Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 64-bit Windows platform, family Rhadamanthys
Trojan:Win64/Rhadamanthys.RR!MTB is a concrete detection of a highly malicious Trojan targeting 64-bit Windows systems. This threat leverages machine learning behavioral analysis along with a specific byte pattern signature to gain unauthorized access, steal data, or deploy further malicious payloads with a low false positive risk.
No specific strings found for this threat
rule Trojan_Win64_Rhadamanthys_RR_2147957705_0
{
meta:
author = "threatcheck.sh"
detection_name = "Trojan:Win64/Rhadamanthys.RR!MTB"
threat_id = "2147957705"
type = "Trojan"
platform = "Win64: Windows 64-bit platform"
family = "Rhadamanthys"
severity = "Critical"
info = "MTB: Microsoft Threat Behavior"
signature_type = "SIGNATURE_TYPE_PEHSTR_EXT"
threshold = "1"
strings_accuracy = "High"
strings:
$x_1_1 = {48 89 c0 90 52 48 8d 12 5a 4c 89 c0 66 90 80 30 72 48 89 c9 48 87 db 48 83 c0 01 48 39 c8 75 ee} //weight: 1, accuracy: High
condition:
(filesize < 20MB) and
(all of ($x*))
}cb3ad16b57b26d5f1750bd562fb4c770dbfb7b03d6f997bf48d66239666ba0a1c8a01ce3d2cf841f7aeaf2ea081b27744bcf2475f1d9aaa8220f6a8ded9a2a89716e8656b4395e1118d5a11255d8c13811436529374ae34fbb79affe22de36203d2fe9c8a19b49107591d98ef849ca7c7c79df2d2eb420ec31f228a5cfe5a026Immediately isolate the affected system, remove the malicious file using an updated antivirus/EDR, and perform a comprehensive scan for any additional compromise. Investigate for persistence mechanisms, network communication indicative of C2, and potential data exfiltration.