🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 51440f5a52c3bea327dff5f79b0e875455719bcdf1d963af7637f26bddc90591. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 10


Intelligence 10 IOCs 1 YARA 2 File information Comments

SHA256 hash: 51440f5a52c3bea327dff5f79b0e875455719bcdf1d963af7637f26bddc90591
SHA3-384 hash: 0cc343044249034642e4b17c820d83e1db0ef64b6eb99ad8e3903484f65a81c5a1af48e033e2a1c0f938ad19526358e0
SHA1 hash: 9fbd31d4f97ca4405a9b7abbb4e22e2554fceeaa
MD5 hash: 8bd13a7858764b487ae00b5394d59c75
humanhash: social-romeo-music-hamper
File name:HalkbankEkstre20220801178701033009.exe
Download: download sample
Signature AZORult
File size:708'096 bytes
First seen:2022-08-02 05:50:53 UTC
Last seen:2022-08-02 06:44:55 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'247 x AgentTesla, 20'516 x Formbook, 12'378 x SnakeKeylogger)
ssdeep 12288:eRIg6SKlpxf4W5+PqljSt0yx985nQ/ZwBBZoO2A3dtNOfM0G72n:xLlpxfX+PqljaMQxwJ26dA6U
TLSH T173E4E041A77ACF36DA354BFBD20171101F7E5CAA11A1F6486D8878FBED79F018640A8B
TrID 72.5% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.4% (.EXE) Win64 Executable (generic) (10523/12/4)
6.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.4% (.EXE) Win32 Executable (generic) (4505/5/1)
2.0% (.EXE) OS/2 Executable (generic) (2029/13)
File icon (PE):PE icon
dhash icon 31f098b29298f031 (53 x AgentTesla, 35 x Formbook, 12 x RedLineStealer)
Reporter abuse_ch
Tags:AZORult exe


Avatar
abuse_ch
AZORult C2:
http://doub1e.shop/PL341/index.php

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://doub1e.shop/PL341/index.php https://threatfox.abuse.ch/ioc/841085/

Intelligence


File Origin
# of uploads :
2
# of downloads :
771
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Sending a custom TCP request
Creating a file in the %temp% directory
Running batch commands
Creating a process with a hidden window
Launching a process
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware packed
Result
Threat name:
Azorult
Detection:
malicious
Classification:
phis.troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
C2 URLs / IPs found in malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Icon mismatch, binary includes an icon from a different legit application in order to fool users
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Self deletion via cmd or bat file
Snort IDS alert for network traffic
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Yara detected AntiVM3
Yara detected Azorult
Yara detected Azorult Info Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 677112 Sample: HalkbankEkstre2022080117870... Startdate: 02/08/2022 Architecture: WINDOWS Score: 100 37 Snort IDS alert for network traffic 2->37 39 Malicious sample detected (through community Yara rule) 2->39 41 Icon mismatch, binary includes an icon from a different legit application in order to fool users 2->41 43 8 other signatures 2->43 8 HalkbankEkstre20220801178701033009.exe 3 2->8         started        process3 file4 25 HalkbankEkstre2022...78701033009.exe.log, ASCII 8->25 dropped 45 Self deletion via cmd or bat file 8->45 12 HalkbankEkstre20220801178701033009.exe 67 8->12         started        17 HalkbankEkstre20220801178701033009.exe 8->17         started        signatures5 process6 dnsIp7 35 doub1e.shop 188.114.96.3, 49740, 49757, 80 CLOUDFLARENETUS European Union 12->35 27 C:\Users\user\AppData\...\vcruntime140.dll, PE32 12->27 dropped 29 C:\Users\user\AppData\Local\...\ucrtbase.dll, PE32 12->29 dropped 31 C:\Users\user\AppData\Local\...\softokn3.dll, PE32 12->31 dropped 33 45 other files (none is malicious) 12->33 dropped 47 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 12->47 49 Tries to steal Instant Messenger accounts or passwords 12->49 51 Tries to steal Mail credentials (via file / registry access) 12->51 53 5 other signatures 12->53 19 cmd.exe 1 12->19         started        file8 signatures9 process10 process11 21 conhost.exe 19->21         started        23 timeout.exe 1 19->23         started       
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2022-08-02 05:51:08 UTC
File Type:
PE (.Net Exe)
Extracted files:
40
AV detection:
24 of 26 (92.31%)
Threat level:
  5/5
Result
Malware family:
azorult
Score:
  10/10
Tags:
family:azorult collection discovery infostealer spyware stealer trojan
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Loads dropped DLL
Reads data files stored by FTP clients
Reads local data of messenger clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Azorult
Malware Config
C2 Extraction:
http://doub1e.shop/PL341/index.php
Unpacked files
SH256 hash:
39c2d879c57f07305ce60412dc8a88f02e51f1a14a06cc605768d1d7f5313807
MD5 hash:
db51fe170a9e5d6ec5429a2fbd9d0353
SHA1 hash:
e30a58125fc41322db6cf2ccb6a6d414ed379016
SH256 hash:
cb4512de96d2211af8398e69a862e9522e691a930dee3579203ab5f933052ea5
MD5 hash:
8c30d66a1192596200f8bafe28671942
SHA1 hash:
4bce6cd1931551e9c84d4917820a864ca1f0400c
Detections:
win_azorult_g1 win_azorult_auto
SH256 hash:
a9c5b2c628a47247402ff05d399855caf6f6a22146d44cd0fd9d7fc05a65ba66
MD5 hash:
228ff1006be83039e4de2b5e0475a5b0
SHA1 hash:
3adef5cc343067fa6b9d5e712114dc619c867a72
SH256 hash:
9f05228319b4d24d66ca0758c7a88cb3d1d62f390a250165e21c3aa095be9d7f
MD5 hash:
5a1e4b8cb2e66e5952d1970307446007
SHA1 hash:
1d0db5551837904619c6d1ebc26c9e95cf61c986
SH256 hash:
0c7676e3dc96e0261aa2ef2ef28a14bddfcc2617e9d574bfacb79102fe16220d
MD5 hash:
29a2c35b890ce16d1f22156f8717b02d
SHA1 hash:
01e2755f904af5549303433d7f20ced4d6ed2ed0
SH256 hash:
51440f5a52c3bea327dff5f79b0e875455719bcdf1d963af7637f26bddc90591
MD5 hash:
8bd13a7858764b487ae00b5394d59c75
SHA1 hash:
9fbd31d4f97ca4405a9b7abbb4e22e2554fceeaa
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments