Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family RemcosRAT
This detection identifies RemcosRAT, a commercial Remote Access Trojan (RAT) that allows an attacker to gain complete control over an infected system. It can be used for data theft, espionage via keylogging and screen capture, and remote command execution. The '!MTB' suffix indicates this detection was made by a machine learning model based on the file's malicious behavior.
No detailed analysis available from definition files.
c657d5a1069f9aacf50a01f859e4301761337d5e45601278597ec5f3cd1c8e3aImmediately isolate the affected system from the network to sever attacker access. Use Windows Defender or another endpoint security tool to perform a full scan and remove all related components. Investigate the initial access vector and reset all user credentials that were used or stored on the machine.