nobody say about payload, only installer, dropper, mbr and etc boring things, what is payload this malware? is it only downloader?
A forum for reverse engineering, OS internals and malware analysis
ikolor wrote:next..resources.rar is a GbpBoot (alias Urelas) bootkit data (in your post https://www.virustotal.com/en/file/5bf7 ... 467459457/ is MBR file).
https://www.virustotal.com/en/file/c127 ... 467457618/
https://www.virustotal.com/en/file/5bf7 ... 467459457/