#AZORult Tracker is now publicly available!
https://t.co/5gkkswYgVp
It's centralizing AZORult C2 panels and monitoring them for threat hunting and statistics purpose π¦
Happy hunting!
For those who are curious about how Azorult Tracker works, @DrStache_ and @b0oml had the opportunity to present the project at the #hitchhack2021 organized by @hack2g2. The replay is available (it's in French π«π·).
https://t.co/LM4FcHBWaX
Plain text format has been added to the "list" endpoints of the API.
There are also two new feeders, MalwareBazaar and URLhaus from @abuse_ch π
https://t.co/23lygVPlRE
https://t.co/E4B2JSMPlz
https://t.co/4rzGahV1Fa
@luc4m @makflwana @VK_Intel@James_inthe_box@malwrhunterteam@MalwareTechBlog Statistics on victims can only be made when we have access to the guest.php page, which reduces representativeness, moreover hacked panels are not counted, because of the inconsistent data being injected. The majority of the RU victims are from a single C2 https://t.co/Q6FrrJpuNk
@baberpervez2@abuse_ch The vocation of the tracker isn't AZORult binaries, but only C2 panels. Most of the time, we don't know the URLs serving the malicious binaries, however, we do get the second stage URLs, if any. They will be sent to URLhaus via the API in the near future :)
#AZORult Tracker is now publicly available!
https://t.co/5gkkswYgVp
It's centralizing AZORult C2 panels and monitoring them for threat hunting and statistics purpose π¦
Happy hunting!