Concrete signature match: Trojan - Appears legitimate but performs malicious actions for PowerShell platform, family Powdow
This detection indicates a Trojan from the Powdow family attempting to execute malicious PowerShell scripts, identified through Windows Defender's machine learning behavioral analysis (!MTB). Trojans typically aim to gain unauthorized access, steal data, or establish persistence, and this particular variant uses PowerShell for its activities.
No specific strings found for this threat
c40317bafe39ec13bd944009bd6c53e6db8430c488433fdace6a3527b26588bb021a02dbe5a2258713659732552c3bbbb243c2ca1c07b18b2c46b47d4d40bbedIsolate the affected host, perform a full system scan with updated antivirus, and investigate the source of the PowerShell execution. Review system logs for further indicators of compromise and ensure all systems are patched and configured securely.