🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e062aea7aa7f1e6d4f5ad5a5029cf7cc2ef0724852ad03d76f2d07b8f5558615. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e062aea7aa7f1e6d4f5ad5a5029cf7cc2ef0724852ad03d76f2d07b8f5558615
SHA3-384 hash: 0d92e97d8681bcb3d989198153fb7a125f8f89b0acf36c777f9195682c2d40d4849cf32c70f6182744b6d7af94f92d63
SHA1 hash: e50e1150b7b35a089932fe4a58df1ef51c8219c6
MD5 hash: 295b2d76161197eff3e0802239576ff5
humanhash: crazy-saturn-south-solar
File name:T. HALK BANKASI A.S.exe
Download: download sample
Signature AZORult
File size:550'948 bytes
First seen:2021-08-17 14:10:51 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f21b9f4ed04fb68076e88d1363ed51e4 (10 x Formbook, 3 x RemcosRAT, 2 x Loki)
ssdeep 12288:Xkuzg4vUltD8VSNxKAdyDqn9LDd+gZ65UDNku:XkSfUbDxKAda89ghu
Threatray 17 similar samples on MalwareBazaar
TLSH T105C4CF01A6DDC237D5E22432C1E9B1F928387E61DB5F4AEB27D43E29BB741D16D20A13
dhash icon 8660ecb292d66600 (1 x AZORult)
Reporter abuse_ch
Tags:AZORult exe geo Halkbank TUR

Intelligence


File Origin
# of uploads :
1
# of downloads :
385
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
T. HALK BANKASI A.S.exe
Verdict:
No threats detected
Analysis date:
2021-08-17 14:49:38 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Azorult
Detection:
malicious
Classification:
troj.spyw.evad
Score:
88 / 100
Signature
C2 URLs / IPs found in malware configuration
Found malware configuration
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for submitted file
Yara detected Azorult
Yara detected Azorult Info Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 466900 Sample: T. HALK BANKASI A.S.exe Startdate: 17/08/2021 Architecture: WINDOWS Score: 88 16 Found malware configuration 2->16 18 Malicious sample detected (through community Yara rule) 2->18 20 Multi AV Scanner detection for submitted file 2->20 22 3 other signatures 2->22 7 T. HALK BANKASI A.S.exe 1 2->7         started        process3 signatures4 24 Maps a DLL or memory area into another process 7->24 10 T. HALK BANKASI A.S.exe 7->10         started        12 conhost.exe 7->12         started        process5 process6 14 WerFault.exe 23 9 10->14         started       
Threat name:
Win32.Backdoor.NetWiredRc
Status:
Malicious
First seen:
2021-08-17 14:12:03 UTC
AV detection:
15 of 28 (53.57%)
Threat level:
  5/5
Result
Malware family:
azorult
Score:
  10/10
Tags:
family:azorult infostealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Suspicious use of SetThreadContext
Azorult
Malware Config
C2 Extraction:

Unpacked files
SH256 hash:
e062aea7aa7f1e6d4f5ad5a5029cf7cc2ef0724852ad03d76f2d07b8f5558615
MD5 hash:
295b2d76161197eff3e0802239576ff5
SHA1 hash:
e50e1150b7b35a089932fe4a58df1ef51c8219c6
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments