@vaber
Thanks for the samples. It seems blind copy-paste, when they put most of code that even never called including not used second dll. They sligthly modified Hibiki module, so instead of cmd.exe it start malware dropped to %temp% folder. But failed to understand preparations made early in code and leave them while they are not needed. Lol, awful copy-paste without understanding.
Thanks for the samples. It seems blind copy-paste, when they put most of code that even never called including not used second dll. They sligthly modified Hibiki module, so instead of cmd.exe it start malware dropped to %temp% folder. But failed to understand preparations made early in code and leave them while they are not needed. Lol, awful copy-paste without understanding.
Ring0 - the source of inspiration