Suspicious vbc.exe Spawned by Installer Process

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-13
Updated
2026-09-13

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the Visual Basic compiler vbc.exe being launched by a Setup or installer process, the injection host behavior of malware spread through cracked-software YouTube lures. Attackers hollow vbc.exe to run beaconing code that persists after the installer exits. A compiler binary spawned by an installer and used as a network beacon host is highly anomalous.

Related detections9 linkedT1055 — drag to rearrange
Suspicious n8n Campaign RMM Installer Masquerading as OneDrive Document
Suspicious NFe-Themed Brazilian Lure Executable Execution
Suspicious Office Application Spawning Script Or Shell Interpreter
Suspicious Network Connection From wabmig.exe (Turian Injection)
Suspicious Outbound Network Connection from Explorer Process
Suspicious Executable Dropped in Public Users Directory Named Ctrlpanel (via file_event)
Suspicious AppLaunch.exe Spawned As Injection Target (via process_creation)
Suspicious BugSleep Marker File in Public Directory
Suspicious Interlock Fake Updater Executable Execution
Suspicious vbc.exe Spawned by Installer Process
Pivot detection · T1055 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.