Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 32-bit Windows platform, family Egairtigado
This detection identifies Trojan:Win32/Egairtigado, specifically the ValleyRAT remote access trojan, masquerading as "kernel32.exe". This malware establishes a command-and-control connection to 103.121.93.78:8668, granting attackers full remote control over the compromised system via a web download.
No detailed analysis available from definition files.
ffc89638df4301aedb7a018f2bec7f929abe03de04ebfe040d5a53272582e618Immediately isolate the infected system. Delete the malicious "kernel32.exe" file, perform a full system scan with updated antivirus software, and block the C2 IP (103.121.93.78) at the network firewall. Investigate the infection vector and reset all user and administrative credentials on the affected system.