Trojan

Trojan.AzorultPMF.S25378462 information

Malware Removal

The Trojan.AzorultPMF.S25378462 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AzorultPMF.S25378462 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Macedonian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics

How to determine Trojan.AzorultPMF.S25378462?


File Info:

name: 69A785EA093A48289F06.mlw
path: /opt/CAPEv2/storage/binaries/756eb78b44608ecf180638a4bafd6d1f840372d47297a4c074a0f4fd1f5b5d1b
crc32: CFEB54C3
md5: 69a785ea093a48289f064347e292d90f
sha1: 3793ac1889c2d74637d2e80304d425b165b94a72
sha256: 756eb78b44608ecf180638a4bafd6d1f840372d47297a4c074a0f4fd1f5b5d1b
sha512: bbae19d686f49a81202cc91b156c92502b49b5d9600d5f351e561469c90799e66e09f1c9afea928f20afb159a4f3999ed57edce7cd68648769a0e0c2bfa22eda
ssdeep: 6144:mzbMFZ2xBEmZlUkXPCsLQgWEztygsgH0o2NYjPLMdR95tMBzGWFUtsc49l:m8rrS5fC2QcZyHgH0oRjPcf4yTtsZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D94E02132D0C073C05665B68C25CBB0AEBAB47556225A8FFFC85FBD9F247D2972530A
sha3_384: c14ca1c89dad893a51a8dcf7a5e0a59645cb550ed9e101f90cfa6ac9d9b50135f41bb6dccad72c88faa4a03b3bd0c4df
ep_bytes: e8b5660000e978feffffcccccccccccc
timestamp: 2020-06-14 07:33:08

Version Info:

FileVers: 65.51.36.16
ProductVersa: 7.50.25.71
InternalName: peatemas
LegalCopyrighd: sharnir
Translations: 0x0169 0x0300

Trojan.AzorultPMF.S25378462 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47580618
FireEyeGeneric.mg.69a785ea093a4828
CAT-QuickHealTrojan.AzorultPMF.S25378462
McAfeeRDN/RedLineStealer
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058b7b21 )
AlibabaTrojanSpy:Win32/Azorult.a7839934
K7GWTrojan ( 0058b7b21 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34114.zq1@aKgPD1dG
CyrenW32/Kryptik.FXB.gen!Eldorado
SymantecPacked.Generic.620
ESET-NOD32a variant of Win32/Kryptik.HNOU
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKD.47580618
SUPERAntiSpywareTrojan.Agent/Generic
AvastWin32:DropperX-gen [Drp]
TencentMalware.Win32.Gencirc.11dba7df
Ad-AwareTrojan.GenericKD.47580618
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/Crypt.Agent.zlpeh
DrWebTrojan.PWS.Siggen3.7921
ZillyaTrojan.Kryptik.Win32.3641245
TrendMicroTROJ_GEN.R002C0DLA21
McAfee-GW-EditionBehavesLike.Win32.Dropper.gc
SophosMal/Generic-R + Troj/Krypt-BO
IkarusTrojan.Win32.Azorult
GDataTrojan.GenericKD.47580618
JiangminTrojanSpy.Stealer.kgt
AviraTR/Crypt.Agent.zlpeh
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.34E85DE
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2D605CA
MicrosoftTrojan:Win32/Azorult.RM!MTB
CynetMalicious (score: 100)
AhnLab-V3CoinMiner/Win.Glupteba.R456691
Acronissuspicious
VBA32Trojan.Agent
ALYacTrojan.GenericKD.47580618
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R002C0DLA21
RisingTrojan.Kryptik!1.DAF8 (CLASSIC)
YandexTrojan.Kryptik!0h3l7IS8p8I
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_89%
FortinetW32/Kryptik.HNOL!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.889c2d
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.73793603.susgen

How to remove Trojan.AzorultPMF.S25378462?

Trojan.AzorultPMF.S25378462 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment