Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family Darkcloud
Trojan:MSIL/Darkcloud.ZSK!MTB is a .NET-based information-stealing trojan. It is designed to steal a wide range of sensitive data, including cryptocurrency wallets, browser credentials, and application session tokens, and exfiltrate it to a remote command-and-control server.
No detailed analysis available from definition files.
8ebd003e1a80ebe1ca3d678c0d308ea45c060c2eeda6771dffe4e3772a1cfd61Immediately isolate the host from the network to prevent further data exfiltration. Use antivirus to remove the threat, then reset all passwords for accounts stored in web browsers and other compromised applications. Assume all local cryptocurrency wallets are compromised.