Trojan

What is “Trojan:Win32/Azorult.VAM!MTB”?

Malware Removal

The Trojan:Win32/Azorult.VAM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Azorult.VAM!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Uzbek (Cyrillic)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Azorult.VAM!MTB?


File Info:

crc32: DE6BF004
md5: b4ba060296fb7611fb4ec58387321d72
name: B4BA060296FB7611FB4EC58387321D72.mlw
sha1: b0976550d1922f15a233fdf6be9fdb0a3574b9c8
sha256: 7ee8f16f00c11840579df38a0656c9813abc3795fa50bd5b7160fea8f8e3d6eb
sha512: fa2f55a591060c817ebd2fc76d45354cab8ffd6b6351ab1634351117fb11cf983216c83ce62814899c5b7f960b89290622baf354d9e6a9848cf8d4b5cf68da56
ssdeep: 98304:ZyNnI+ChDbx9+YXe5gXBEREn2WzEQYcHQr:ZyWFB52WzEQYr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersions: 7.0.0.25
LegalCopyrights: Wsegda
ProductVersions: 67.0.20.45
Translation: 0x0409 0x067b

Trojan:Win32/Azorult.VAM!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AntiSandbox.GenericKDS.36336488
McAfeePacked-GBE!B4BA060296FB
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.AntiSandbox.GenericKDS.36336488
K7GWRiskware ( 0040eff71 )
CyrenW32/Trojan.FWF.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Dropper.Glupteba-9831991-0
KasperskyTrojan.Win32.Eb.btt
AlibabaTrojan:Win32/Azorult.f8c5f034
RisingTrojan.Eb!8.10DCC (CLOUD)
Ad-AwareTrojan.AntiSandbox.GenericKDS.36336488
EmsisoftTrojan.AntiSandbox.GenericKDS.36336488 (B)
ComodoMalware@#1r57pbvprk3i5
F-SecureTrojan.TR/AD.GoCloudnet.dgd
TrendMicroTROJ_GEN.R03BC0DBF21
McAfee-GW-EditionBehavesLike.Win32.Emotet.wc
FireEyeGeneric.mg.b4ba060296fb7611
SophosMal/Generic-R + Troj/Godrop-V
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.dgd
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Azorult.VAM!MTB
GridinsoftTrojan.Win32.Emotet.oa
ArcabitTrojan.AntiSandbox.GenericS.D22A7368
ZoneAlarmTrojan.Win32.Eb.btt
GDataWin32.Trojan.PSE.BCUR3C
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R366244
BitDefenderThetaGen:NN.ZexaF.34804.3tW@aS9aGSNG
ALYacTrojan.AntiSandbox.GenericKDS.36336488
VBA32BScope.Trojan.Azorult
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32a variant of Win32/Kryptik.HJLC
TrendMicro-HouseCallTROJ_GEN.R03BC0DBF21
TencentWin32.Trojan.Eb.Pgcw
IkarusTrojan.Crypt
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HJLC!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Generic.HwoCPBcA

How to remove Trojan:Win32/Azorult.VAM!MTB?

Trojan:Win32/Azorult.VAM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment