MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 89eed680f78aa51d6ae975b8ceca9c76c8f0c2142fa1edf6e400ab2eefbe33bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Matiex
Vendor detections: 4
| SHA256 hash: | 89eed680f78aa51d6ae975b8ceca9c76c8f0c2142fa1edf6e400ab2eefbe33bd |
|---|---|
| SHA3-384 hash: | 4327eb54c43695667d203227170d1296551e6896a180f6f0d9f4e4cdcef1d848c168e33a1f6b7eb7c03dbd8d045891e7 |
| SHA1 hash: | 5f5b0aeb3ec3755d7bcc12df2080a1d08a1409ec |
| MD5 hash: | b36f72a2444c2566bb07154aadc68673 |
| humanhash: | white-nuts-lithium-sad |
| File name: | invoice copy.pdf.z |
| Download: | download sample |
| Signature | Matiex |
| File size: | 361'107 bytes |
| First seen: | 2020-07-31 05:53:50 UTC |
| Last seen: | Never |
| File type: | z |
| MIME type: | application/x-rar |
| ssdeep | 6144:N4sfnGXkk8HF7Q8LDYlo1DZMU26x4tI84ODquNMbDH6teKH3kecT0GWG00kNHNG7:NTfnGXkTFU8351NS6x4tIqRMvHKeK3mB |
| TLSH | E4742301881BD348FC3BB88E5631654EE59DAEBEC105D766330A0A695D4E236DF74CF2 |
| Reporter | |
| Tags: | Matiex z |
abuse_ch
Malspam distributing unidentified malware:HELO: biz.vnpt.vn
Sending IP: 37.48.83.10
From: Acount Director <kieu.lt@biz.vnpt.vn>
Subject: Proforma Invoice
Attachment: invoice copy.pdf.z (contains "invoice copy.pdf.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-07-31 05:55:09 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
AgentTesla
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.