

Rewterz Threat Alert – GuLoader Malspam Campaign – Active IOCs
March 18, 2022
Rewterz Threat Alert – Ursnif Banking Trojan – Active IOCs
March 18, 2022
Rewterz Threat Alert – GuLoader Malspam Campaign – Active IOCs
March 18, 2022
Rewterz Threat Alert – Ursnif Banking Trojan – Active IOCs
March 18, 2022Severity
High
Analysis Summary
The AZORULT malware is an information stealer which was discovered in 2016. This malware steals IDs, browsing history, cookies, passwords, and other information. AZORult serves as a malware downloader and it was advertised on Russian underground forums as a way to extract sensitive data from compromised computers. Browser history, bitcoin, ID, cookies, and passwords can be stolen by this malware. Phishing emails and the Fallout Exploit Kit (EK), in combination with social engineering tactics, are the primary infection vectors for the AZORult virus. The virus can also act as a loader, allowing more malware to be downloaded.
Impact
- Information Theft
- Credential Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 3b753f760f97b526392a2d7cd2f034b8
SHA-256
- 6fd11b4a09db2c2713edbe0bb7536402e7e7bf0255ed7b80c6dc4d934938e327
SHA-1
- c746419307c55d44f9b7341efcaaa4ac1ee6e7dc
Remediation
Block all threat indicators at your respective controls.
Search for IOCs in your environment.