Rewterz
Rewterz Threat Alert – NJRAT – Active IOCs
July 12, 2022
Rewterz
Rewterz Threat Alert – APT MustangPanda – Active IOCs
July 12, 2022

Rewterz Threat Alert – AZORult Malware – Active IOCs

Severity

High

Analysis Summary

The AZORULT malware is an information stealer which was discovered in 2016. This malware steals IDs, browsing history, cookies, passwords, and other information. AZORult serves as a malware downloader and it was advertised on Russian underground forums as a way to extract sensitive data from compromised computers. Browser history, bitcoin, ID, cookies, and passwords can be stolen by this malware. Phishing emails and the Fallout Exploit Kit (EK), in combination with social engineering tactics, are the primary infection vectors for the AZORult virus. The virus can also act as a loader, allowing more malware to be downloaded.

Impact

  • Information Theft
  • Credential Theft
  • Exposure of Sensitive Data

Indicators of Compromise

MD5

  • 438cbbc5449ace7dc2f23c8f884a51e5
  • 131a32033cf88976a8df48361b90207d
  • 8f6bcccfa18eba6cdbeb716ce795ea83
  • 4153a781aaf6b3f9df717e4624409954

SHA-256

  • c56d7650cb69a9ecc1cb26d4324a0708ae5eea20e640b33e32bbcb45b58c0703
  • d75d7b0534ff648f16f5751be79a2c23158b6412a780180aec78c77c7e95071d
  • 38a38cd4d2b2ecef6cdaf804f4569647a5526011e29f233b0326cd0f06f30916
  • 10cd2cf9a16578b8b9a285f5b567e18c4189ca837321201214f62f04c9bd5940

SHA-1

  • e485f4b2797c6e3cb66c0fdcf388a4373b5dc495
  • ce260393460fa5d4cbfa17d3329fd33594810add
  • e3f8f390edf308a460130b4fd5436e0cb5b20811
  • dae7e2fb6b156fff8ca221528ad5c522dfc6bd45

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.