

Rewterz Threat Alert – Ramnit Malware – Active IOCs
July 16, 2022
Rewterz Threat Alert – Amadey Botnet – Active IOCs
July 16, 2022
Rewterz Threat Alert – Ramnit Malware – Active IOCs
July 16, 2022
Rewterz Threat Alert – Amadey Botnet – Active IOCs
July 16, 2022Severity
High
Analysis Summary
The AZORULT malware is an information stealer which was discovered in 2016. This malware steals IDs, browsing history, cookies, passwords, and other information. AZORult serves as a malware downloader and it was advertised on Russian underground forums as a way to extract sensitive data from compromised computers. Browser history, bitcoin, ID, cookies, and passwords can be stolen by this malware. Phishing emails and the Fallout Exploit Kit (EK), in combination with social engineering tactics, are the primary infection vectors for the AZORult virus. The virus can also act as a loader, allowing more malware to be downloaded.
Impact
- Information Theft
- Credential Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 3d52a7cb61220a3e0fa5b579fcf318d5
SHA-256
- 8955fde86ffc02568ef3eedf2b552a9024f1fa5a1af1ab4cd8bb4066b943f9ab
SHA-1
- d37558725e7297643ec9f0fb91082c3039a28f39
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.