AZORult is an information stealer malware that is targeted at stealing credentials and accounts. Updated multiple times over the years, AZORult continues to be an active concern for the users, stealing information such as banking passwords, credit card details, browser histories, and even cryptocurrency.
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Connects to CnC server
|
Creates files in the user directory
|
No info indicators. |
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0005F308 | 0x00060000 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ | 5.92695 |
.data | 0x00061000 | 0x000029BC | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x00064000 | 0x000009C8 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 2.20928 |
No exports.
Click at the process to see the details.
Image |
---|
c:\users\admin\appdata\local\temp\quotation.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvbvm60.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\sxs.dll |
c:\windows\system32\version.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\dhcpcsvc.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\apphelp.dll |
Image |
---|
c:\systemroot\system32\ntdll.dll |
c:\users\admin\appdata\local\temp\quotation.exe |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvbvm60.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\sxs.dll |
c:\windows\system32\version.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\dhcpcsvc.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\apphelp.dll |
Image |
---|
c:\users\admin\appdata\local\temp\quotation.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\crtdll.dll |
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\iertutil.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\rasapi32.dll |
c:\windows\system32\rasman.dll |
c:\windows\system32\rtutils.dll |
c:\windows\system32\sensapi.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\version.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\fwpuclnt.dll |
c:\users\admin\appdata\local\temp\2fda\nss3.dll |
c:\users\admin\appdata\local\temp\2fda\mozglue.dll |
c:\windows\system32\dbghelp.dll |
c:\users\admin\appdata\local\temp\2fda\msvcp140.dll |
c:\users\admin\appdata\local\temp\2fda\vcruntime140.dll |
c:\users\admin\appdata\local\temp\2fda\api-ms-win-crt-runtime-l1-1-0.dll |
c:\windows\system32\ucrtbase.dll |
c:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll |
c:\windows\system32\api-ms-win-core-file-l2-1-0.dll |
c:\windows\system32\api-ms-win-core-localization-l1-2-0.dll |
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll |
c:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll |
c:\windows\system32\api-ms-win-core-file-l1-2-0.dll |
c:\users\admin\appdata\local\temp\2fda\api-ms-win-crt-string-l1-1-0.dll |
c:\users\admin\appdata\local\temp\2fda\api-ms-win-crt-heap-l1-1-0.dll |
c:\users\admin\appdata\local\temp\2fda\api-ms-win-crt-stdio-l1-1-0.dll |
c:\users\admin\appdata\local\temp\2fda\api-ms-win-crt-convert-l1-1-0.dll |
c:\users\admin\appdata\local\temp\2fda\api-ms-win-crt-locale-l1-1-0.dll |
c:\users\admin\appdata\local\temp\2fda\api-ms-win-crt-math-l1-1-0.dll |
c:\users\admin\appdata\local\temp\2fda\api-ms-win-crt-multibyte-l1-1-0.dll |
c:\users\admin\appdata\local\temp\2fda\api-ms-win-crt-time-l1-1-0.dll |
c:\users\admin\appdata\local\temp\2fda\api-ms-win-crt-filesystem-l1-1-0.dll |
c:\users\admin\appdata\local\temp\2fda\api-ms-win-crt-environment-l1-1-0.dll |
c:\users\admin\appdata\local\temp\2fda\api-ms-win-crt-utility-l1-1-0.dll |
c:\windows\system32\winmm.dll |
c:\windows\system32\wsock32.dll |
c:\users\admin\appdata\local\temp\2fda\softokn3.dll |
c:\users\admin\appdata\local\temp\2fda\freebl3.dll |
c:\windows\system32\vaultcli.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\ieframe.dll |
c:\windows\system32\psapi.dll |
c:\windows\system32\oleacc.dll |
c:\windows\system32\mlang.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\propsys.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\apphelp.dll |
Image |
---|
c:\windows\system32\cmd.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\winbrand.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\timeout.exe |
Image |
---|
c:\windows\system32\timeout.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\version.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3976 | Quotation.exe | POST | 200 | 104.27.150.73:80 | http://wolfftradding.pl/ijarut/index.php | US |
text
binary
|
|
malicious |
PID | Process | IP | ASN | CN | Reputation |
---|---|---|---|---|---|
3976 | Quotation.exe | 104.27.150.73:80 | Cloudflare Inc | US | shared |
PID | Process | Class | Message |
---|---|---|---|
3976 | Quotation.exe | A Network Trojan was detected | ET TROJAN AZORult Variant.4 Checkin M2 |
3976 | Quotation.exe | A Network Trojan was detected | AV TROJAN Azorult CnC Beacon |
3976 | Quotation.exe | A Network Trojan was detected | AV TROJAN AZORult CnC Beacon |
3976 | Quotation.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult client request |
3976 | Quotation.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult.Stealer HTTP Header |
3976 | Quotation.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult.Stealer HTTP Header |
3976 | Quotation.exe | A Network Trojan was detected | MALWARE [PTsecurity] AZORult client request |
No debug info.