2021-08-05 (THURSDAY) - AZORULT DISTRIBUTED THROUGH MALSPAM
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2021-08-05-AZORult-IOCs.txt.zip 1.1 kB (1,095 bytes)
- 2021-08-05-AZORult-IOCs.txt (1,629 bytes)
- 2021-08-05-AZORult-malspam.eml.zip 309 kB (309,078 bytes)
- 2021-08-05-AZORult-malspam.eml (449,578 bytes)
- 2021-08-05-AZORult-infection.pcap.zip 3.6 MB (3,558,829 bytes)
- 2021-08-05-AZORult-infection.pcap (5,687,946 bytes)
- 2021-08-05-AZORult-malware.zip 832 kB (831,918 bytes)
- 24_AUGUST.xlsb (237,505 bytes)
- scwxc.exe (689,664 bytes)
IMAGES
Shown above: Screenshot of the malspam.
Shown above: Screenshot of the malicious Excel spreadsheet.
Shown above: Traffic from the infection filtered in Wireshark.
Shown above: TCP stream showing the HTTP HEAD request and response for the AZORult EXE.
Shown above: TCP stream showing the HTTP GET request and response for the AZORult EXE.
Shown above: TCP stream showing start of AZORult post-infection traffic.
Shown above: Windows EXE for AZORult saved to the infected Windows host.
Click here to return to the main page.