Trojan

Trojan:Win32/Azorult.RF!MTB removal instruction

Malware Removal

The Trojan:Win32/Azorult.RF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Azorult.RF!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
telete.in
apps.identrust.com

How to determine Trojan:Win32/Azorult.RF!MTB?


File Info:

crc32: 51C018D3
md5: aa96f47dbf601f3bcb87a44c1a3e222a
name: AA96F47DBF601F3BCB87A44C1A3E222A.mlw
sha1: f6a7d37e19af98c61f8fbcecea8b1089478f7641
sha256: 75bc5234ba652f847e14755352f4b39c26ffcfb5cec2b48d34e066b0581772dd
sha512: 9d52e6294a6f8ce0c3aefd3adb5323e1687897fe766609888d08e26c4682e5afa8c911beb0e32b3f9ab82e8d487661e695fa421db234460f87a06b462266e04e
ssdeep: 12288:AG5geDr04R381cnezG/fvUZG/ocmBabXaJFUFi5F6JBcbkXsL:8e53PezynUZG/TQaTZoF6JUkXsL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersus: 1.0.55.28
ProductVersus: 1.0.55.28
Translations: 0x0185 0x01c7

Trojan:Win32/Azorult.RF!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
MalwarebytesTrojan.MalPack.GS
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Azorult.02381da7
Cybereasonmalicious.e19af9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLAA
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderTrojan.GenericKDZ.75441
MicroWorld-eScanTrojan.GenericKDZ.75441
Ad-AwareTrojan.GenericKDZ.75441
SophosML/PE-A + Mal/GandCrypt-B
BitDefenderThetaGen:NN.ZexaF.34690.JuW@aWuTJlw
McAfee-GW-EditionBehavesLike.Win32.Lockbit.hc
FireEyeGeneric.mg.aa96f47dbf601f3b
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_94%
MicrosoftTrojan:Win32/Azorult.RF!MTB
GridinsoftTrojan.Heur!.02054021
AegisLabTrojan.Win32.Stop.j!c
GDataTrojan.GenericKDZ.75441
AhnLab-V3Trojan/Win.MalPE.R422236
Acronissuspicious
McAfeeArtemis!AA96F47DBF60
MAXmalware (ai score=87)
VBA32BScope.Backdoor.Convagent
PandaTrj/GdSda.A
RisingRansom.Stop!8.10810 (CLOUD)
FortinetW32/Kryptik.HLAA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/Azorult.RF!MTB?

Trojan:Win32/Azorult.RF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment