Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 32-bit Windows platform, family Casdet
Trojan:Win32/Casdet!rfn is a highly capable Windows 32-bit Trojan leveraging various system utilities like mshta, regsvr32, rundll32, BITS, and PowerShell for execution, persistence, and evasion. It exhibits advanced functionalities including API hooking for monitoring or manipulation, scheduled task creation, remote file operations, and data encoding, indicating a comprehensive and stealthy threat.
Relevant strings associated with this threat: - !#HSTR:StringCodeForMshta.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.C!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.L!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.O!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRegsvr32.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRundll32.A!pli (PEHSTR_EXT) - rundll32 (PEHSTR_EXT) - !#HSTR:StringCodeForBITSJobs.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForPowerShell.G!pli (PEHSTR_EXT) - !#HSTR:StringCodeForScheduledTask.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForDataEncoding.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.J!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.K!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteFileCopy.B!pli (PEHSTR_EXT) - !#HSTR:ExecutionGuardrails (PEHSTR_EXT) - !#HSTR:StringCodeForFileDeletion.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.M!pli (PEHSTR_EXT) - !#HSTR:StringCodeForNetshHelperDLL.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteServices.A!pli (PEHSTR_EXT)
6dca0ea8a52a323b2ae173ef75d7ebb1cc6f909c855e76676a6478b9e40fb861872d8079ab450bfd1417b9128b619f7e9b43291dc7391044dd838f5b7e8dde523878dd5c8eba1e5b53ab2e07e7b5482e95a3fd3e98268bcd7861318bc9902376dc4f25b2247cfdd6fc96848db30a178baa4419a4c854e86e315b465836102d14425bf771c8c9f740b1ae9803dcb4fd45af4d6a6f171fcc72fc7d511095ca82ceImmediately isolate the infected system to prevent further compromise. Perform a full system scan with updated antivirus definitions, remove all detected malicious files, and meticulously check for and remove any persistence mechanisms such as scheduled tasks, startup entries, or modified system configurations. Ensure all operating system and application security patches are up to date and monitor network traffic for suspicious activity.