🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0081ec4836a7ecf5b428ba410dc9a86d679cb0d6ef8bb52dc7c8721efc3a4b3d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 0081ec4836a7ecf5b428ba410dc9a86d679cb0d6ef8bb52dc7c8721efc3a4b3d
SHA3-384 hash: b6ad38aec68a8ff06054f8d670fd5957e901b50190a1f477277dde56c6a4215da97404aafc1e3408701ea4c1c4819866
SHA1 hash: 19df37b9b865c78d37bb41c75cba6697159d62a0
MD5 hash: 07bf5c0cec29332eaee4559712044afa
humanhash: pasta-iowa-idaho-stairway
File name:helper.exe
Download: download sample
Signature AZORult
File size:215'000 bytes
First seen:2023-12-19 22:06:26 UTC
Last seen:2023-12-19 23:18:39 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash e1ed1b87d365b2ea75670bba09649dc7 (11 x AZORult)
ssdeep 3072:rmLd2f5yZBRE34J8Quhn0o2lGPetr2MVbc1ugYSpGd9Prw2HvrKe2NphPK:y5EOb38QS2/Zbc1ugYSpG3THeNp
TLSH T18E248C977EFEA6B1E411BAF41C38CE6506ACFC411F90D89713888B931E45AC2571CAE7
TrID 40.3% (.EXE) Win64 Executable (generic) (10523/12/4)
19.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
17.2% (.EXE) Win32 Executable (generic) (4505/5/1)
7.7% (.EXE) OS/2 Executable (generic) (2029/13)
7.6% (.EXE) Generic Win/DOS Executable (2002/3)
Reporter 1ZRR4H
Tags:AZORult exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
343
Origin country :
CL CL
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Sending an HTTP POST request
Running batch commands
Creating a process with a hidden window
Launching a process
Sending an HTTP GET request
Creating a window
DNS request
Sending a custom TCP request
Using the Windows Management Instrumentation requests
Creating a file in the %AppData% directory
Adding an access-denied ACE
Reading critical registry keys
Stealing user critical data
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
overlay packed
Result
Threat name:
AZORult++
Detection:
malicious
Classification:
bank.spyw.evad
Score:
69 / 100
Signature
Antivirus detection for URL or domain
Contains functionality to inject code into remote processes
Detected AZORult++ Trojan
Found evasive API chain (may stop execution after checking locale)
Found evasive API chain (may stop execution after checking mutex)
Multi AV Scanner detection for submitted file
Sigma detected: Powershell Download and Execute IEX
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2023-12-18 18:10:59 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
10 of 37 (27.03%)
Threat level:
  2/5
Verdict:
malicious
Result
Malware family:
n/a
Score:
  8/10
Tags:
spyware stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Accesses 2FA software files, possible credential harvesting
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks computer location settings
Blocklisted process makes network request
Unpacked files
SH256 hash:
35c84b1e0f382a91290faef6f6aa2f906c8646fe57a30250abd3db250013f5f9
MD5 hash:
d1683c2b9579eb690657ed97426e5867
SHA1 hash:
1f595e9227caa374e43e9756bac0526032a1731e
SH256 hash:
0081ec4836a7ecf5b428ba410dc9a86d679cb0d6ef8bb52dc7c8721efc3a4b3d
MD5 hash:
07bf5c0cec29332eaee4559712044afa
SHA1 hash:
19df37b9b865c78d37bb41c75cba6697159d62a0
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments