MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 3f6f9797ee0e556772ef5acef99604251a6a8b5ee257f51581c9a089569256eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AZORult
Vendor detections: 4
| SHA256 hash: | 3f6f9797ee0e556772ef5acef99604251a6a8b5ee257f51581c9a089569256eb |
|---|---|
| SHA3-384 hash: | f3a78e835d3cb708b5df93f86bb362db260b00ccb356852965ec9d3748f39e4c7519ab040c7431f50e9c95756d2f177a |
| SHA1 hash: | 20e683fcaa47713c271c63fc9c11c0dda93ac248 |
| MD5 hash: | 6009cc9d3e26b5eb06ff7d83ea3e6abe |
| humanhash: | mango-five-virginia-blue |
| File name: | Order No. DOC.00064.2020.zip |
| Download: | download sample |
| Signature | AZORult |
| File size: | 422'991 bytes |
| First seen: | 2020-08-03 14:00:27 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:CUITPmNKYQW2LXZR1cg0hqUumzQTq36XAeoNIf6qLanXoidAsw6bE60R3hMPw6Fq:LIL6uLXh0IeL36XKNIfzidvw+J+Uj0P |
| TLSH | 589423EDFA311169FF5099EA2F503764EA8F8D6C0E0607182CA06E97D59E7D33E48364 |
| Reporter | |
| Tags: | AZORult zip |
abuse_ch
Malspam distributing AZORult:HELO: server.sgbcg.com
Sending IP: 113.11.251.241
From: Amhai khan <info-lunartrading@mail.ru>
Subject: Order No. DOC/00064/2020
Attachment: Order No. DOC.00064.2020.zip (contains "Order No. DOC.00064.2020.exe")
AZORult C2:
http://3.123.254.92/index.php
Intelligence
File Origin
# of uploads :
1
# of downloads :
171
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Strictor
Status:
Malicious
First seen:
2020-08-03 14:02:09 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Strictor
Score:
0.80
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AZORult
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.