Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 64-bit Windows platform, family Rozena
This threat is a Trojan from the Rozena malware family, detected on 64-bit Windows systems through behavioral analysis. Rozena is known to create backdoors, enabling attackers to gain remote control, steal sensitive information, and download additional malicious payloads.
No specific strings found for this threat
rule Trojan_Win64_Rozena_EM_2147889023_0
{
meta:
author = "threatcheck.sh"
detection_name = "Trojan:Win64/Rozena.EM!MTB"
threat_id = "2147889023"
type = "Trojan"
platform = "Win64: Windows 64-bit platform"
family = "Rozena"
severity = "Critical"
info = "MTB: Microsoft Threat Behavior"
signature_type = "SIGNATURE_TYPE_PEHSTR_EXT"
threshold = "6"
strings_accuracy = "High"
strings:
$x_3_1 = {48 c7 44 24 30 00 00 00 00 c7 44 24 28 00 00 00 00 c7 44 24 20 03 00 00 00 41 b9 00 00 00 00 41 b8 01 00 00 00 ba 00 00 00 80} //weight: 3, accuracy: High
$x_3_2 = {48 c7 44 24 28 00 00 00 00 c7 44 24 20 00 00 00 00 41 b9 00 00 00 00 41 b8 02 00 00 01 ba 00 00 00 00 48 89 c1} //weight: 3, accuracy: High
condition:
(filesize < 20MB) and
(all of ($x*))
}7a1ce7981617497fe17c998698146437831520e9ab4dd5c454097ccf061f093e1. Isolate the affected machine from the network immediately. 2. Use Windows Defender to perform a full system scan and remove the detected threat. 3. Change passwords for all accounts accessed from the machine and review system logs for signs of further compromise or data exfiltration.