🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc2ee44ba5333b341f4d497c99162cae95a7821e882f0634e60851a6086df8b2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 7


Intelligence 7 IOCs 1 YARA 2 File information Comments

SHA256 hash: bc2ee44ba5333b341f4d497c99162cae95a7821e882f0634e60851a6086df8b2
SHA3-384 hash: 266749ba49442ce881f196a4fb4f4321806f35392b724701294ab5707b270d8e4a8f2ad660e27e29effc9b7ba5c2b00d
SHA1 hash: 74e92a4ff28a093136f5e2e683d88c1d80aaf18f
MD5 hash: 434bdc2a74b2d3ee69dab3297db4c097
humanhash: one-jig-eight-early
File name:Ziraat Bankasi Swift Mesaji_1.rar
Download: download sample
Signature AZORult
File size:147'238 bytes
First seen:2023-07-17 11:56:12 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:HBzmsNw3C2tEPiUHlw9bM42411q6UXii38QCPl7Y2pLaP3:RmhVgRH8lLIyi3LIl7Yr3
TLSH T1CBE31341B7F034D898FBFC44948461B206B539E939E692AE23E1EC2CAC93B5750EDE04
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter TeamDreier
Tags:AZORult rar

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://blss8.shop/URT341/index.php https://threatfox.abuse.ch/ioc/1137931/

Intelligence


File Origin
# of uploads :
1
# of downloads :
117
Origin country :
DK DK
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Ziraat Bankasi Swift Mesaji.exe
File size:162'155 bytes
SHA256 hash: 0a0aee862a220ef9b3c5930319ab048750c71d6a8c24397006220c04627006a4
MD5 hash: 0793bb7d9f45c0861870ee73df976612
MIME type:application/x-dosexec
Signature AZORult
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
control lolbin overlay packed shell32
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2023-07-17 10:23:51 UTC
File Type:
Binary (Archive)
Extracted files:
8
AV detection:
10 of 38 (26.32%)
Threat level:
  5/5
Result
Malware family:
guloader
Score:
  10/10
Tags:
family:azorult family:guloader collection discovery downloader infostealer spyware stealer trojan
Behaviour
Checks processor information in registry
Delays execution with timeout.exe
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Enumerates physical storage devices
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Checks QEMU agent file
Checks computer location settings
Loads dropped DLL
Reads data files stored by FTP clients
Reads local data of messenger clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Azorult
Guloader,Cloudeye
Malware Config
C2 Extraction:
http://blss8.shop/URT341/index.php
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:win_flawedammyy_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.flawedammyy.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AZORult

rar bc2ee44ba5333b341f4d497c99162cae95a7821e882f0634e60851a6086df8b2

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments