Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 32-bit Windows platform, family Phorpiex
This is a concrete detection of Trojan:Win32/Phorpiex, a well-known botnet and spam-spreading malware family. The threat was identified through machine learning behavioral analysis, indicating the presence of malicious behaviors associated with this trojan.
No specific strings found for this threat
rule Trojan_Win32_Phorpiex_RA_2147839148_0
{
meta:
author = "threatcheck.sh"
detection_name = "Trojan:Win32/Phorpiex.RA!MTB"
threat_id = "2147839148"
type = "Trojan"
platform = "Win32: Windows 32-bit platform"
family = "Phorpiex"
severity = "Critical"
info = "MTB: Microsoft Threat Behavior"
signature_type = "SIGNATURE_TYPE_PEHSTR_EXT"
threshold = "1"
strings_accuracy = "Low"
strings:
$x_1_1 = {99 b9 ff 7f 00 00 f7 f9 81 c2 e8 03 00 00 52 e8 ?? ?? ?? ?? 99 b9 ff 7f 00 00 f7 f9 81 c2 e8 03 00 00 52 8d 95 ?? ?? ff ff 52 68 ?? ?? ?? ?? 8d 85 ?? ?? ff ff 50 ff 15} //weight: 1, accuracy: Low
condition:
(filesize < 20MB) and
(all of ($x*))
}bd9f942b1082ef254f72b9b82a04c196a6029c9cf900c034b4657719b191e4a8Immediately isolate the infected system. Perform a full system scan with updated antivirus, remove/quarantine the detected file, and investigate for persistence mechanisms. Ensure all operating systems and software are fully patched and updated.