Trojan

Should I remove “Trojan.AzorultPMF.S25015837”?

Malware Removal

The Trojan.AzorultPMF.S25015837 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AzorultPMF.S25015837 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Urdu (India)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location

How to determine Trojan.AzorultPMF.S25015837?


File Info:

name: 85DBD51DE8867AD2F95A.mlw
path: /opt/CAPEv2/storage/binaries/a404346de4709d81426f4769006727904a018fbbd86db8194a0b24c00b774390
crc32: 70B3F664
md5: 85dbd51de8867ad2f95a44d9a0d656c0
sha1: 72574ffe2f49d3dd9e9a16becb9728ebf7715015
sha256: a404346de4709d81426f4769006727904a018fbbd86db8194a0b24c00b774390
sha512: 5959b4b117cd1b178bc6702b0b4b3ff3f4e3656be6dd93cc86c59126ba66c63b72ae8eaf90b1dba95a816350097e48dc4bef126cf5f6a24a9ef6cbe11300b79c
ssdeep: 3072:wXGe/n/3KWWhovhV71eOYOtlpPL2Ernpr/ni2:kH3ihovhzewpr/nt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FE3AF1032D18035D5A7563069B4EAA12E7ABC326675C18F73A452FF1FF02D1DAA13EB
sha3_384: a86bc11c5586f2528878e0fa99aed7ea93314ff753b6681c9cbc1d09228be390e8e7afab83a56de2f6d7204325867b20
ep_bytes: e8502a0000e989feffffcccccccccccc
timestamp: 2020-07-04 05:14:43

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.77.27
Translation: 0x0114 0x046a

Trojan.AzorultPMF.S25015837 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
CAT-QuickHealTrojan.AzorultPMF.S25015837
McAfeeLockbit-FSWW!85DBD51DE886
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058af711 )
BitDefenderGen:Heur.Mint.Titirez.jq0@mrtngToG
K7GWTrojan ( 0058af711 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Kryptik.FUG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNLS
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaRansom:Win32/StopCrypt.53b75ae8
NANO-AntivirusTrojan.Win32.MalwareCrypter.jilcwf
MicroWorld-eScanGen:Heur.Mint.Titirez.jq0@mrtngToG
RisingBackdoor.Tofsee!8.1E9 (TFE:dGZlOgVZbPPE9oaOFw)
Ad-AwareGen:Heur.Mint.Titirez.jq0@mrtngToG
SophosMal/Generic-S + Troj/Krypt-BO
DrWebTrojan.DownLoader44.6089
ZillyaTrojan.Kryptik.Win32.3644411
TrendMicroTrojan.Win32.SMOKELOADER.YXBK2Z
McAfee-GW-EditionBehavesLike.Win32.Emotet.ch
FireEyeGeneric.mg.85dbd51de8867ad2
EmsisoftTrojan.Crypt (A)
IkarusTrojan-Ransom.StopCrypt
GDataWin32.Trojan.BSE.11GYDBI
JiangminTrojan.Agent.dsci
AviraTR/AD.MalwareCrypter.teenk
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.34D9A27
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/StopCrypt.PU!MTB
AhnLab-V3Trojan/Win.FSWW.R453623
Acronissuspicious
VBA32Backdoor.Mokes
ALYacGen:Heur.Mint.Titirez.jq0@mrtngToG
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXBK2Z
TencentTrojan.Win32.Stop.16000125
YandexTrojan.Kryptik!hcsrz/8SXZc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_93%
FortinetW32/Lockbit.FSWW!tr
BitDefenderThetaGen:NN.ZexaF.34182.jq0@aqtngToG
AVGWin32:Malware-gen
Cybereasonmalicious.e2f49d
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.AzorultPMF.S25015837?

Trojan.AzorultPMF.S25015837 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment