Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 32-bit Windows platform, family Ravartar
This threat is a Trojan from the Ravartar family, delivered as a RAR archive via email attachment. It functions as a loader (donutloader) for AgentTesla, a potent information-stealing malware designed to exfiltrate sensitive data from the infected system.
No detailed analysis available from definition files.
d43c8476acb00d80f509248b65613957c2a4277c8cb443c4705e569f5753943b0b2a7a69a665ac168ce03806ce62e311487b9e2b54c63777550af7d92dcd1e0a7e663929cb61b753b476ca4a29b3e0b04399846ce9bcf9d697c0d6b28c5fe53fb092219f779c34c8e14df01c3270b2efbc050e12cc44684a97059dc346b53b89815474181729abbb340095d4b7a9a0e5b10858e6ab1d429dd0d6633646b8d49bImmediately isolate the affected endpoint and ensure the detected Trojan is quarantined/removed. Force password resets for all accounts used on the compromised machine, especially email and critical business accounts. Conduct a full system scan and perform thorough threat hunting for any signs of persistence or further compromise. Reinforce email security policies and user awareness training to prevent future social engineering attacks.