MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 22150ae9d5a353ba8eecf50a3f5918e26c3df239d4e9f816e3e2ad6acf55cf23. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 22150ae9d5a353ba8eecf50a3f5918e26c3df239d4e9f816e3e2ad6acf55cf23
SHA3-384 hash: 03922a89d39772af9e3e3da537cc4d9f2bd9352579eca5e1c3d7f95c50e3cce74d01f0d5427f6ec627f39a523a701714
SHA1 hash: 7f2d69b25d802048a3cccce193f4762c227203b9
MD5 hash: 3ef844ad93572d87a47357b1f9b366e9
humanhash: football-alabama-floor-pizza
File name:CCMA Final Reminder Case CMS GAJB18471-21.DOC.gz
Download: download sample
Signature AZORult
File size:179'829 bytes
First seen:2021-01-19 12:55:00 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 3072:j/0SFvDIG39XypP40VkHZKrmCBCM8NFgAjauSG7FPcmi3Fwmq07Plw+x3iVE6WXG:jrBxc40G5KSqCM+fSWP9ixq0G+x3i6x2
TLSH 2D042314D744C5BA40312C9FE29B6ADDCA43FB5334FC9244EEB99AB4201263B99C571B
Reporter abuse_ch
Tags:AZORult gz


Avatar
abuse_ch
Malspam distributing AZORult:

HELO: freyzmarketing.com
Sending IP: 188.138.122.57
From: casemngtsys@ccma.org.za
Subject: URGENT - CCMA Final Reminder: CCMA Case GAJB18471-21 (GAJB) is Rescheduled for 'Arbitration' for Fri 29-January-2021 10:00
Attachment: CCMA Final Reminder Case CMS GAJB18471-21.DOC.gz (contains "CCMA Final Reminder Case CMS GAJB18471-21.DOC.exe")

AZORult C2:
http://193.239.147.212/azone/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
289
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-19 12:55:09 UTC
AV detection:
5 of 44 (11.36%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AZORult

gz 22150ae9d5a353ba8eecf50a3f5918e26c3df239d4e9f816e3e2ad6acf55cf23

(this sample)

  
Dropping
AZORult
  
Delivery method
Distributed via e-mail attachment

Comments