Rewterz Threat Advisory – CVE-2021-44757 – Zoho Fixes Critical Vulnerability
January 18, 2022Rewterz Threat Alert – FormBook Malware – Active IOCs
January 18, 2022Rewterz Threat Advisory – CVE-2021-44757 – Zoho Fixes Critical Vulnerability
January 18, 2022Rewterz Threat Alert – FormBook Malware – Active IOCs
January 18, 2022Severity
High
Analysis Summary
The AZORULT malware is an information stealer which was discovered in 2016. This malware steals IDs, browsing history, cookies, passwords, and other information. AZORult serves as a malware downloader and it was advertised on Russian underground forums as a way to extract sensitive data from compromised computers. Browser history, bitcoin, ID, cookies, and passwords can be stolen by this malware. Phishing emails and the Fallout Exploit Kit (EK), in combination with social engineering tactics, are the primary infection vectors for the AZORult virus. The virus can also act as a loader, allowing more malware to be downloaded.
Impact
- Information Theft
- Credential Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- f6d6341191771bbb8f19bb8fe1649373
- 7fd4108b3c3b9548ebdceffd15d5aba4
- 30a13b555af375657675ecb0cb645725
- 9b04ee2bca8a665b443b412f61a0b8dc
SHA-256
- 2a2ad82e6929d1bdd6ab3cde2f791cff3aae68f2e550271d3ebb53d7ddbe4e9b
- 1032f45da46e60c23dacd53f9bd8bc08446a771d9d3e998d0fa5310cfd3fbc5a
- 4166d0e0b5adc0558a58722e20f0e77bdecfe25097239dcb21c4757631d0f5b9
- 00560a50e280b40c594bd2b6a7b2997e267df56293cdfbee9d802d545cbf61bf
SHA-1
- dfce3da73a3055a7c561b6db01707236451dbde1
- 0229e18275b882f60e26933c1121c44bb2c080b4
- b48140c4534aee2ceeb3fa7bda06bf024e1dee37
- 22bd0fbc51ae74b6e6e7e55649eec74db3e7fc05
Remediation
Block all threat indicators at your respective controls.
Search for IOCs in your environment.