Trojan

How to remove “Trojan:Win32/Azorult.RFA!MTB”?

Malware Removal

The Trojan:Win32/Azorult.RFA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Azorult.RFA!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Collects information to fingerprint the system

How to determine Trojan:Win32/Azorult.RFA!MTB?


File Info:

name: BFE76785C9F85BAD141E.mlw
path: /opt/CAPEv2/storage/binaries/1daf637340b8a169ecea3ca8ebd32234bac6aea1152c32001b49b1594fee5197
crc32: E8D9CA45
md5: bfe76785c9f85bad141e7e80624aed3c
sha1: 73d8a841d71c7b03e2099c2c1d0cf9c4be8cecb5
sha256: 1daf637340b8a169ecea3ca8ebd32234bac6aea1152c32001b49b1594fee5197
sha512: 21f426f71601e2d74c946c5cce83f79d994a97af5df31201ea6ceb2c725001ac2c357955389812fd6fd6c724bef87418090d057d49f711c91f2c2aae1581cd18
ssdeep: 1536:27ax3H4XLAUDaiWDpNOPNDK0yxDbP8k2spVFy73PWJ5+TeEJc7xcV7Ej:SgHIL0T06bELsHFyLU5meECWp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FB14BE217D9CC472D6A396705426C3B06A3AB8723A708D473795176EDF313E2AF7A306
sha3_384: 0e0fa033dda243a83ee3698f117b96000728ac5fdd38fb7fa330b2d03dc7deba17b844f46b191ff7e40a03cacc26412e
ep_bytes: e89d2e0000e979feffff8bff558bec8b
timestamp: 2021-09-05 03:05:11

Version Info:

FileVersion: 21.79.127.9
Copyrighz: Copyrighz (C) 2022, fuzkorte
Translations: 0x0116 0x00d3

Trojan:Win32/Azorult.RFA!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Strab.4!c
tehtrisGeneric.Malware
DrWebTrojan.Siggen17.19930
CAT-QuickHealTrojan.AzorultPMF.S26916072
McAfeePacked-GDT!BFE76785C9F8
MalwarebytesTrojan.MalPack.GS
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKDZ.84631
K7GWTrojan ( 0058f1bc1 )
K7AntiVirusTrojan ( 0058f1bc1 )
CyrenW32/Kryptik.EYC.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HOQK
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Strab.gen
AlibabaTrojan:Win32/Azorult.e885f5b7
NANO-AntivirusTrojan.Win32.Mokes.jmsoqx
MicroWorld-eScanTrojan.GenericKDZ.84631
TencentWin32.Trojan.Strab.Plkp
Ad-AwareTrojan.GenericKDZ.84631
SophosMal/Generic-S + Mal/Agent-AWV
ComodoMalware@#3k462vf9nrxg1
ZillyaTrojan.Kryptik.Win32.3718759
TrendMicroTROJ_GEN.R06CC0DCF22
McAfee-GW-EditionPacked-GDT!BFE76785C9F8
FireEyeGeneric.mg.bfe76785c9f85bad
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Mokes.fje
WebrootW32.Trojan.Gen
AviraTR/AD.PhobosRansom.wsqdx
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Azorult.RFA!MTB
ArcabitTrojan.Generic.D14A97
GDataWin32.Trojan.Kryptik.SE
VBA32Trojan.Agent
ALYacTrojan.GenericKDZ.84631
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R06CC0DCF22
RisingTrojan.Kryptik!1.DC53 (CLOUD)
IkarusTrojan.Win32.Azorult
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FilecoderPhobos.F!tr.ransom
AVGWin32:AceCrypter-K [Cryp]
Cybereasonmalicious.1d71c7
AvastWin32:AceCrypter-K [Cryp]

How to remove Trojan:Win32/Azorult.RFA!MTB?

Trojan:Win32/Azorult.RFA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment