Rewterz Threat Alert – Vidar Malware – Active IOCs
June 28, 2022Rewterz Threat Alert – BumbleBee Malware – Active IOCs
June 28, 2022Rewterz Threat Alert – Vidar Malware – Active IOCs
June 28, 2022Rewterz Threat Alert – BumbleBee Malware – Active IOCs
June 28, 2022Severity
High
Analysis Summary
The AZORULT malware is an information stealer which was discovered in 2016. This malware steals IDs, browsing history, cookies, passwords, and other information. AZORult serves as a malware downloader and it was advertised on Russian underground forums as a way to extract sensitive data from compromised computers. Browser history, bitcoin, ID, cookies, and passwords can be stolen by this malware. Phishing emails and the Fallout Exploit Kit (EK), in combination with social engineering tactics, are the primary infection vectors for the AZORult virus. The virus can also act as a loader, allowing more malware to be downloaded.
Impact
- Information Theft
- Credential Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 784eab90de34489e035dbaf9df509704
- d7534c12aabe7dbce577d03b0de79e02
SHA-256
- dfc19a780fe5e0ee317afe7c21a51538f2d1a112fe21fcdaee038cb138cf411d
- 1362be545c6b048d9819735da8f6954d504da9c614db1775a18c8a0557de3c0a
SHA-1
- 62505128d4647e919989e4a885f6cb094bfee36b
- 4768be86ff5a370d476fd31cec8d217bd2e2adb7
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.