Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family Lazy
Trojan:MSIL/Lazy.GPBX!MTB is a malicious .NET executable detected using machine learning behavioral analysis. It is classified as part of the 'Lazy' family, indicating potential for unwanted or harmful actions on the system.
No specific strings found for this threat
rule Trojan_MSIL_Lazy_GPBX_2147912800_0
{
meta:
author = "threatcheck.sh"
detection_name = "Trojan:MSIL/Lazy.GPBX!MTB"
threat_id = "2147912800"
type = "Trojan"
platform = "MSIL: .NET intermediate language scripts"
family = "Lazy"
severity = "Critical"
info = "MTB: Microsoft Threat Behavior"
signature_type = "SIGNATURE_TYPE_PEHSTR_EXT"
threshold = "1"
strings_accuracy = "Low"
strings:
$x_1_1 = {fe 01 39 24 00 00 00 00 00 23 00 [0-16] c1 23 00 00 [0-18] 28 ?? 00 00 0a fe} //weight: 1, accuracy: Low
condition:
(filesize < 20MB) and
(all of ($x*))
}b405513249de55aa8da7e970475fd42c0057f6cc1a8b91c04ff38b59a18ae9ca297dc0ceca30c0746b01354486eae850a8359f1a20483c69a54686d1464947991f7fc48f3a67f98551503e2370375849884c2ceddf290423f794d137fad186d5c2787aaf09af7973cf3307a2984cf8e8b79cfa196baab7ffecb6ed365c2ff90086f697c2c9f941a7caa7336879a42b61fe8ddd8a5d210bdac6d624104ad48907Quarantine and remove the detected file. Conduct a full system scan with updated antivirus software to identify and remove any related malware.