Trojan

Trojan-PSW.Win32.Azorult.aiqd (file analysis)

Malware Removal

The Trojan-PSW.Win32.Azorult.aiqd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Azorult.aiqd virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
drjones88ave.com

How to determine Trojan-PSW.Win32.Azorult.aiqd?


File Info:

crc32: 72D8F884
md5: e4b0d0200d65486f3d08127049178f83
name: wrar580.exe
sha1: accacabc25027c88a372d8f265e4e9c99033df5d
sha256: 68c29062b4865c602cddf27c85c9fa8ddf34b703e68e897e160bd54c25fecdd8
sha512: 8cf27bbd47bc13967bd30282a7eee57e7198de63e2f1fb1c4da7fa53d91b9b7d5d8b4989554a94e4fa8b54132ca851c79d968994e0891c8f6a82c61b9faa6ec1
ssdeep: 24576:u53uhF5UvfiS24z6BqVAoUYcNL/0pLaYiYf2q9AUy:u5+hFiM4z/kL8PfVs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: flunking
FileVersion: 19.82.0.28
CompanyName: viewfortydinnerbegankeepKenya<
Builder: burangulov.askar@gmail.com 08:47:20 23/12/2019
Created: 7z SFX Constructor v4.5.0.0 (http://usbtor.ru/viewtopic.php?t=798)
LegalTrademarks: drink*sort*grain*Friday*almost*signal]
Comments: provide-travel-exciting-please-care-half>
ProductName: Coconscious3
ProductVersion: 19.82.0.28
OriginalFilename: flunking.exe
Translation: 0x0000 0x04b0

Trojan-PSW.Win32.Azorult.aiqd also known as:

MicroWorld-eScanTrojan.PasswordStealer.GenericKD.32913894
McAfeeArtemis!E4B0D0200D65
BitDefenderTrojan.GenericKD.42215773
Cybereasonmalicious.c25027
ArcabitTrojan.PasswordStealer.Generic.D1F639E6
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.BWPGPIQ
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Azorult.aiqd
AlibabaTrojan:Win32/Predator.ali2000022
Ad-AwareTrojan.PasswordStealer.GenericKD.32913894
EmsisoftTrojan.GenericKD.42215773 (B)
McAfee-GW-EditionArtemis
FortinetW32/Generik.BWPGPIQ!tr
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.e4b0d0200d65486f
SophosMal/Generic-S
JiangminTrojan.Generic.amval
WebrootW32.Trojan.GenKD
MAXmalware (ai score=82)
Endgamemalicious (high confidence)
ZoneAlarmTrojan-PSW.Win32.Azorult.aiqd
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
GDataWin32.Trojan-Stealer.Azorult.9XTICX
BitDefenderThetaGen:NN.ZexaF.33558.fr3@aSYWSnf
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-PSW.Win32.Azorult.aiqd?

Trojan-PSW.Win32.Azorult.aiqd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment