 Uhr)
🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
🪟 Windows TippsSetting up live captions stuck in Windows 11(14.09.2026 um 16:31 Uhr)
🕵️ SicherheitslückenBurn Out, Or Fade Away(14.09.2026 um 14:25 Uhr)
🪟 Windows TippsWindows 11's latest update broke my speakers, and I'm not alone(14.09.2026 um 18:54 Uhr)

⚠️ Malware / Trojaner / Viren 🕛 vor 1 Jahr 9 Min Lesezeit SECURITY-FEED
0

Research that builds detections

↗ Quelle (blog.virustotal.com)
🔬 IoC Intelligence (10 Indikatoren erkannt)
14d886517fff2cc8955844b252c985ab59f2f95b2849002778f03a8f07eb8aefEDB3046610020EE614B5B81B0439895EA731372E6F6978CE25617AE01B143351FCCB961AE76D9E600A558D2D0225ED43466876F453563A272ADB5D568670ECA98D805E7ECAA5A2E18C92B6D3C947DF931460E2E6D7F8ECA4240B7C78FA619D15c9f9f193409217f73cc976ad078c6f8bf65d3aabcf5fad3e5a47536d47aa6761e96a0c1bc5f720d7f0a53f72e5bb424163c943c24a437b1065957a79f5872675+2 weitere
🗣️ Stimme:
📑 Inhaltsübersicht
📺
blog.virustotal.com




Note:
You can view the full content of the blog into VirusTotal, as well as ways in which for SOCs and IRs teams), and we have also shown how those who can use it too.

But there's another really cool way to use VirusTotal - for people who build detections and those who are doing research. We want to show everyone how we use VirusTotal in our work. Hopefully, this will be helpful and also give people ideas for new ways to use it themselves.

To explain our process, we used examples of samples that we found in recent campaigns. These caught our attention due to some behaviors that had not been identified by public detection rules in the community. For that reason we have created two Sigma rules to share with the community, but if you want to get all the details about how we identified it and started our research, go to our repository. This can save time and effort, as well as provide insight into previously observed samples that can be further researched.

A different approach would be to instead look for malicious files that are not detected by existing Sigma rules, since they can uncover novel methodologies and provide new opportunities for detection creation.

One approach is to hunt for files that are flagged by at least five different AV vendors, were recently uploaded within the last month, have sandbox execution (in order to view their behavior), and which have not triggered any Crowdsourced Sigma rules.

p:5+ have:behavior fs:30d+ not have:sigma

This initial query can be adapted to incorporate additional filters that the researcher may find relevant. These could include modifiers to identify for example, the presence of the PowerShell process in the list of executed processes (behavior_created_processes:powershell.exe), filtering results to only include documents (type:document), or identifying communication with services like Pastebin (behavior_network:pastebin.com).

Another way to go is to look at files that have been flagged by at least five AV’s and were tested in either Zenbox or CAPE. These sandboxes often have great logs produced by Sysmon, which are really useful for figuring out how to spot these threats. Again, we'd want to focus on files uploaded in the last month that haven't triggered any Sigma rules. This gives us a good starting point for building new detection rules.

p:5+ (sandbox_name:"CAPE Sandbox" or sandbox_name:"Zenbox") fs:30d+ not have:sigma

Lastly, another idea is to look for files that have not triggered many high severity detections from the Sigma Crowdsourced rules, as these can be more evasive. Specifically, we will look for samples with zero critical, high or medium alerts - and no more than two low severity ones.

p:5+ have:behavior fs:30d+ sigma_critical:0 sigma_high:0 sigma_medium:0 sigma_low:2-

With these queries, we can start investigating some samples that may be interesting to create detection rules.


Our detections for the community


Our approach helps us identify behaviors that seem interesting and worth focusing on.

title: Detect The Execution Of More.com And Vbc.exe Related to Lummac Stealer
id: 19b3806e-46f2-4b4c-9337-e3d8653245ea
status: experimental
description: Detects the execution of more.com and vbc.exe in the process tree. This behaviors was observed by a set of samples related to Lummac Stealer. The Lummac payload is injected into the vbc.exe process.
references:
- https://www.virustotal.com/gui/file/14d886517fff2cc8955844b252c985ab59f2f95b2849002778f03a8f07eb8aef
- https://strontic.github.io/xcyclopedia/library/more.com-EDB3046610020EE614B5B81B0439895E.html
- https://strontic.github.io/xcyclopedia/library/vbc.exe-A731372E6F6978CE25617AE01B143351.html
author: Joseliyo Sanchez, @Joseliyo_Jstnk
date: 2024-11-14
tags:
- attack.defense-evasion
- attack.t1055
logsource:
category: process_creation
product: windows
detection:
# VT Query: behaviour_processes:"C:\\Windows\\SysWOW64\\more.com" behaviour_processes:"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe"
selection_parent:
ParentImage|endswith: '\more.com'
selection_child:
- Image|endswith: '\vbc.exe'
- OriginalFileName: 'vbc.exe'
condition: all of selection_*
falsepositives:
- Unknown
level: high

Sysmon event for: Detect The Execution Of More.com And Vbc.exe Related to Lummac Stealer



{
"System": {
"Provider": {
"Guid": "{5770385F-C22A-43E0-BF4C-06F5698FFBD9}",
"Name": "Microsoft-Windows-Sysmon"
},
"EventID": 1,
"Version": 5,
"Level": 4,
"Task": 1,
"Opcode": 0,
"Keywords": "0x8000000000000000",
"TimeCreated": {
"SystemTime": "2024-11-26T16:23:05.132539500Z"
},
"EventRecordID": 692861,
"Correlation": {},
"Execution": {
"ProcessID": 2396,
"ThreadID": 3116
},
"Channel": "Microsoft-Windows-Sysmon/Operational",
"Computer": "DESKTOP-B0T93D6",
"Security": {
"UserID": "S-1-5-18"
}
},
"EventData": {
"RuleName": "-",
"UtcTime": "2024-11-26 16:23:05.064",
"ProcessGuid": "{C784477D-F5E9-6745-6006-000000003F00}",
"ProcessId": 4184,
"Image": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe",
"FileVersion": "14.8.3761.0",
"Description": "Visual Basic Command Line Compiler",
"Product": "Microsoft® .NET Framework",
"Company": "Microsoft Corporation",
"OriginalFileName": "vbc.exe",
"CommandLine": "C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe",
"CurrentDirectory": "C:\\Users\\george\\AppData\\Roaming\\comlocal\\RUYCLAXYVMFJ\\",
"User": "DESKTOP-B0T93D6\\george",
"LogonGuid": "{C784477D-9D9B-66FF-6E87-050000000000}",
"LogonId": "0x5876e",
"TerminalSessionId": 1,
"IntegrityLevel": "High",
"Hashes": {
"SHA1": "61F4D9A9EE38DBC72E840B3624520CF31A3A8653",
"MD5": "FCCB961AE76D9E600A558D2D0225ED43",
"SHA256": "466876F453563A272ADB5D568670ECA98D805E7ECAA5A2E18C92B6D3C947DF93",
"IMPHASH": "1460E2E6D7F8ECA4240B7C78FA619D15"
},
"ParentProcessGuid": "{C784477D-F5D4-6745-5E06-000000003F00}",
"ParentProcessId": 6572,
"ParentImage": "C:\\Windows\\SysWOW64\\more.com",
"ParentCommandLine": "C:\\Windows\\SysWOW64\\more.com",
"ParentUser": "DESKTOP-B0T93D6\\george"
}
}

File Creation Related To RAT Clients



Sigma rule on GitHub:


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf blog.virustotal.com.
↗ Original-Artikel auf blog.virustotal.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
The Gemini desktop app is now available for Windows
1 Quelle
Setting up live captions stuck in Windows 11
1 Quelle
Burn Out, Or Fade Away
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Research that builds detections

Thematisch verwandte Begriffe: Research, that, builds, detections · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...