Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 64-bit Windows platform, family GhostRat
This threat is a Remote Access Trojan (RAT) from the GhostRat family, detected by its malicious behavior using machine learning. Its purpose is to grant an attacker covert remote control over the infected system, enabling data theft, surveillance, and further compromise. The detection indicates that the malware was observed performing suspicious actions on the machine.
No specific strings found for this threat
743b0674221a41f64fc52cdb62dc0f9abfeff460ec6c5660ceb2279f7098a0d55383de5956d052794022598d14df4f8ccaf6c278f6d5b8c13dc2ec0ab6b10fe3fd7ba89670c0b89e31619074d75089487012e4492b3319b2c418a6fe2dc22b1e246511b11ac092dad686f3c0b99e6445299f0fb72f379b2d06e8a112e02efb0384aa32d0c5eb678f62ba0c24d6f39ed9b61acf261a89ddaa1fb3d9ca392b1231Isolate the affected host from the network immediately. Use Windows Defender to quarantine and remove the threat. Investigate the system for signs of persistence, data exfiltration, or lateral movement, and consider resetting passwords for any accounts used on the machine.