Everything starts with a VBS file. It is available on VirusTotal. It is suspicious to have a text file sized 600KB, which already indicates it is a dropper in the first look.
Digging into the file, the first line presents:
code = "==A#>,A#>,A#>,A#>,A#>,A#>,A#>,A#>,A#>,...
Another clue that it is a dropper. Base64 strings often indicate that it is the encoded payload.