🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cdf77c2af71c09e830990c14e72b624223094ee4c10b6a9dfaf2f4e27366ed4c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 13


Intelligence 13 IOCs 1 YARA File information Comments

SHA256 hash: cdf77c2af71c09e830990c14e72b624223094ee4c10b6a9dfaf2f4e27366ed4c
SHA3-384 hash: 9367cad201890a3a726679f128060fb63c6cfc648808f95b56a19be90b916a1d84b83156a595e845e2a8795b2eb0f56c
SHA1 hash: 92ae276bf9b0d815cc304c5356a9cb8d75802147
MD5 hash: d46d4f79c6821e040811acbedd4ba8a0
humanhash: iowa-high-rugby-oxygen
File name:CDF77C2AF71C09E830990C14E72B624223094EE4C10B6.exe
Download: download sample
Signature AZORult
File size:164'864 bytes
First seen:2022-10-26 00:21:09 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 4972b0e064f5cc7d3cc41853d19b4d2e (1 x AZORult)
ssdeep 3072:dmxBNvuXY3dmNCQF7rmo11XzfGJ+IlzupkGAZKPaT5:kcVNCyXmojXG+IlzDFKs
Threatray 1'437 similar samples on MalwareBazaar
TLSH T182F302C1BB905046D93F0679B716AFA03484FCECDB97826F116C9E1F98A2FA14F86741
TrID 54.9% (.EXE) UPX compressed Win32 Executable (27066/9/6)
13.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.1% (.EXE) Win32 Executable (generic) (4505/5/1)
4.1% (.EXE) OS/2 Executable (generic) (2029/13)
File icon (PE):PE icon
dhash icon 001a190d0e130504 (1 x AZORult)
Reporter abuse_ch
Tags:AZORult exe


Avatar
abuse_ch
AZORult C2:
http://antrakt.site/index.php

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://antrakt.site/index.php https://threatfox.abuse.ch/ioc/949549/

Intelligence


File Origin
# of uploads :
1
# of downloads :
348
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
azorult
ID:
1
File name:
CDF77C2AF71C09E830990C14E72B624223094EE4C10B6.exe
Verdict:
Malicious activity
Analysis date:
2022-10-26 00:23:05 UTC
Tags:
trojan rat azorult

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a custom TCP request
Launching the default Windows debugger (dwwin.exe)
Result
Malware family:
n/a
Score:
  9/10
Tags:
n/a
Behaviour
MalwareBazaar
SystemUptime
EnumerateProcesses
MeasuringTime
EvasionGetTickCount
EvasionQueryPerformanceCounter
CheckCmdLine
Result
Threat name:
Azorult
Detection:
malicious
Classification:
troj.spyw
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
C2 URLs / IPs found in malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Yara detected Azorult
Yara detected Azorult Info Stealer
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Sodinokibi
Status:
Malicious
First seen:
2019-02-10 22:58:32 UTC
File Type:
PE (Exe)
Extracted files:
43
AV detection:
26 of 26 (100.00%)
Threat level:
  5/5
Result
Malware family:
azorult
Score:
  10/10
Tags:
family:azorult infostealer trojan upx
Behaviour
Program crash
UPX packed file
Azorult
Malware Config
C2 Extraction:
http://antrakt.site/index.php
Verdict:
Informative
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
b28e836de88e9c8a861f1779277dea23364c6aa49009c2178ae1d086a9939204
MD5 hash:
bcc49a135e24543e2a5dd99c2de5319f
SHA1 hash:
56e188939c2f66ea36976aea1304327550b98fd9
Detections:
Azorult win_azorult_auto win_azorult_g1
SH256 hash:
2ca9ef9bfb3afd261ed7379b27e3077df2260fab67198720eee6f77554e9c40d
MD5 hash:
10aa21a7445332c19a2a55d1840dc568
SHA1 hash:
b9664e179a8c53ddbd239ae66d7769554b9f8a64
SH256 hash:
cdf77c2af71c09e830990c14e72b624223094ee4c10b6a9dfaf2f4e27366ed4c
MD5 hash:
d46d4f79c6821e040811acbedd4ba8a0
SHA1 hash:
92ae276bf9b0d815cc304c5356a9cb8d75802147
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments