Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family LibeRAT
This threat is a Remote Access Trojan (RAT) from the LibeRAT malware family, built on the .NET platform. It is designed to give an attacker remote control over the infected system, enabling data theft, surveillance, and further compromise. The detection was based on malicious behaviors identified by a machine learning model, not a static signature.
No specific strings found for this threat
201136e11845281a5fe445cfc9bfa95385dc8b06fc63b5a15cf2f3f4540ee259Allow Windows Defender to remove the threat and run a full system scan. Investigate the entry point (e.g., suspicious email/download) and delete it. Since this is a RAT, immediately reset passwords for all critical accounts used on the machine and check for persistence mechanisms.