Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family Lazy
Trojan:MSIL/Lazy.GPBX!MTB is a malicious .NET executable detected using machine learning behavioral analysis. It is classified as part of the 'Lazy' family, indicating potential for unwanted or harmful actions on the system.
No specific strings found for this threat
rule Trojan_MSIL_Lazy_GPBX_2147912800_0
{
meta:
author = "threatcheck.sh"
detection_name = "Trojan:MSIL/Lazy.GPBX!MTB"
threat_id = "2147912800"
type = "Trojan"
platform = "MSIL: .NET intermediate language scripts"
family = "Lazy"
severity = "Critical"
info = "MTB: Microsoft Threat Behavior"
signature_type = "SIGNATURE_TYPE_PEHSTR_EXT"
threshold = "1"
strings_accuracy = "Low"
strings:
$x_1_1 = {fe 01 39 24 00 00 00 00 00 23 00 [0-16] c1 23 00 00 [0-18] 28 ?? 00 00 0a fe} //weight: 1, accuracy: Low
condition:
(filesize < 20MB) and
(all of ($x*))
}71090a6478f4eb6ac24f138a6401c848245ee9388fdf33abdf0ef29377200b6617c3ca5eeae6f48af796f5a6c3925d5f08ca18489a40980228080089be453db053d2caf655411502709eabbe29b017f9e2ee684f61deeeb4b0f3a56c6bdad26c48cb351586972d880f7b8316ad4c0872cb88a7411943465f565eb526dbd7dc10044d8e41acb7ef6ad30c8e74f48044d7811d2d8110f088f281ebc697525b3b48Quarantine and remove the detected file. Conduct a full system scan with updated antivirus software to identify and remove any related malware.