[2018-10-11] Unknown->FalloutEK->AZORult

October 11, 2018

Overview

Saz file is 2018-10-11_19-58-54.saz

(↓Analysis result using EKFiddle)

Malware

AZORult

676cfa47f9477e1696a51a68fccb1856c7c8bf17f449236fea386a3f399e6a58
[Hybrid-Analysis] [VirusTotal]

Traffic-Chain

http[:]//89.34.111.126:18001/in/ali/
↓
http[:]//37.1.221.103/get/
↓
[Fallout Exploit Kit][Landing Page]
http[:]//myhouseincartoon.xyz/minimizes_6560/4583-ullaged-4495/8078/6082-Treeify-Grifted-argillic/OuCZydEM.dhtml?tQM886xh=cassabas&akvUTw=7908
↓
[Fallout Exploit Kit][Malware Payload]
http[:]//myhouseincartoon.xyz/achingly_gadroons_leonardo_Lithoxyl/PAu54tvIP.html?distains=Foolify_orejon_Dollish&xgofsekMV=7TOv&AHyMTe=1978-11-08