It drops something winrar.exe which renames itself to logon.exe and runs through HKCU\....\Run registry key. Extracted from VBC.exe payload dll attached.
Attachments
pass: malware
(248.74 KiB) Downloaded 38 times
(248.74 KiB) Downloaded 38 times
pass: malware
(414.23 KiB) Downloaded 38 times
(414.23 KiB) Downloaded 38 times
Ring0 - the source of inspiration