Trojan

Trojan-PSW.Win32.Azorult.vpy (file analysis)

Malware Removal

The Trojan-PSW.Win32.Azorult.vpy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Azorult.vpy virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Serbian
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
iplogger.org
a.tomx.xyz
gcleaner.ru

How to determine Trojan-PSW.Win32.Azorult.vpy?


File Info:

crc32: D54748E9
md5: d4d27e4f161301c83aedbba11586da16
name: D4D27E4F161301C83AEDBBA11586DA16.mlw
sha1: b6652db4608866aec88cde3b563853e72529e134
sha256: e0142ffffdbf3e64c432bc155f5f6ca9ec9377844ea8458563ec3639e60df0ed
sha512: 726cee950d910f62104c7e3c024309de0283e265a0bdca02c07d5d2d4f854f0c05491a91c398b8c9e6c8555141507da97bbda196f307318fac80c1e5757d39e6
ssdeep: 12288:BOaA/iM0AW9+/8SWp6rS5QCr9s8SDqekg7d:4aA/iM0AxApWfqFz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-PSW.Win32.Azorult.vpy also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Azorult.4!c
Elasticmalicious (high confidence)
ClamAVWin.Malware.Score-6995873-0
CAT-QuickHealRansom.Stop.MP4
ALYacTrojan.Brsecmon.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1667698
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanPSW:Win32/Kryptik.de1ad6da
K7GWTrojan ( 0055204a1 )
K7AntiVirusTrojan ( 0055204a1 )
CyrenW32/S-d75e9604!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GTZE
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Azorult.vpy
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Azorult.frigwd
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan-qqpass.Qqrob.Wstm
Ad-AwareTrojan.Brsecmon.1
SophosML/PE-A + Mal/GandCrab-G
ComodoTrojWare.Win32.Fakecsrss.AV@88nqyj
BitDefenderThetaGen:NN.ZexaF.34170.CuW@aKWQpIdG
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionSodinokibi!D4D27E4F1613
FireEyeGeneric.mg.d4d27e4f161301c8
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Azorult.cho
WebrootW32.Trojan.Gen
AviraTR/AD.Chapak.ees
Antiy-AVLTrojan/Generic.ASMalwS.2BE8BD0
MicrosoftTrojan:Win32/Kryptik.DR!MTB
ArcabitTrojan.Brsecmon.1
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
GDataTrojan.Brsecmon.1
TACHYONTrojan-PWS/W32.Azorult.473088
AhnLab-V3Win-Trojan/MalPe25.Suspicious.X2021
Acronissuspicious
McAfeeSodinokibi!D4D27E4F1613
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingRansom.Sodinokibi!1.CA18 (CLASSIC)
IkarusTrojan-Ransom.Sodinokibi
MaxSecureRansomeware.GandCrypt.Gen
FortinetW32/GenKryptik.DQHN!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan-PSW.Win32.Azorult.vpy?

Trojan-PSW.Win32.Azorult.vpy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment