🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 772517cb1fd0d04befcebe3e7850a6741e360c73e69b4c75a9c2d7e079e3699a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 9


Intelligence 9 IOCs YARA 3 File information Comments

SHA256 hash: 772517cb1fd0d04befcebe3e7850a6741e360c73e69b4c75a9c2d7e079e3699a
SHA3-384 hash: fb8c06b3b414b0a003158aad1785809cf0db6130d49bb63fa24c54fb9c8dcafde310a3d9a4eadc71e5e5216495fb9772
SHA1 hash: 80696792cdf65d2a8419ee74d47e9375680b0dc5
MD5 hash: a7461a0e132f7c7d2b9797027095445b
humanhash: ten-hawaii-beer-double
File name:Swift Document #672701.exe
Download: download sample
Signature AZORult
File size:1'146'008 bytes
First seen:2023-12-12 13:00:10 UTC
Last seen:2023-12-12 14:29:40 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f10e4da994053bf80c20cee985b32e29 (65 x GuLoader, 9 x RemcosRAT, 6 x QuasarRAT)
ssdeep 24576:XZzYV1YqL+Lob51mxrloSXu/hXY4Op4SCoeJYCfPrEthbD:Y11L+ODcoSepo4Op4hHfTu3
TLSH T1EF353397A6208463C17579F12DF5288288779B0E6629CA1B271C3B19FF301E2BE5B717
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10523/12/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla)
Reporter abuse_ch
Tags:AZORult exe signed

Code Signing Certificate

Organisation:Arglebargled
Issuer:Arglebargled
Algorithm:sha256WithRSAEncryption
Valid from:2023-12-03T02:47:30Z
Valid to:2026-12-02T02:47:30Z
Serial number: 352e33907d880be474b18ac4ff08fe67c0920eec
Thumbprint Algorithm:SHA256
Thumbprint: b7f504acee53faed95a7d835fe9b841136b32436e9baf62944e3ed2acf4b2f4c
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
abuse_ch
AZORult C2:
http://b2i1.shop/B2341/index.php

Intelligence


File Origin
# of uploads :
2
# of downloads :
380
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Creating a file in the %temp% directory
Creating a window
Creating a file
Creating a process from a recently created file
Launching a process
Sending a custom TCP request
Gathering data
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
control installer lolbin overlay packed shell32
Result
Threat name:
Azorult, GuLoader
Detection:
malicious
Classification:
phis.troj.spyw.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
Found suspicious powershell code related to unpacking or dynamic code loading
Initial sample is a PE file and has a suspicious name
Maps a DLL or memory area into another process
Obfuscated command line found
Snort IDS alert for network traffic
Suspicious powershell command line found
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Very long command line found
Writes to foreign memory regions
Yara detected Azorult
Yara detected GuLoader
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1360126 Sample: Swift_Document_#672701.exe Startdate: 12/12/2023 Architecture: WINDOWS Score: 100 44 b2i1.shop 2->44 46 schleswig-flensburg.freifunk.net 2->46 56 Snort IDS alert for network traffic 2->56 58 Antivirus detection for URL or domain 2->58 60 Yara detected GuLoader 2->60 62 2 other signatures 2->62 11 Swift_Document_#672701.exe 1 44 2->11         started        signatures3 process4 file5 42 C:\Users\user\AppData\...\ugenkendeliges.Emi, ASCII 11->42 dropped 72 Suspicious powershell command line found 11->72 15 powershell.exe 12 11->15         started        signatures6 process7 signatures8 74 Suspicious powershell command line found 15->74 76 Obfuscated command line found 15->76 78 Very long command line found 15->78 80 Found suspicious powershell code related to unpacking or dynamic code loading 15->80 18 powershell.exe 15 15->18         started        21 conhost.exe 15->21         started        process9 signatures10 52 Writes to foreign memory regions 18->52 54 Maps a DLL or memory area into another process 18->54 23 wab.exe 63 18->23         started        process11 dnsIp12 48 b2i1.shop 172.67.196.251, 49714, 49716, 80 CLOUDFLARENETUS United States 23->48 50 schleswig-flensburg.freifunk.net 89.238.66.41, 49713, 80 MANITUDE Germany 23->50 34 C:\Users\user\AppData\...\vcruntime140.dll, PE32 23->34 dropped 36 C:\Users\user\AppData\Local\...\ucrtbase.dll, PE32 23->36 dropped 38 C:\Users\user\AppData\Local\...\softokn3.dll, PE32 23->38 dropped 40 45 other files (none is malicious) 23->40 dropped 64 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 23->64 66 Tries to steal Instant Messenger accounts or passwords 23->66 68 Tries to steal Mail credentials (via file / registry access) 23->68 70 4 other signatures 23->70 28 cmd.exe 1 23->28         started        file13 signatures14 process15 process16 30 conhost.exe 28->30         started        32 timeout.exe 1 28->32         started       
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2023-12-12 13:01:05 UTC
File Type:
PE (Exe)
Extracted files:
14
AV detection:
15 of 22 (68.18%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
azorult
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Drops file in Program Files directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Unpacked files
SH256 hash:
772517cb1fd0d04befcebe3e7850a6741e360c73e69b4c75a9c2d7e079e3699a
MD5 hash:
a7461a0e132f7c7d2b9797027095445b
SHA1 hash:
80696792cdf65d2a8419ee74d47e9375680b0dc5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments