MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 da6761f510410bffddc3d88f53c4a63f2be0c56eee45e5c8f2d82081d84d14d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Matiex


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: da6761f510410bffddc3d88f53c4a63f2be0c56eee45e5c8f2d82081d84d14d3
SHA3-384 hash: 384b54f3dc5352558ba900d42712d5db7650a839ce06cbf11b18486cf8edcad42072c3f74834ad47e0fd1933b9cc944d
SHA1 hash: a7ee44386bdbf54a720fc2b1988e172ce43dc9b2
MD5 hash: 67f49e016549b9c96cb1c66da62b38d1
humanhash: mirror-five-undress-tango
File name:pictures and Invoice.zip
Download: download sample
Signature Matiex
File size:1'510'254 bytes
First seen:2020-07-07 08:26:07 UTC
Last seen:2020-07-07 09:55:01 UTC
File type: zip
MIME type:application/zip
ssdeep 24576:VBaFxh1+2OTUl5t7LwzfhSNNNt2+YdoEYe4Kzpf5xo9aozCKM3oZ+xxGCzOcVq:/aFz1FkY59L6hAI+Qw8zt0aozCKMtn/s
TLSH 616533B3D5E025060A6572AAFBF5258125900E17ADA5FD4ED0F9D8CE7A308E8F5F1CC2
Reporter abuse_ch
Tags:AgentTesla Matiex zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: slot0.fundscript.xyz
Sending IP: 45.95.169.179
From: info@fundscript.xyz
Reply-To: info@fundscript.xyz
Subject: Conclusion of Goods
Attachment: pictures and Invoice.zip (contains "Invoice 4907856.exe")

AgentTesla SMTP exfil server:
smtp.privateemail.com:587

Intelligence


File Origin
# of uploads :
3
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-07 08:28:07 UTC
AV detection:
21 of 31 (67.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Matiex

zip da6761f510410bffddc3d88f53c4a63f2be0c56eee45e5c8f2d82081d84d14d3

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments