Concrete signature match: Trojan - Appears legitimate but performs malicious actions for PowerShell platform, family Boxter
This threat is a PowerShell-based Trojan from the Boxter family, detected by machine learning based on its malicious behavior. Trojans in this family typically act as downloaders, creating a backdoor to fetch and execute additional malware. The use of PowerShell is a 'living-off-the-land' technique intended to evade traditional, signature-based security.
No specific strings found for this threat
24a5f8a5d6e8068b3fd39e237fa58085b773df193fc5ef71529de0eb248c480eIsolate the affected host from the network immediately. Use security software to quarantine or remove the threat. Review PowerShell execution logs, scheduled tasks, and other persistence mechanisms for related malicious activity, then perform a full system scan.