Trojan

How to remove “Trojan.AzorultRI.S26129306”?

Malware Removal

The Trojan.AzorultRI.S26129306 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AzorultRI.S26129306 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Argentina)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Creates a copy of itself
  • Created a service that was not started
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.AzorultRI.S26129306?


File Info:

name: DC0D6F8BC49173E96074.mlw
path: /opt/CAPEv2/storage/binaries/dc0dfeeb788194ed4bcd771d929e2291ecdd66b2789abda7b06744441243cfe6
crc32: F0B03007
md5: dc0d6f8bc49173e960747f64e79db21a
sha1: 3e749a152a9583d94ba637506d5ee0a527ca51e9
sha256: dc0dfeeb788194ed4bcd771d929e2291ecdd66b2789abda7b06744441243cfe6
sha512: afafe0096449922e6455849444a1e07bbaaa0fb1a57eaa1bdda2470622c25082385108b9400da2b28945b06e52367ba6c4297e2d395eb0bad1168ab21f5ceed5
ssdeep: 24576:62WFhBTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTn:6vFh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13DE66C30AAFCF951E4EF4A709535AAD85D39FC92A801427B2153370F29B1E8D4DE136E
sha3_384: 1755daf88193e2c79e264603cf3c79fc52db8dcc196aeae3cc17114e8afa5fb9271eb90123de4bdea89525adc0562663
ep_bytes: e82a5c0000e979feffffcccccccccccc
timestamp: 2020-09-17 17:12:33

Version Info:

InternationalName: bomgvioci.iwa
Copyright: Copyrighz (C) 2021, fudkort
ProjectVersion: 3.10.70.17
Translation: 0x0129 0x0794

Trojan.AzorultRI.S26129306 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.82209
FireEyeGeneric.mg.dc0d6f8bc49173e9
CAT-QuickHealTrojan.AzorultRI.S26129306
McAfeePacked-GEE!DC0D6F8BC491
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005690671 )
K7GWTrojan ( 005690671 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZexaF.34182.@tW@aWCdrwU
CyrenW32/Qbot.FK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNYK
ClamAVWin.Malware.Generic-9935529-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.GenericKDZ.82209
AvastWin32:CrypterX-gen [Trj]
TencentMalware.Win32.Gencirc.11e48912
Ad-AwareTrojan.GenericKDZ.82209
SophosML/PE-A + Mal/Agent-AWV
DrWebTrojan.DownLoader44.29818
ZillyaTrojan.Kryptik.Win32.3671592
McAfee-GW-EditionBehavesLike.Win32.Packed.th
EmsisoftTrojan.Crypt (A)
APEXMalicious
JiangminTrojan.Agent.ducf
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.3501DC6
MicrosoftRansom:Win32/StopCrypt.PAL!MTB
GDataWin32.Trojan.BSE.16VOW5Z
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPE.R464220
VBA32BScope.Trojan.Convagent
ALYacTrojan.GenericKDZ.82209
MalwarebytesTrojan.MalPack.GS
IkarusTrojan.Win32.Crypt
RisingTrojan.Kryptik!1.DB29 (RDMK:cmRtazpWlwGQTVbpk21QfgTX1OV+)
YandexTrojan.Agent!qDrJKBWz8C4
SentinelOneStatic AI – Suspicious PE
FortinetW32/GenKryptik.ERHN!tr
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.52a958
PandaTrj/GdSda.A

How to remove Trojan.AzorultRI.S26129306?

Trojan.AzorultRI.S26129306 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment