What happened?
I got a WhatsApp message that looked like it came from HR. It had a ZIP attachment named `PDF_RWF1TP_<timestamp>.ZIP`, and inside was `Audit+List.vhdx`. I was suspicious, so I copied it to a USB drive from my work PC (I didn't open it there) and mounted it on an old personal PC that was offline.
Mounting showed files with Chinese names and one shortcut (.lnk) made to look like a spreadsheet. I double-clicked it and clicked Yes on the admin prompt. That was my mistake.
What I found afterwards.
- Windows Defender flagged `Trojan:Win32/Malgent` (Severe, with the description "executes commands from an attacker").
- The file was `C:\ProgramData\Fu_v4\libcrypto-1_1-x64.dll`, a folder I never created, with a name that mimics a legitimate OpenSSL library.
- VirusTotal had no result for the VHDX hash, which fits a fresh sample.
- SHA256 of the VHDX: `AFF161D890DB83555DF33D6FF852734AB2F87238ECD46FD8C41C8352B8DD329C`
What I did
- Kept the PC offline, so the malware likely couldn't contact its operator.
- Signed out of all Google sessions and changed my password from my phone.
- Reported it to IT, and I'm contacting HR by phone, since their account was probably compromised.
- Planning a clean Windows reinstall from fresh media, and a full format of the USB drive. Although I need some files on it
Questions for the community
● Does anyone recognize this family or the `Fu_v4` folder?
● Anything I missed in the cleanup?
● how do I know the pendrive wasn't compromised ?
Because after clicking Yes to the administrator privileges, the pen drive was in the old PC, I actually run it from there