Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 64-bit Windows platform, family Rhadamanthys
The detected threat is the Rhadamanthys trojan, a known information stealer. The machine learning model observed it performing system reconnaissance by executing PowerShell commands to gather details about the host, such as user accounts, hardware, and OS version, in preparation for data exfiltration.
No detailed analysis available from definition files.
42a822998ce7c2be43e58dad17d1fcd1675b54f4bb79bbb93522d2442cad80c48c6e8be26b5152a019fd7284429eca10f07ea5c8f0c160748e1fb5f2be2d5e42Isolate the host from the network to prevent further compromise. Perform a full antivirus scan to ensure all malicious components are removed. Reset passwords for all users on the affected machine and investigate the initial access vector (e.g., phishing email, malicious download).