ATT&CKReferencesProofpoint Azorult July 2018

Proofpoint Azorult July 2018

Proofpoint. (2018, July 30). New version of AZORult stealer improves loading features, spreads alongside ransomware in new campaign. Retrieved November 29, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareAzorult

Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot.

T1082
System Information Discovery
MalwareAzorult

Azorult can collect the machine information, system architecture, the OS version, computer name, Windows product name, the number of CPU cores, video card information, and the system language.

T1105
Ingress Tool Transfer
MalwareAzorult

Azorult can download and execute additional files. Azorult has also downloaded a ransomware payload called Hermes.

T1124
System Time Discovery
MalwareAzorult

Azorult can collect the time zone information from the system.

T1140
Deobfuscate/Decode Files or Information
MalwareAzorult

Azorult uses an XOR key to decrypt content and uses Base64 to decode the C2 address.

T1573.001
Symmetric Cryptography
MalwareAzorult

Azorult can encrypt C2 traffic using XOR.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.