MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 35179778958fe523ba324a706da15ddf578c27432ea36436b6c8f496e030ae6c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Matiex


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 35179778958fe523ba324a706da15ddf578c27432ea36436b6c8f496e030ae6c
SHA3-384 hash: c8b170caa27650d68bd79138f26a6d1d036a339d1b96383eb790dba55fdf62386f36345c2373430b399c742983f74d17
SHA1 hash: ba0de9dd3048677840dc1cdcec008733e1b3ef79
MD5 hash: de9257cf2825bbf215efca5ade5ce709
humanhash: bakerloo-yankee-hydrogen-autumn
File name:0900S890000.zip
Download: download sample
Signature Matiex
File size:1'028'866 bytes
First seen:2020-12-18 09:27:46 UTC
Last seen:2020-12-18 09:27:55 UTC
File type: zip
MIME type:application/zip
ssdeep 24576:hvZm6ie5qk2GiHpGJ0S0VYRu1z3E1C6zm53kLv:hRzt5qk7iJbbVx01Rze0L
TLSH 8125335CB944A222F71A7E386E1A0F6798051D8944EFCA0CC1FD1EBAC4EF855B9D72D0
Reporter abuse_ch
Tags:zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: hosted-by.rootlayer.net
Sending IP: 185.222.58.152
From: ventas@fasemex.com.mx
Subject: NUEVO PEDIDO # 090800
Attachment: 0900S890000.zip (contains "0900S890000.exe")

Intelligence


File Origin
# of uploads :
2
# of downloads :
130
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Zenpak
Status:
Malicious
First seen:
2020-12-18 09:28:07 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Matiex

zip 35179778958fe523ba324a706da15ddf578c27432ea36436b6c8f496e030ae6c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments