Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family QuasarRat
This is a detection for QuasarRat, a well-known open-source Remote Access Trojan (RAT). It grants an attacker full remote control over the infected system, allowing for data theft, surveillance, and command execution. The !MTB suffix indicates this was identified through machine learning-based behavioral analysis rather than a static signature.
No detailed analysis available from definition files.
6475a67a8117925b5ddf98899466ed0a818040eed7ffa6bf4795059116b9f5d7Immediately isolate the affected host from the network. Run a full antivirus scan to remove the threat. Investigate for persistence mechanisms, reset all user passwords on the machine, and consider reimaging the device as the extent of compromise is likely unknown.