General

  • Target

    b731a6c7110d0ed272e977babaa204f6_JaffaCakes118

  • Size

    538KB

  • Sample

    240617-g7nmhaybph

  • MD5

    b731a6c7110d0ed272e977babaa204f6

  • SHA1

    90a7fc73fdcbf4d51af667818ba4b22f15d6634a

  • SHA256

    da6d45fd39478c021900718f516197ec10fca556936a3960e13e787bdda1b5ea

  • SHA512

    cf95608a960c010d0c0a0dc0440b56f0d79d93ec5608b5e6a0522c8a6b4cb5d847033c8527634de8f872d729fe2188dbd06350137b95654045ee78407a44a145

  • SSDEEP

    6144:r2GhNafuzces6tYAG5zyAHax1XOnJyut/u7b2PBCb+/MsqwltKAibwc8Np5:r2iNaGzKZYkm+UxPsZw1wv1

Malware Config

Extracted

Family

azorult

C2

http://adtechsolutions.in/buda/32/index.php

Targets

    • Target

      b731a6c7110d0ed272e977babaa204f6_JaffaCakes118

    • Size

      538KB

    • MD5

      b731a6c7110d0ed272e977babaa204f6

    • SHA1

      90a7fc73fdcbf4d51af667818ba4b22f15d6634a

    • SHA256

      da6d45fd39478c021900718f516197ec10fca556936a3960e13e787bdda1b5ea

    • SHA512

      cf95608a960c010d0c0a0dc0440b56f0d79d93ec5608b5e6a0522c8a6b4cb5d847033c8527634de8f872d729fe2188dbd06350137b95654045ee78407a44a145

    • SSDEEP

      6144:r2GhNafuzces6tYAG5zyAHax1XOnJyut/u7b2PBCb+/MsqwltKAibwc8Np5:r2iNaGzKZYkm+UxPsZw1wv1

    • Azorult

      An information stealer that was first discovered in 2016, targeting browsing history and passwords.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks