MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f5dca31cc4d151da1e23983ff01043a8d0d69a687a9d581b1a14f1e287ebfa8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5f5dca31cc4d151da1e23983ff01043a8d0d69a687a9d581b1a14f1e287ebfa8
SHA3-384 hash: 1b4b33f47c0760aadc22b60dc3aab73894f4e9b8f6edeb776a46bfa6823590062b37bf3fac4ed58319836533e273370e
SHA1 hash: 5878e9cebcf78b4e72cc4001187eb7da9986ea0e
MD5 hash: 6459f5a50386aaa915484b64aee8656d
humanhash: kentucky-echo-double-ack
File name:REQ 9315393V200220.zip
Download: download sample
Signature AZORult
File size:390'724 bytes
First seen:2020-08-13 10:57:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:xbNF2Q4A8P9Jm39OzC2mBwswGGw8L1b2wl3RIGwCFGZukSqViK/sKwaIX4BuEinO:xf8ASJP+2meswG3Q1z3NkRZkZaIIM6x
TLSH AC8423177497C571F92B8578318A821DC95A04274BB0EDE57027EA8EC176E31FC2AFA8
Reporter abuse_ch
Tags:AZORult zip


Avatar
abuse_ch
Malspam distributing AZORult:

HELO: server.sgbcg.com
Sending IP: 113.11.251.241
From: Amministrazione SRL <ru-bill@nic.ru>
Reply-To: me <testing@mkontakt.az>
Subject: Quotation Request for Requisition 9315393V200220
Attachment: REQ 9315393V200220.zip (contains "REQ 9315393V200220.exe")

Loki C2:
http://70.35.200.190/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
193
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-08-13 10:59:04 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AZORult

zip 5f5dca31cc4d151da1e23983ff01043a8d0d69a687a9d581b1a14f1e287ebfa8

(this sample)

  
Dropping
AZORult
  
Delivery method
Distributed via e-mail attachment

Comments