Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 64-bit Windows platform, family Nanodump
This is a concrete detection of Trojan:Win64/Nanodump.ANO!MTB, a malicious program from the Nanodump family, identified via machine learning behavioral analysis. This Trojan is designed to dump process memory, particularly sensitive processes like LSASS, to extract user credentials. Its presence indicates an active attempt to compromise system security for potential lateral movement and privilege escalation.
No detailed analysis available from definition files.
8a5795bee788ef228b1b5f3b94449a26eb708e2e345faf5dab29b894d73bf66eImmediately isolate the affected system from the network. Perform a full, in-depth scan with updated antivirus/EDR software to ensure complete removal of the threat and any related artifacts. Investigate for signs of credential theft, lateral movement, or other compromise, and rotate any potentially compromised credentials.