Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 64-bit Windows platform, family Reflo
This is a concrete detection of Trojan:Win64/Reflo!pz, a sophisticated CoinMiner malware delivered by the Amadey botnet. It leverages rootkit capabilities like reflective DLL injection and API hooking for stealth and persistence, alongside various Windows utilities for execution and maintaining its presence.
Relevant strings associated with this threat: - ?ReflectiveDllMain@@YAHPEAE@Z (PEHSTR_EXT) - \CRYPTOCOIN\rootkit\r77-rootkit-master_1.3.0\r77-rootkit-master\vs\x64\Release\r77-x64.pdb (PEHSTR_EXT) - !#HSTR:StringCodeForMshta.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.C!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.L!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.O!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRegsvr32.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRundll32.A!pli (PEHSTR_EXT) - rundll32 (PEHSTR_EXT) - !#HSTR:StringCodeForBITSJobs.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForPowerShell.G!pli (PEHSTR_EXT) - !#HSTR:StringCodeForScheduledTask.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForDataEncoding.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.J!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.K!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteFileCopy.B!pli (PEHSTR_EXT) - !#HSTR:StringCodeForFileDeletion.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.M!pli (PEHSTR_EXT) - !#HSTR:StringCodeForNetshHelperDLL.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteServices.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForSoftwarePacking.C!pli (PEHSTR_EXT)
5187e5216ddf0f63d74a69f483c9568d0b04f7ae67dd17ed1d7644b97ce3a8d18fc455e31efe2cbb2ccffb27169f67e54d2535ecc71aa070f0d26817d0aca480c4fabfcf75a6745956013a61656e620c485d9f39b286b4c7e3b099fe1bba652ad1518d0bd89529e64e3e4e8a433b988c99334b2c3ebdbdf85de312addaa8bbbfae6e65d00f1bb515ff1fb8f049afc360161fa38260e0bf1329c2dde072d70a67Immediately isolate the infected host, perform a full deep scan with updated security software, and investigate for and remove all persistence mechanisms including scheduled tasks and modified system utilities. Block the associated command-and-control IP (62.60.226.140) at the network perimeter and consider re-imaging the system due to the presence of rootkit components.