🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1dfc5e26c8fc4d0b4cfd8bf008b5ace5f4e512314f6ac4d8006b04c7217c26dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 7


Intelligence 7 IOCs YARA 8 File information Comments

SHA256 hash: 1dfc5e26c8fc4d0b4cfd8bf008b5ace5f4e512314f6ac4d8006b04c7217c26dd
SHA3-384 hash: 926c36234fbda22ba3b027f97f8fe8b36220ad82f16344b13eb74834c69d1539127aeeddd6da35a2b860448880b7f4ae
SHA1 hash: 20a3d75445c9d3a75cf430c2f28cd3879c37bdde
MD5 hash: 1c8b5bc446ce36fadff5ee444c0d7085
humanhash: venus-emma-asparagus-autumn
File name:Modifications_List.one
Download: download sample
Signature AZORult
File size:1'115'112 bytes
First seen:2024-09-02 12:01:38 UTC
Last seen:Never
File type:Microsoft OneNote (one) one
MIME type:application/octet-stream
ssdeep 24576:QLPskXqS0jFC6LkpzqPskXqS0jFC6LkpzWoKywypSpbYmb93PK/g:WJXUJC6LkpzqJXUJC6LkpzEMSNYmpy/g
TLSH T1B435F1E6A5BEF230C1A51438F851AF1896152CF6DE448A057F3C5E0FAB61F81F7D218A
Magika unknown
Reporter lowmal3
Tags:AZORult one

Intelligence


File Origin
# of uploads :
1
# of downloads :
225
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
Generic Agent
Result
Verdict:
Malicious
File Type:
OneNote File - Malicious
Behaviour
SuspiciousEmbeddedObjects detected
Result
Threat name:
AZORult
Detection:
malicious
Classification:
phis.troj.spyw.expl.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Detected AZORult Info Stealer
Detected unpacking (changes PE section rights)
Document exploit detected (process start blacklist hit)
Drops PE files with a suspicious file extension
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
Machine Learning detection for dropped file
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious Microsoft Office Child Process
Sigma detected: Suspicious Microsoft OneNote Child Process
Suricata IDS alerts for network traffic
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Yara detected Azorult
Yara detected Azorult Info Stealer
Yara detected Malicious OneNote
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1502903 Sample: Modifications_List.one Startdate: 02/09/2024 Architecture: WINDOWS Score: 100 47 ehzwq.shop 2->47 49 augloop.office.com 2->49 53 Suricata IDS alerts for network traffic 2->53 55 Found malware configuration 2->55 57 Malicious sample detected (through community Yara rule) 2->57 59 13 other signatures 2->59 10 ONENOTE.EXE 91 422 2->10         started        13 ONENOTEM.EXE 2->13         started        signatures3 process4 file5 39 C:\...\{FE86234F-D31D-473F-9942-7F67F0932207}, PE32 10->39 dropped 41 C:\Users\user\AppData\Local\Temp41otes.pif, PE32 10->41 dropped 43 C:\Users\user\AppData\Local\...\00000007.bin, PE32 10->43 dropped 45 C:\Users\user\AppData\...\00000007.bin (copy), PE32 10->45 dropped 15 Notes.pif 10->15         started        18 ONENOTEM.EXE 4 10->18         started        process6 signatures7 69 Multi AV Scanner detection for dropped file 15->69 71 Detected unpacking (changes PE section rights) 15->71 73 Detected AZORult Info Stealer 15->73 75 3 other signatures 15->75 20 Notes.pif 69 15->20         started        process8 dnsIp9 51 ehzwq.shop 172.67.162.36, 443, 49731, 49732 CLOUDFLARENETUS United States 20->51 31 C:\Users\user\AppData\Local\...\softokn3.dll, PE32 20->31 dropped 33 C:\Users\user\AppData\Local\...\nssdbm3.dll, PE32 20->33 dropped 35 C:\Users\user\AppData\Local\Temp\...\nss3.dll, PE32 20->35 dropped 37 45 other files (2 malicious) 20->37 dropped 61 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 20->61 63 Tries to steal Instant Messenger accounts or passwords 20->63 65 Tries to steal Mail credentials (via file / registry access) 20->65 67 6 other signatures 20->67 25 cmd.exe 1 20->25         started        file10 signatures11 process12 process13 27 conhost.exe 25->27         started        29 timeout.exe 1 25->29         started       
Threat name:
Win32.Trojan.Malnote
Status:
Malicious
First seen:
2024-09-02 11:40:07 UTC
File Type:
Document
Extracted files:
7
AV detection:
16 of 38 (42.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  4/10
Tags:
discovery
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:OneNote_EmbeddedFiles_NoPictures
Author:Nicholas Dhaeyer - @DhaeyerWolf
Description:OneNote files that contain embedded files that are not pictures.
Reference:https://blog.didierstevens.com/2023/01/22/analyzing-malicious-onenote-documents/
Rule name:OneNote_magic
Author:Stuart Gonzalez
Rule name:onenote_maldocs
Author:Stuart Gonzalez
Rule name:SEH__vba
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Suspicious_OneNote
Author:marcin@ulikowski.pl
Description:Detects OneNote documents with FileDataStoreObject structure containing: PE32, shortcut files (*.lnk), encoded JS, Windows Help File (*.chm), or batch script
Rule name:SUSP_OneNote
Author:spatronn
Description:Hard-Detect One
Rule name:SUSP_OneNote_Embedded_FileDataStoreObject_Type_Jan23_1
Author:Florian Roth
Description:Detects suspicious embedded file types in OneNote files
Reference:https://blog.didierstevens.com/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AZORult

Microsoft OneNote (one) one 1dfc5e26c8fc4d0b4cfd8bf008b5ace5f4e512314f6ac4d8006b04c7217c26dd

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments