Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family Lazy
Trojan:MSIL/Lazy.GPBX!MTB is a malicious .NET executable detected using machine learning behavioral analysis. It is classified as part of the 'Lazy' family, indicating potential for unwanted or harmful actions on the system.
No specific strings found for this threat
rule Trojan_MSIL_Lazy_GPBX_2147912800_0
{
meta:
author = "threatcheck.sh"
detection_name = "Trojan:MSIL/Lazy.GPBX!MTB"
threat_id = "2147912800"
type = "Trojan"
platform = "MSIL: .NET intermediate language scripts"
family = "Lazy"
severity = "Critical"
info = "MTB: Microsoft Threat Behavior"
signature_type = "SIGNATURE_TYPE_PEHSTR_EXT"
threshold = "1"
strings_accuracy = "Low"
strings:
$x_1_1 = {fe 01 39 24 00 00 00 00 00 23 00 [0-16] c1 23 00 00 [0-18] 28 ?? 00 00 0a fe} //weight: 1, accuracy: Low
condition:
(filesize < 20MB) and
(all of ($x*))
}297dc0ceca30c0746b01354486eae850a8359f1a20483c69a54686d1464947991f7fc48f3a67f98551503e2370375849884c2ceddf290423f794d137fad186d5c2787aaf09af7973cf3307a2984cf8e8b79cfa196baab7ffecb6ed365c2ff90086f697c2c9f941a7caa7336879a42b61fe8ddd8a5d210bdac6d624104ad4890747a9b1d333be590277d0dbcfbd1146fd18f37870150de5bd7c277434fb64abacQuarantine and remove the detected file. Conduct a full system scan with updated antivirus software to identify and remove any related malware.