MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e9c42b737c586759102817b5922701598ec9c9256b36cf5fc28782fa09016ca4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e9c42b737c586759102817b5922701598ec9c9256b36cf5fc28782fa09016ca4
SHA3-384 hash: 38180a7605152fe95758aa5f4bca5d2dea386e3ac0885fc4e4cba31c0a44e1889427f3007ac0d269b5b3f095d62a45dc
SHA1 hash: b1c822950c670bf814a0d5683c2a4b6107a7a537
MD5 hash: 39f0b06bbcd289f628443a16ea7d782d
humanhash: kansas-lemon-iowa-yellow
File name:e9c42b737c586759102817b5922701598ec9c9256b36cf5fc28782fa09016ca4
Download: download sample
Signature AZORult
File size:541'184 bytes
First seen:2020-03-23 16:23:44 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 54b262fcc1f097cf4c87295a213868c7 (1 x AZORult)
ssdeep 12288:TwRVqGpdh4kyfq7HG5hEwpwcDfaTxK6eeyYHtcJYJx6KZ:TiVD/49fqKowrza1K6e6iJYJJZ
Threatray 278 similar samples on MalwareBazaar
TLSH 75B49E36F6D04533E1232539DC4B5265A52ABED0292819B72FE92C886FF9B8135373D3
Reporter Marco_Ramilli
Tags:AZORult exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2019-08-09 15:30:40 UTC
AV detection:
27 of 30 (90.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

AZORult

Executable exe e9c42b737c586759102817b5922701598ec9c9256b36cf5fc28782fa09016ca4

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryExA
kernel32.dll::LoadLibraryA
kernel32.dll::GetSystemInfo
kernel32.dll::GetStartupInfoA
kernel32.dll::GetDiskFreeSpaceA
kernel32.dll::GetCommandLineA
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileA
kernel32.dll::FindFirstFileA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegOpenKeyExA
advapi32.dll::RegQueryValueExA
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::CreateMenu
user32.dll::FindWindowA
user32.dll::PeekMessageA
user32.dll::CreateWindowExA

Comments