Rewterz Threat Alert – LockBit 3.0 Ransomware – Active IOCs
July 21, 2022Rewterz Threat Advisory – CVE-2022-20861 – Cisco Nexus Dashboard Vulnerability
July 21, 2022Rewterz Threat Alert – LockBit 3.0 Ransomware – Active IOCs
July 21, 2022Rewterz Threat Advisory – CVE-2022-20861 – Cisco Nexus Dashboard Vulnerability
July 21, 2022Severity
High
Analysis Summary
The AZORULT malware is an information stealer which was discovered in 2016. This malware steals IDs, browsing history, cookies, passwords, and other information. AZORult serves as a malware downloader and it was advertised on Russian underground forums as a way to extract sensitive data from compromised computers. Browser history, bitcoin, ID, cookies, and passwords can be stolen by this malware. Phishing emails and the Fallout Exploit Kit (EK), in combination with social engineering tactics, are the primary infection vectors for the AZORult virus. The virus can also act as a loader, allowing more malware to be downloaded.
Impact
- Information Theft
- Credential Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- a2b9efea590696dd7255d667730ca683
- 085945894359889fc3168c9ead4ec36d
- f49276c8ddb872c2e207d3f01fdd8dd3
SHA-256
- 7ae28df7080800df2ff68c8bd20ad4d284af6d875e33c92fe0f38e6686d5a90e
- 9c17b08702418e52671e7a7d48db8375fd7a29bcb5654b4d54354efb7eef041d
- 3dff06d73e16ec5512b856f9367ad4eb892244daa07196ddacdba5f48885c8e9
SHA-1
- e7ed37a383d2aca4b72ec0b92472c47837ef7982
- 6d8884713b2fef8b04f34b42cd6f1018d6097c47
- 87b27c182336b6770047f49c0e44b1be839161ac
URL
- http[:]//autocracking[.]com
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.