ANY.RUN Releases Expert Malware Analysis on AZORult
DUBAI, DUBAI, UNITED ARAB EMIRATES, September 4, 2024 /EINPresswire.com/ -- ANY.RUN, a leading provider of interactive malware analysis solutions, presents an insightful guest post by malware reverse engineer and threat intelligence analyst, Mostafa ElSheimy. In this comprehensive analysis, Mostafa examines the main functionalities of AZORult, a sophisticated credential and payment card information stealer.
๐๐จ๐ฆ๐ฉ๐ซ๐๐ก๐๐ง๐ฌ๐ข๐ฏ๐ ๐๐ซ๐๐๐ค๐๐จ๐ฐ๐ง ๐จ๐ ๐๐๐๐๐ฎ๐ฅ๐ญโ๐ฌ ๐๐ฏ๐จ๐ฅ๐ฎ๐ญ๐ข๐จ๐ง ๐๐ง๐ ๐๐๐ก๐๐ฏ๐ข๐จ๐ซ
ElSheimy provides an in-depth look into the evolution of AZORult, tracing its origins from its early development in Delphi to its transition into C++ and the introduction of .bit domain support.
The key findings include:
โข Execution of hidden PowerShell commands: AZORult uses PowerShell scripts to execute malicious commands undetected.
โข Registry manipulation: AZORult modifies and deletes Windows registry keys, further securing its persistence within the system.
โข File dropping: The malware deploys additional payloads, such as Declinometer235.exe, to enhance its functionality and ensure broader system compromise.
โข Anti-debugging techniques: It employs techniques such as GetTickCount to detect if it's running in a virtualized environment, helping it avoid detection.
๐๐ก๐ฒ ๐๐ก๐ข๐ฌ ๐๐๐ญ๐ญ๐๐ซ๐ฌ ๐๐จ๐ซ ๐๐ฒ๐๐๐ซ๐ฌ๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ ๐๐ซ๐จ๐๐๐ฌ๐ฌ๐ข๐จ๐ง๐๐ฅ๐ฌ
For cybersecurity experts, this report serves as a practical guide to understanding malwareโs strategies and methods, which can be vital for developing countermeasures against this type of threat.
Learn more on ANY.RUNโs blog
๐๐๐จ๐ฎ๐ญ ๐๐๐.๐๐๐
ANY.RUN assists over 400,000 cybersecurity professionals worldwide with its interactive sandbox solutions, simplifying the analysis of malware targeting both Windows and Linux systems. Our advanced threat intelligence tools, including TI Lookup, YARA Search, and Feeds, help organizations quickly gather Indicators of Compromise (IOCs), understand active threats, and respond faster to incidents.
The ANY.RUN team
ANYRUN FZCO
+1 657-366-5050
email us here
Visit us on social media:
X
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.