MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6df680b0ce18173aec143502e2a4e8fa219ebe4ac4f42c639e64ff8a1afdd129. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Matiex


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6df680b0ce18173aec143502e2a4e8fa219ebe4ac4f42c639e64ff8a1afdd129
SHA3-384 hash: 3105e379cb4f20e888abcd302542c1e3bdd4af95c40b0d7c459b00f79b305cb519959d4eb0f60f78d6c7c59557b9c44b
SHA1 hash: 74d58f4c349e88f0337b99768b01ffd6de376df9
MD5 hash: 1feb87a1cde3b978bddc82f2bc762443
humanhash: friend-nine-don-mockingbird
File name:PO 6522301.PDF.rar
Download: download sample
Signature Matiex
File size:266'995 bytes
First seen:2020-08-08 09:04:18 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:/pCj8Iq3Q2DQL4kk8mq4tgbg3DCbmONB0P2zqc+K7dgvEZfh:/p68IqOcZq4q03DRUCSq455D
TLSH 3A442311532A70E3C7A8BE45E4A60DAD2F67153D40B52803BE7D3F1D991FAEC044DAAD
Reporter abuse_ch
Tags:Matiex rar Yahoo


Avatar
abuse_ch
Malspam distributing Matiex:

HELO: sonic313-15.consmr.mail.bf2.yahoo.com
Sending IP: 74.6.133.125
From: Admin Service <enjazgroup@yahoo.com>
Reply-To: Admin Service <enjazgroup@yahoo.com>
Subject: Purchase Order
Attachment: PO 6522301.PDF.rar (contains "PO 6522301.PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
109
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-08 09:06:07 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Matiex

rar 6df680b0ce18173aec143502e2a4e8fa219ebe4ac4f42c639e64ff8a1afdd129

(this sample)

  
Dropping
Matiex
  
Delivery method
Distributed via e-mail attachment

Comments