Request for Further Investigation: Trojan Detection Related to WinRAR Update

Lars Frishert | Lannet IT 20 Reputation points
2025-08-04T11:52:11.19+00:00

Dear Microsoft,

I am reaching out to request further investigation into a recent severe Trojan detection on our system:

Threat Details:

  • Name: Trojan:Win32/Egairtigado!rfn

Category: Trojan

Severity: Severe

Detected At: 2025-08-04 10:57:45

Quarantined At: 2025-08-04 10:57:51

Detected File: C:\Program Files\WinRAR\Default.SFX

Process User: NT AUTHORITY\SYSTEM

Detection Source: System

The file was last modified on 2025-07-30 11:50:35, and the detection occurred shortly after using the following command to update WinRAR:

powershel

We would appreciate your assistance in determining whether:

The malicious file was introduced during the update via winget, or

The trojan is embedded in the latest official WinRAR release itself.

Given the nature of the detection and its association with a legitimate application, we would like to avoid false positives or potential supply chain compromises. If needed, we can provide the quarantined file and relevant logs.

Thank you in advance for your support and analysis.Dear Huntress,

I am reaching out to request further investigation into a recent severe Trojan detection on our system:

Threat Details:

Name: Trojan:Win32/Egairtigado!rfn

Category: Trojan

Severity: Severe

Detected At: 2025-08-04 10:57:45

Quarantined At: 2025-08-04 10:57:51

Detected File: C:\Program Files\WinRAR\Default.SFX

Process User: NT AUTHORITY\SYSTEM

Detection Source: System

The file was last modified on 2025-07-30 11:50:35, and the detection occurred shortly after using the following command to update WinRAR:

powershel

We would appreciate your assistance in determining whether:

The malicious file was introduced during the update via winget, or

The trojan is embedded in the latest official WinRAR release itself.

Given the nature of the detection and its association with a legitimate application, we would like to avoid false positives or potential supply chain compromises. If needed, we can provide the quarantined file and relevant logs.

Thank you in advance for your support and analysis.

Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
{count} votes

Accepted answer
  1. Jose Benjamin Solis Nolasco 5,221 Reputation points
    2025-08-05T00:53:39.3866667+00:00

    @Lars Frishert | Lannet IT

    Please submit the quarantined Default.SFX to the Microsoft Security Intelligence portal: https://www.microsoft.com/wdsi/filesubmission That will allow our analysts to validate if this is a confirmed trojan or a false positive.

    😊 If my answer helped you resolve your issue, please consider marking it as the correct answer. This helps others in the community find solutions more easily. Thanks!

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.