Rewterz Threat Alert – APT SideWinder Group – Active IOCs
June 17, 2022Rewterz Threat Update – BlackCat Ransomware Group Publishes Victims’ Data On The Clear Web
June 17, 2022Rewterz Threat Alert – APT SideWinder Group – Active IOCs
June 17, 2022Rewterz Threat Update – BlackCat Ransomware Group Publishes Victims’ Data On The Clear Web
June 17, 2022Severity
Medium
Analysis Summary
The AZORULT malware is an information stealer which was discovered in 2016. This malware steals IDs, browsing history, cookies, passwords, and other information. AZORult serves as a malware downloader and it was advertised on Russian underground forums as a way to extract sensitive data from compromised computers. Browser history, bitcoin, ID, cookies, and passwords can be stolen by this malware. Phishing emails and the Fallout Exploit Kit (EK), in combination with social engineering tactics, are the primary infection vectors for the AZORult virus. The virus can also act as a loader, allowing more malware to be downloaded.
Impact
- Information Theft
- Credential Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- fd2941ef783596e86cbd69d59e605deb
- fe78ff52af137e85b04ca7b6ca033713
- 2f953fbeffe9c0830ee8d57ffa186a70
- 1833589c607ac469b174b2814369ce61
SHA-256
- eef91c02acd9d1d358478506fa350970844320d199e18323864ece1d59c6a0d2
- 88bc64e5717a856b01a04684c7e69114d309d52a885de9fc759e5a99ac20afd5
- 60fb564c1cf5881fb5ca9400b84833db2a45f8ea221e9db4c4a24793646e2efe
- a5bb96d731ef58cf17cc579578ab89c7c46f275982be8eb137ff64268dff1efc
SHA-1
- a3bfe07450df0fb9ea769dab9c8b944a403f255b
- d214624809b7d99aa5136330f868c7afca3a48be
- 344491d4f32c9bdb4fecba67fc34a5223b5cca5a
- cf9f0075bab1121727670149313ad19b4bdd5329
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.