Lummac Stealer Activity - Execution Of More.com And Vbc.exe — Detection Rule

Detects the execution of more.com and vbc.exe in the process tree. This behavior was observed by a set of samples related to Lummac Stealer. The Lummac payload is injected into the vbc.exe process.

Read the full analysis on IntelFusions