Another case where generic rules did the job:
THOR/Valhalla flagged a Python RAT (“anyad2.pyw”, uploaded from Hungary) using only broad detection logic – suspicious import/function combinations and token stealer indicators.
3/64 AVs flagged it. We didn’t need a name.
Sample: virustotal.com/gui/file/4373…#ThreatDetection#PythonRAT@thor_scanner
Analisi di un #PythonRat individuato su un dominio italiano
➡️ Deoffuscazione del payload
➡️ Analisi del payload
➡️ Comandi supportati
➡️ Similitudini
💣 Disponibili #IoC 👇
🔗 cert-agid.gov.it/news/malwar…