Concrete signature match: Trojan - Appears legitimate but performs malicious actions for Batch Script platform, family QuasarRAT
This threat is a batch script used to deploy QuasarRAT, a powerful open-source Remote Access Trojan (RAT). Once executed, QuasarRAT provides an attacker with complete remote control over the infected system, enabling data theft, surveillance, and further malicious activities. The detection is based on machine learning behavioral analysis, indicating suspicious script activity.
No detailed analysis available from definition files.
e2234446c1cecf5b5c5d1a1f81b37310aff066dfb4aa12df0c6c8138b8abb752Isolate the affected machine from the network. Use Windows Defender to perform a full scan and remove the threat. Investigate the source of the infection and check for persistence mechanisms. Change all user passwords associated with the compromised system.