Trojan

Should I remove “Trojan.AzorultPMF.S24966815”?

Malware Removal

The Trojan.AzorultPMF.S24966815 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AzorultPMF.S24966815 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Paraguay)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Trojan.AzorultPMF.S24966815?


File Info:

name: 9681C9EE21333A789692.mlw
path: /opt/CAPEv2/storage/binaries/7d40ba14216748e48cade38e8b3013746172b8df1d72c799eec42eb893903325
crc32: DF135EDD
md5: 9681c9ee21333a789692822205291748
sha1: 373398f72d15639a1dbac6e4a29b29221da85b3f
sha256: 7d40ba14216748e48cade38e8b3013746172b8df1d72c799eec42eb893903325
sha512: e6863af4fbb39a670573a81a2f97d15d3b247a3fe4d3381694c0a2ee16d73f9bc4787cb7e69083d86433d413215428048cf9c27c5f408a38b98e4896a68d8fc8
ssdeep: 6144:tPq6ynnisgCoMZk6Tep1oAZQSXuZet0ySbgHxYJ9VbKqlne:k6uvgYkE61oQQSXuZet0ySbgi9VbV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B3549E0467A0C435F1B746F889BA93B97D3EBDA16B3890CB62D126EA47356E0DD30347
sha3_384: c6d9887a29892c9f0c1ba393ee7f5261dab7adc89fd9868fbd2a5433d439e4ea59d7f3b31f31af44f997536f7adc3450
ep_bytes: 8bff558bece806030000e8110000005d
timestamp: 2020-09-29 00:04:16

Version Info:

0: [No Data]

Trojan.AzorultPMF.S24966815 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Chapak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.50855
MicroWorld-eScanTrojan.GenericKDZ.81106
FireEyeGeneric.mg.9681c9ee21333a78
CAT-QuickHealTrojan.AzorultPMF.S24966815
McAfeePacked-GDT!9681C9EE2133
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3636036
SangforTrojan.Win32.Chapak.gen
K7AntiVirusTrojan ( 0058a5a11 )
AlibabaMalware:Win32/km_24af8.None
K7GWTrojan ( 0058a5a11 )
Cybereasonmalicious.72d156
CyrenW32/Kryptik.FQI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNKJ
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXBKXZ
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderTrojan.GenericKDZ.81106
AvastWin32:DropperX-gen [Drp]
Ad-AwareTrojan.GenericKDZ.81106
SophosMal/Generic-R + Troj/Krypt-DY
BaiduWin32.Trojan.Kryptik.jm
TrendMicroTrojan.Win32.SMOKELOADER.YXBKXZ
McAfee-GW-EditionBehavesLike.Win32.Injector.dm
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11CIAVD
JiangminTrojanSpy.Stealer.iho
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.Agent.dehya
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.34D8268
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftTrojan.Win32.Downloader.sa
ViRobotTrojan.Win32.Z.Undef.297472
MicrosoftTrojan:Win32/Azorult.RMA!MTB
CynetMalicious (score: 100)
AhnLab-V3CoinMiner/Win.Glupteba.R452572
Acronissuspicious
VBA32BScope.Trojan.Krypter
ALYacTrojan.GenericKDZ.81106
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
IkarusTrojan.Agent
eGambitUnsafe.AI_Score_91%
FortinetW32/Kryptik.FSC!tr
WebrootW32.Trojan.Gen
AVGWin32:DropperX-gen [Drp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.AzorultPMF.S24966815?

Trojan.AzorultPMF.S24966815 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment