Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family Coins
This threat is a Trojan downloader from the 'Coins' malware family, which is associated with cryptocurrency theft or unauthorized mining. It uses PowerShell to download and execute additional malicious payloads from a remote server, hiding its activity from the user.
No detailed analysis available from definition files.
b8bc4a9c9cd869b0186a1477cfcab4576dfafb58995308c1e979ad3cc00c60f2Isolate the affected machine from the network. Use your security software to remove the threat and perform a full system scan. Investigate for persistence mechanisms, such as new scheduled tasks or startup entries, and reset passwords for any user accounts on the machine.