MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eb5c42c60c0920dbd637295b097801bb65b209f2c362dcdd0a8816dd27169bc6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AZORult


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: eb5c42c60c0920dbd637295b097801bb65b209f2c362dcdd0a8816dd27169bc6
SHA3-384 hash: 25dea5e04fd06a3479f1d3d14e7d4406493041d81a3f7a6f7f76c6a81596c78cebf0a3886f82a2df2a033e460578448b
SHA1 hash: e7cfd49bdc07e77c92e30286c656c88a8aabde59
MD5 hash: cc9923519f5997f925ae1ce4899a76ab
humanhash: sodium-hamper-mirror-charlie
File name:Company Profile.zip
Download: download sample
Signature AZORult
File size:572'195 bytes
First seen:2020-08-31 05:46:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:FNk/O1VuR5oW39MMBgPhfo5VheBN9Xcyt47QQ9Lv+6bIHy4mI+VR:F2/O1VTUxgNJcyt4739vES4AVR
TLSH 1CC423DD929841C48FED6B644CB317EA9A2DCD5E2B83A084ECA0C5535C202F51979EFF
Reporter abuse_ch
Tags:AZORult zip


Avatar
abuse_ch
Malspam distributing AZORult:

HELO: server.sgbcg.com
Sending IP: 113.11.251.241
From: Talaat.Shawky@yanartrading.com
Reply-To: Talaat Shawky <pee@eloquentcs.com>
Subject: YANAR Trading - RFQ Products.
Attachment: Company Profile.zip (contains "Company Profile.exe")

AZORult C2:
http://51.83.105.108/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
243
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Zusy
Status:
Malicious
First seen:
2020-08-31 00:17:10 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AZORult

zip eb5c42c60c0920dbd637295b097801bb65b209f2c362dcdd0a8816dd27169bc6

(this sample)

  
Dropping
AZORult
  
Delivery method
Distributed via e-mail attachment

Comments