[2018-10-27] Unknown->RigEK->AZORult

October 27, 2018

Overview

Saz file is 2018-10-27_00-00-32.saz

(↓Analysis result using EKFiddle)

Malware

AZORult

14abcb9b688c6ed83d26225bf03ca54138982873074e7cfa14d0627ddef013d5
[Hybrid-Analysis] [VirusTotal]

Traffic-Chain

http[:]//kello.igg.biz
↓
http[:]//kello.igg.biz/1.php
↓
[RIG Exploit Kit][Landing Page]
http[:]//46.229.212.237/?MzkzNTg2&YidZQN&HJQU=heartfelt&fxDPFPuYQ=wrapped&BOjEuOE=professional&iVSWzuK=known&qBJUmtoXg=professional&thfafg4=m2Epvt4KecCOgO0ihPTfFE3z9xVV1pG9P37hkfUnxOahZeH-xKIUTp1u9CSUbI&GGsRD=known&hZEblXqje=constitution&fdgdsff4=wXbQMvXcJwDQA4bGMvrESLtNNknQA0KK2Ib2_dqyEoH9cmnihNzUSkr16B2aC&cbAWgC=difference&mWHivcTe=criticized&mFtb=constitution&CEOhtjgkH=constitution&KtoNvOJBMjM1OTUw
↓
[RIG Exploit Kit][SWF Payload]
http[:]//46.229.212.237/?NTQ5MTc=&IphitfCOtiSE&hWYzdIdc=heartfelt&ArNBLJZYMjk=detonator&yTjozze=difference&YVevoaPGqQy=already&kBwsVurpaRDASr=perpetual&xfLcskpEhuXZt=heartfelt&zLuojzZ=referred&nzaOROpCxp=heartfelt&thfafg4=cDaAfm2BeHewI0yt1aVA5FpPuni0GAyhDI1Z-D-kOIZw9M_5eSEbgL2Vnwx7kSQIgvgECy&fdgdsff4=wnnQMvXcKxXQFYbGKuXDSKNDKU7WGkaVw4-RhMG3YpnNfynz2OzURnL6tASVVFWRrbMdKu&qmIWTDaQZ=blackmail&vnGdkzGlq=heartfelt&HUeXwnwiHKrg=known&zPZfqCTNehnpMzE5Mzcx
↓
[Fallout Exploit Kit][Malware Payload]
http[:]//46.229.212.237/?NjMxOTk1&KliVwqnfHDwTVK&cWGWarZwxGqwS=community&wiyrQkK=constitution&fdgdsff4=xXfQMvWabRXQA53EKvLcT6NDMVHRFUCL2YidmrHWefjafFWkzrvFTF_6ozKAQwSG6_VtdfJZDVa&IrprmsnGI=blackmail&thfafg4=yhBCELgMzm45VBwxA8a762EaGmxOagMKB9UHYaQNEqZecErQ73ljyyrkkecwgzhCB4GBgkexdUWo&MoDJpVIMspcPhVJ=community&miMYBsMwUmlplk=referred&SgxjXIUcWuqfDsg=known&znjjcafz=detonator&UMtFNUCzPv=difference&WxftuGTLbBWLUT=wrapped&konctThTp=professional&GWmInxXBAqvHkK=perpetual&EdKFDDypFeaMTQ1Mzkw