Rewterz
Rewterz Threat Advisory – Detection and Prevention of Web Shell Malware
August 22, 2021
Rewterz
Rewterz Threat Alert – NJRAT – Active IOCs
August 22, 2021

Rewterz Threat Alert – AZORult Malware – Active IOCs

Severity

Medium

Analysis Summary

AZORult is a payment card and credential information stealer. It was sold on Russian underground forums as a means to collect sensitive information from infected systems. The malware is also able to steal cookies, browsing history, cryptocurrency, and ID/passwords. Exploits such as phishing emails and Fallout Exploit Kit (EK) paired with social engineering techniques are major infection vectors of the AZORult malware.The malware can also be used as a loader to download other malware.

Impact

  • Information Theft
  • Credential Theft
  • Exposure of Sensitive Data

Indicators of Compromise

MD5

  • 6a4824ab00e63c2f1bbf29a24d78b2a4
  • c0e0a9d259bbf9faab7fd5049bf6b662
  • 70ded05d874a95b1b3027c1e97b16287
  • 7b7c13961dd5633dbd63837ba08aaed7

SHA-256

  • c5209b1b684e41df6739f73149653844ba2a6b603036e7667919fc1a01489486
  • 909cf19d116b61a8aba27f7f63d4b078a8f7dde3e28df3bc3d9643d0b93d3506
  • aca7a7d812ac2192255aa3d47477f13b05963da0383e459d6b09d1630cd11aae
  • 22a117c101443073379635cf75a22acfaa3dcc65c29bde65a3287d177147f2e1

SHA1

  • 8a6323955835bd3ebaa4aa15717e81f02b89fd89
  • 68d08417768fc5650c2bdec03d496c20435efeb0
  • b12023392be69985ba2e2fdc3094e80baeca55c0
  • e6c7f08a005b4f195cf1f0ac024442157dc0e8c0

URL

  • hxxp[:]//ciuj[[.]]ir/masab/index[.]php
  • hxxp[:]//jamesrlongacre[[.]]ug/index[.]php

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.