Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 32-bit Windows platform, family CastleRat
Trojan:Win32/CastleRat.ACL!MTB is a confirmed Remote Access Trojan (RAT) capable of providing an attacker with unauthorized remote control and data exfiltration capabilities. This highly confident detection leverages both concrete signature matching and machine learning behavioral analysis.
No detailed analysis available from definition files.
7a183d113322a729e73344460bac8e87a2d72f83d30980566c8d2f99eb576d01Immediately isolate the infected system, perform a full system scan with updated antivirus software, and remove all detected malicious components. Update operating system and applications, and reset any potentially compromised credentials.