It drops something winrar.exe which renames itself to logon.exe and runs through HKCU\....\Run registry key. Extracted from VBC.exe payload dll attached.
Attachments
pass: malware
(248.74 KiB) Downloaded 39 times
(248.74 KiB) Downloaded 39 times
pass: malware
(414.23 KiB) Downloaded 39 times
(414.23 KiB) Downloaded 39 times
Ring0 - the source of inspiration