Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 32-bit Windows platform, family Meterpreter
This threat is the Meterpreter payload, a core component of the Metasploit Framework. It provides an attacker with full remote control over the compromised system, enabling data theft, privilege escalation, and lateral movement within the network. The detection was triggered by a machine learning model observing behaviors characteristic of an active Meterpreter session.
No specific strings found for this threat
rule Trojan_Win32_Meterpreter_RPZ_2147897077_0
{
meta:
author = "threatcheck.sh"
detection_name = "Trojan:Win32/Meterpreter.RPZ!MTB"
threat_id = "2147897077"
type = "Trojan"
platform = "Win32: Windows 32-bit platform"
family = "Meterpreter"
severity = "Critical"
info = "MTB: Microsoft Threat Behavior"
signature_type = "SIGNATURE_TYPE_PEHSTR_EXT"
threshold = "1"
strings_accuracy = "High"
strings:
$x_1_1 = {5b 5b 61 59 5a 51 ff e0 58 5f 5a 8b 12 e9} //weight: 1, accuracy: High
condition:
(filesize < 20MB) and
(all of ($x*))
}49da2afba7c87307eea000e281084e14ed6b0d460686bd193cfde8aab44c1893934671323bc0719346edb90b9de8dc95eca30a38ed3789629589f1010b112aa72dff71491616990e3a350ba7c1128ccfee9fa9826cfaaf92f62e1051ac63e46f1. Immediately isolate the affected host from the network to prevent further compromise. 2. Investigate for persistence mechanisms and signs of lateral movement. 3. Re-image the system from a known-good source and reset all associated user credentials.