MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 36659906eb6832c7e9e93050a0ed361a18da1498c9a40eb85f2b7db7aba378b5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 36659906eb6832c7e9e93050a0ed361a18da1498c9a40eb85f2b7db7aba378b5
SHA3-384 hash: 82dbe3b3b67f87532e900e4f492360cd1feea91b3d8866a8d2f0d9661f18dfb87ca0712a2d931518ae1287013a228e98
SHA1 hash: 56d43312c886a98432315d44169bf5242999649d
MD5 hash: 0109240aa04ee1b991f0aedbb2423cd1
humanhash: robert-alabama-muppet-lithium
File name:36659906eb6832c7e9e93050a0ed361a18da1498c9a40eb85f2b7db7aba378b5
Download: download sample
Signature AZORult
File size:3'516'587 bytes
First seen:2020-11-13 15:14:21 UTC
Last seen:2024-07-24 13:01:53 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 00be6e6c4f9e287672c8301b72bdabf3 (116 x RedLineStealer, 70 x AsyncRAT, 55 x AgentTesla)
ssdeep 98304:XJMnnOUHuyqZ99hI1G84UCxE75AR8SLB6DJV2:X25HvqZ5Io+CxE75SLIr2
Threatray 876 similar samples on MalwareBazaar
TLSH 53F51205D310A9F2F506353981A77982CD9FBF7450B69A06B2CA1B68DFAB4DEDF0C640
Reporter seifreed
Tags:AZORult

Intelligence


File Origin
# of uploads :
2
# of downloads :
164
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Creating a window
Searching for the window
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Chifrax
Status:
Malicious
First seen:
2020-11-13 15:15:18 UTC
AV detection:
11 of 29 (37.93%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious behavior: GetForegroundWindowSpam
Unpacked files
SH256 hash:
36659906eb6832c7e9e93050a0ed361a18da1498c9a40eb85f2b7db7aba378b5
MD5 hash:
0109240aa04ee1b991f0aedbb2423cd1
SHA1 hash:
56d43312c886a98432315d44169bf5242999649d
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments