Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 32-bit Windows platform, family Blihan
Trojan:Win32/Blihan!rfn is a concrete detection of a malicious program designed to gain unauthorized access or perform harmful activities on a Windows system. It establishes persistence by modifying the Software\Microsoft\Windows\CurrentVersion\Run registry key, ensuring it launches automatically with Windows.
Relevant strings associated with this threat: - Software\Microsoft\Windows\CurrentVersion\Run (PEHSTR_EXT)
1a71a76509524a9b10ea75864e8e6887a31532767c4480dfa46bcfe2078f9767fef05f1c1f99ea11792df83a17d5cfe0f28ae3def6331bd98b3c7675489e12a8Immediately isolate the infected system from the network. Run a full scan with Windows Defender to quarantine and remove detected files. After removal, verify the Software\Microsoft\Windows\CurrentVersion\Run registry key for any remaining malicious entries and ensure all system updates are applied.