Concrete signature match: Virus Tool - Tool used to create or modify malware for 32-bit Windows platform, family Vbinder
VirTool:Win32/Vbinder!pz is a malicious tool designed to bundle and disguise other malware within a single executable file. Upon execution, it drops and runs its hidden payloads, which can use various system utilities like PowerShell and Scheduled Tasks to establish persistence, evade detection, and carry out further malicious activities.
Relevant strings associated with this threat: - ShellExecuteA (PEHSTR) - MSVBVM60.DLL (PEHSTR) - shell32.dll (PEHSTR_EXT) - ShellExecuteA (PEHSTR_EXT) - MSVBVM60.DLL (PEHSTR_EXT) - !#HSTR:StringCodeForMshta.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.C!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.L!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.O!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRegsvr32.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRundll32.A!pli (PEHSTR_EXT) - rundll32 (PEHSTR_EXT) - !#HSTR:StringCodeForBITSJobs.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForPowerShell.G!pli (PEHSTR_EXT) - !#HSTR:StringCodeForScheduledTask.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForDataEncoding.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.J!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.K!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteFileCopy.B!pli (PEHSTR_EXT) - !#HSTR:ExecutionGuardrails (PEHSTR_EXT) - !#HSTR:StringCodeForFileDeletion.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.M!pli (PEHSTR_EXT) - !#HSTR:StringCodeForNetshHelperDLL.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteServices.A!pli (PEHSTR_EXT)
4e57af02f430ffdacb81b8b597b251bac12de9c0703fb5325411dc83ca8d8e11937ab37bf1f1df7bf66f9df7e31d8b10b2114edfdf741f498f2efec5eb13354aImmediately isolate the affected machine from the network. Use Windows Defender or another reputable antivirus tool to perform a full system scan and remove the threat. Investigate for persistence mechanisms such as new scheduled tasks or registry keys, and identify the initial point of entry to prevent reinfection.