Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 32-bit Windows platform, family Pomal
Trojan:Win32/Pomal!rfn is a sophisticated Trojan capable of executing malicious code via Windows utilities like mshta, rundll32, and PowerShell, establishing persistence through scheduled tasks and BITS jobs. It employs various techniques including API hooking, data encoding, and network configuration manipulation, with capabilities for remote file operations and file deletion.
Relevant strings associated with this threat: - !#HSTR:StringCodeForMshta.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.C!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.L!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.O!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRegsvr32.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRundll32.A!pli (PEHSTR_EXT) - rundll32 (PEHSTR_EXT) - !#HSTR:StringCodeForBITSJobs.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForPowerShell.G!pli (PEHSTR_EXT) - !#HSTR:StringCodeForScheduledTask.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForDataEncoding.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.J!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.K!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteFileCopy.B!pli (PEHSTR_EXT) - !#HSTR:ExecutionGuardrails (PEHSTR_EXT) - !#HSTR:StringCodeForFileDeletion.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.M!pli (PEHSTR_EXT) - !#HSTR:StringCodeForNetshHelperDLL.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteServices.A!pli (PEHSTR_EXT)
8a515a3baf6b12e0d7e99fc037583fe4a2b8a3926dd1dc2effa59e5faf0fb1213bf99e77f24c2b7e4702388f4db9e98a6ffcce7581d496200bc088c8454e7447e7927e965cdf13f433a7b1273c208c57fbaaa678957d45dd89ea4a657f533512a018712ed88611c53cbd487acaf9bf6220a25546a4995bf9fe7ad92c99054fb1294a44414b420785c5d07bc9ba2f8d182ab5682c0c43bcc3e6eb95667c5ff0fdImmediately isolate affected systems, remove the detected malware, and perform a full system scan. Investigate for initial access, lateral movement, and ensure all systems are patched and security software is updated.