Trojan

Trojan:Win32/Azorult information

Malware Removal

The Trojan:Win32/Azorult is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Azorult virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Trojan:Win32/Azorult?


File Info:

name: 1E1122E988CF74CBC802.mlw
path: /opt/CAPEv2/storage/binaries/6e9d736fb1b6442f2f65234d2c38925ec6f9fbc2556ead26eec0588503379e51
crc32: 0FD0BCDB
md5: 1e1122e988cf74cbc802f4d2d95c00cc
sha1: 95bd141ff7b1f87d7ae42cd2d8fd6a556dd7aa5c
sha256: 6e9d736fb1b6442f2f65234d2c38925ec6f9fbc2556ead26eec0588503379e51
sha512: df39e4e58c70fceece1120f5c6284191ce9a225194264f54149a4d6b6abb537025c23d3ed2bc75141681f97c3fd6da9bb33812c879152103c94dd6689fd9b773
ssdeep: 24576:Wu6J33O0c+JY5UZ+XC0kGsoTacbl6u2il:4u0c++OCvkGsEacJ67s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16D159D22B3DDC360CB669173BF69B3056EBB7C650630B85B2F980D3DA960171162D7A3
sha3_384: 0792082e568ea5246824e49f062aef730bd13701525ec54c20326ea1142850a11f7d0d7989e328dbd8458932e3d6ca2b
ep_bytes: e8b5d00000e97ffeffffcccccccccccc
timestamp: 2019-05-14 14:55:21

Version Info:

Translation: 0x0809 0x04b0

Trojan:Win32/Azorult also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.AutoIt.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.67287025
FireEyeGeneric.mg.1e1122e988cf74cb
CAT-QuickHealTrojan.AutoIT.Injector.A
McAfeeTrojan-AitInject.aq
Cylanceunsafe
VIPRETrojan.GenericKD.67287025
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 0055dc781 )
AlibabaTrojan:Win32/AutoitCrypt.180
K7GWTrojan ( 0055dc781 )
Cybereasonmalicious.988cf7
ArcabitTrojan.Generic.D402B7F1
CyrenW32/AutoIt.QF.gen!Eldorado
SymantecAUT.Heuristic!gen5
tehtrisGeneric.Malware
ESET-NOD32Win32/Packed.Autoit.NBC suspicious
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Autoit.gen
BitDefenderTrojan.GenericKD.67287025
TencentTrojan.Win32.Agent.hfw
SophosTroj/AutoIt-CLG
F-SecureDropper.DR/AutoIt.Gen8
DrWebTrojan.AutoIt.426
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.ch
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.67287025 (B)
AviraDR/AutoIt.Gen8
Antiy-AVLGrayWare/Autoit.ShellCode.a
MicrosoftTrojan:Win32/Azorult
ZoneAlarmUDS:Trojan.Win32.Autoit.gen
GDataTrojan.GenericKD.67287025
GoogleDetected
AhnLab-V3Win-Trojan/AutoInj.Exp
BitDefenderThetaAI:Packer.39DE3CF819
ALYacTrojan.GenericKD.67287025
MAXmalware (ai score=86)
VBA32Trojan.Autoit
MalwarebytesGeneric.Trojan.Malpack.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
IkarusTrojan.Autoit
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Injector.ESJ!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Azorult?

Trojan:Win32/Azorult removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment