Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 32-bit Windows platform, family Pomal
Trojan:Win32/Pomal!rfn is a sophisticated Trojan capable of executing malicious code via Windows utilities like mshta, rundll32, and PowerShell, establishing persistence through scheduled tasks and BITS jobs. It employs various techniques including API hooking, data encoding, and network configuration manipulation, with capabilities for remote file operations and file deletion.
Relevant strings associated with this threat: - !#HSTR:StringCodeForMshta.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.C!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.L!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.O!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRegsvr32.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRundll32.A!pli (PEHSTR_EXT) - rundll32 (PEHSTR_EXT) - !#HSTR:StringCodeForBITSJobs.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForPowerShell.G!pli (PEHSTR_EXT) - !#HSTR:StringCodeForScheduledTask.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForDataEncoding.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.J!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.K!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteFileCopy.B!pli (PEHSTR_EXT) - !#HSTR:ExecutionGuardrails (PEHSTR_EXT) - !#HSTR:StringCodeForFileDeletion.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.M!pli (PEHSTR_EXT) - !#HSTR:StringCodeForNetshHelperDLL.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteServices.A!pli (PEHSTR_EXT)
fe139f5e79bb85516fb7405e8a92f0a9465bb06ca1d7fd623d45ff162e2a94608a515a3baf6b12e0d7e99fc037583fe4a2b8a3926dd1dc2effa59e5faf0fb1213bf99e77f24c2b7e4702388f4db9e98a6ffcce7581d496200bc088c8454e7447e7927e965cdf13f433a7b1273c208c57fbaaa678957d45dd89ea4a657f533512a018712ed88611c53cbd487acaf9bf6220a25546a4995bf9fe7ad92c99054fb1Immediately isolate affected systems, remove the detected malware, and perform a full system scan. Investigate for initial access, lateral movement, and ensure all systems are patched and security software is updated.