RunOnce persistence pointing to vlc.exe in Temp\8bfa
Detects the creation of a registry RunOnce key pointing to an executable named 'vlc.exe' located within a user's temporary directory. This pattern is commonly associated with persistence mechanisms where malware masquerades as a legitimate application to gain execution upon user login.
Sigma

