2021-08-05 (THURSDAY) - AZORULT DISTRIBUTED THROUGH MALSPAM

ASSOCIATED FILES:

  • 2021-08-05-AZORult-IOCs.txt   (1,629 bytes)
  • 2021-08-05-AZORult-malspam.eml   (449,578 bytes)
  • 2021-08-05-AZORult-infection.pcap   (5,687,946 bytes)
  • 24_AUGUST.xlsb   (237,505 bytes)
  • scwxc.exe   (689,664 bytes)

NOTES:

 

IMAGES


Shown above:  Screenshot of the malspam.

 


Shown above:  Screenshot of the malicious Excel spreadsheet.

 


Shown above:  Traffic from the infection filtered in Wireshark.

 


Shown above:  TCP stream showing the HTTP HEAD request and response for the AZORult EXE.

 


Shown above:  TCP stream showing the HTTP GET request and response for the AZORult EXE.

 


Shown above:  TCP stream showing start of AZORult post-infection traffic.

 


Shown above:  Windows EXE for AZORult saved to the infected Windows host.

 

Click here to return to the main page.