MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f6f9797ee0e556772ef5acef99604251a6a8b5ee257f51581c9a089569256eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3f6f9797ee0e556772ef5acef99604251a6a8b5ee257f51581c9a089569256eb
SHA3-384 hash: f3a78e835d3cb708b5df93f86bb362db260b00ccb356852965ec9d3748f39e4c7519ab040c7431f50e9c95756d2f177a
SHA1 hash: 20e683fcaa47713c271c63fc9c11c0dda93ac248
MD5 hash: 6009cc9d3e26b5eb06ff7d83ea3e6abe
humanhash: mango-five-virginia-blue
File name:Order No. DOC.00064.2020.zip
Download: download sample
Signature AZORult
File size:422'991 bytes
First seen:2020-08-03 14:00:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:CUITPmNKYQW2LXZR1cg0hqUumzQTq36XAeoNIf6qLanXoidAsw6bE60R3hMPw6Fq:LIL6uLXh0IeL36XKNIfzidvw+J+Uj0P
TLSH 589423EDFA311169FF5099EA2F503764EA8F8D6C0E0607182CA06E97D59E7D33E48364
Reporter abuse_ch
Tags:AZORult zip


Avatar
abuse_ch
Malspam distributing AZORult:

HELO: server.sgbcg.com
Sending IP: 113.11.251.241
From: Amhai khan <info-lunartrading@mail.ru>
Subject: Order No. DOC/00064/2020
Attachment: Order No. DOC.00064.2020.zip (contains "Order No. DOC.00064.2020.exe")

AZORult C2:
http://3.123.254.92/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
171
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Strictor
Status:
Malicious
First seen:
2020-08-03 14:02:09 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AZORult

zip 3f6f9797ee0e556772ef5acef99604251a6a8b5ee257f51581c9a089569256eb

(this sample)

  
Dropping
AZORult
  
Delivery method
Distributed via e-mail attachment

Comments