user@threatcheck.sh ~ threat-analysis
bash
$ analyze-threat Trojan:MSIL/PureRAT.SO!MTB
Trojan:MSIL/PureRAT.SO!MTB - Windows Defender threat signature analysis

Trojan:MSIL/PureRAT.SO!MTB - Windows Defender Threat Analysis

$ cat analysis.txt
=== THREAT ANALYSIS REPORT ===
Threat Name: Trojan:MSIL/PureRAT.SO!MTB
Classification:
Type:Trojan
Platform:MSIL
Family:PureRAT
Detection Type:Concrete
Known malware family with identified signatures
Variant:SO
Specific signature variant within the malware family
Suffix:!MTB
Detected via machine learning and behavioral analysis
Detection Method:Behavioral
Confidence:Very High
False-Positive Risk:Low

Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family PureRAT

Summary:

This is a concrete detection of Trojan:MSIL/PureRAT.SO, a dangerous Remote Access Trojan (RAT) from the PureRAT family. It grants attackers extensive unauthorized control over the compromised system, enabling data theft, surveillance, and further malicious activities. The detection, confirmed by machine learning behavioral analysis, has a low false positive risk.

Severity:
High
VDM Static Detection:
No detailed analysis available from definition files.
Known malware which is associated with this threat:
Filename: aff1f5eb09bed6d85dd9a7714c18e9d7.exe
b9eabf9c1e7eda061eb824e4d6eee8dcebfa10e85a45bbfd623c87169c2f7a8e
20/08/2026
Remediation Steps:
Immediately isolate the affected system from the network. Perform a full system scan with updated antivirus software to remove the threat. Change all credentials used on the compromised system and investigate for persistence mechanisms, lateral movement, or data exfiltration. Consider a full system reimage if complete removal cannot be confirmed.
=== END REPORT ===
$ reanalyze-threat
This analysis was last updated on 20/08/2026. Do you want to analyze it again?
$ ls available-commands/
user@threatcheck.sh:~$