🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca2467a857a0732cfe8e0868ab28855abb4270c5b5979acc994ce32c3effc9c7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 10


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: ca2467a857a0732cfe8e0868ab28855abb4270c5b5979acc994ce32c3effc9c7
SHA3-384 hash: abd594e7a2dc83be89d9d13477d45226e66e2aec7fe372c0d0e918ca8a0333ad476182c7d634034ce5ac9d36c587040d
SHA1 hash: be24ba4e8424d77ee443365b7a2fd3671fe95622
MD5 hash: ee68a69607760dd56632a0045a7c87ec
humanhash: michigan-four-east-stream
File name:HT1150009-Docs.exe
Download: download sample
Signature AZORult
File size:1'211'504 bytes
First seen:2023-10-18 17:05:46 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b34f154ec913d2d2c435cbd644e91687 (592 x GuLoader, 130 x RemcosRAT, 84 x EpsilonStealer)
ssdeep 24576:MJJB+kZ1+sBAqeOdno9zXSiZQrH0LuxaGwAma0l+SfoPxlAM5f:MDqsBA7inop/wgAwfnlbfoZlAM5f
TLSH T12945122E7A80D17BDA9C4470B845446957E8FEACC3D48A477660226D383DB72CABCF47
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10523/12/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon 62e0c08292b2e409 (2 x AZORult, 1 x GuLoader)
Reporter abuse_ch
Tags:AZORult exe signed

Code Signing Certificate

Organisation:
Issuer:
Algorithm:sha256WithRSAEncryption
Valid from:2023-07-25T23:23:47Z
Valid to:2026-07-24T23:23:47Z
Serial number: 5906d9e49de0aba17036f0a48b0c88f15a74861b
Thumbprint Algorithm:SHA256
Thumbprint: 3780856b83cf520260036db9eb6f769d0abdf137960d483a7995fb8ccfc6cb03
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
abuse_ch
AZORult C2:
http://lqr1.shop/B01341/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
408
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Creating a file
Creating a file in the %temp% subdirectories
Searching for the window
Searching for the Windows task manager window
Sending a custom TCP request
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
control installer lolbin overlay packed shell32
Result
Threat name:
GuLoader
Detection:
malicious
Classification:
n/a
Score:
100 / 100
Signature
Antivirus detection for URL or domain
Maps a DLL or memory area into another process
Self deletion via cmd or bat file
Snort IDS alert for network traffic
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Yara detected GuLoader
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1328247 Sample: HT1150009-Docs.exe Startdate: 18/10/2023 Architecture: WINDOWS Score: 100 36 lqr1.shop 2->36 38 aiv.mk 2->38 44 Snort IDS alert for network traffic 2->44 46 Antivirus detection for URL or domain 2->46 48 Yara detected GuLoader 2->48 9 HT1150009-Docs.exe 1 47 2->9         started        signatures3 process4 file5 24 C:\Users\user\AppData\Local\...\nsExec.dll, PE32 9->24 dropped 26 C:\Users\user\AppData\Local\...\System.dll, PE32 9->26 dropped 50 Self deletion via cmd or bat file 9->50 52 Maps a DLL or memory area into another process 9->52 13 HT1150009-Docs.exe 63 9->13         started        signatures6 process7 dnsIp8 40 lqr1.shop 172.67.197.215, 49813, 49814, 80 CLOUDFLARENETUS United States 13->40 42 aiv.mk 95.156.8.108, 443, 49812 MT-AS-OWNbulOrceNikolovbbMK Macedonia 13->42 28 C:\Users\user\AppData\...\vcruntime140.dll, PE32 13->28 dropped 30 C:\Users\user\AppData\Local\...\ucrtbase.dll, PE32 13->30 dropped 32 C:\Users\user\AppData\Local\...\softokn3.dll, PE32 13->32 dropped 34 45 other files (none is malicious) 13->34 dropped 54 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 13->54 56 Tries to steal Instant Messenger accounts or passwords 13->56 58 Tries to steal Mail credentials (via file / registry access) 13->58 60 5 other signatures 13->60 18 cmd.exe 1 13->18         started        file9 signatures10 process11 process12 20 conhost.exe 18->20         started        22 timeout.exe 1 18->22         started       
Threat name:
Win32.Trojan.Generic
Status:
Malicious
First seen:
2023-10-18 17:06:05 UTC
File Type:
PE (Exe)
Extracted files:
16
AV detection:
8 of 23 (34.78%)
Threat level:
  2/5
Verdict:
malicious
Label(s):
cloudeye
Result
Malware family:
azorult
Score:
  10/10
Tags:
family:azorult collection discovery infostealer spyware stealer trojan
Behaviour
Checks processor information in registry
Delays execution with timeout.exe
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Enumerates physical storage devices
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Checks computer location settings
Deletes itself
Loads dropped DLL
Reads data files stored by FTP clients
Reads local data of messenger clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Azorult
Unpacked files
SH256 hash:
18cb7e2d2f79dd0a61f93a13aa2bbe66635e7ddb50060f38c2df3344b5f012f8
MD5 hash:
3f4ba5fde3a15d9ed8da6cecd16a3a47
SHA1 hash:
ff321a610a17d5084a0a1907c1a2091c8d71515b
SH256 hash:
3eb38ae99653a7dbc724132ee240f6e5c4af4bfe7c01d31d23faf373f9f2eaca
MD5 hash:
0d7ad4f45dc6f5aa87f606d0331c6901
SHA1 hash:
48df0911f0484cbe2a8cdd5362140b63c41ee457
SH256 hash:
5d9ceb1ce5f35aea5f9e5a0c0edeeec04dfefe0c77890c80c70e98209b58b962
MD5 hash:
ec0504e6b8a11d5aad43b296beeb84b2
SHA1 hash:
91b5ce085130c8c7194d66b2439ec9e1c206497c
SH256 hash:
3f47a24d6eeb1203e3325f0b06023e9678df7e860e953925057de17e6c539be4
MD5 hash:
fd78a68cb7e9fa26dec0d9d1b2342c72
SHA1 hash:
06d39a9eadc6d4272a5ae2f2ce632de5628d375b
SH256 hash:
ca2467a857a0732cfe8e0868ab28855abb4270c5b5979acc994ce32c3effc9c7
MD5 hash:
ee68a69607760dd56632a0045a7c87ec
SHA1 hash:
be24ba4e8424d77ee443365b7a2fd3671fe95622
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments