Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family PureRAT
This is a concrete detection of Trojan:MSIL/PureRAT.SO, a dangerous Remote Access Trojan (RAT) from the PureRAT family. It grants attackers extensive unauthorized control over the compromised system, enabling data theft, surveillance, and further malicious activities. The detection, confirmed by machine learning behavioral analysis, has a low false positive risk.
No detailed analysis available from definition files.
b9eabf9c1e7eda061eb824e4d6eee8dcebfa10e85a45bbfd623c87169c2f7a8eImmediately isolate the affected system from the network. Perform a full system scan with updated antivirus software to remove the threat. Change all credentials used on the compromised system and investigate for persistence mechanisms, lateral movement, or data exfiltration. Consider a full system reimage if complete removal cannot be confirmed.