Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 32-bit Windows platform, family Ravartar
This threat is a Trojan from the Ravartar family, delivered as a RAR archive via email attachment. It functions as a loader (donutloader) for AgentTesla, a potent information-stealing malware designed to exfiltrate sensitive data from the infected system.
No detailed analysis available from definition files.
66fe407a08c51640c36597405014dee573df8489eeb218c741767e133692a4ed0b79b2b8d06abba2c98afe52f08bd6603d48905ceebd88b415e3545a5b3d42e78c7349c0607fba5e9a1d4b0183265e54f81d050b02d670a551c0a89601300991d91d2ac9fd07419f0c502f17e30adc89507a78118aceff3e756aa52ebcd1397afdd96aba675606113ee424eb6c31f8dc47d9afbb0e83e8bebcb6299f2fa35cceImmediately isolate the affected endpoint and ensure the detected Trojan is quarantined/removed. Force password resets for all accounts used on the compromised machine, especially email and critical business accounts. Conduct a full system scan and perform thorough threat hunting for any signs of persistence or further compromise. Reinforce email security policies and user awareness training to prevent future social engineering attacks.