MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9d52c8bf2681f26a9942ff0ad4ea89eb87be69a86ea8fc5228eece4c127cdc06. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Matiex


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 9d52c8bf2681f26a9942ff0ad4ea89eb87be69a86ea8fc5228eece4c127cdc06
SHA3-384 hash: 5923ad2b8226b862385f8816bfba2769961e702f21432d683ebecf63ed5c3d2edcb6a466c8c86a0c93c9d52096a76172
SHA1 hash: 0cc77d314510b56d1da334f89b90821100f03596
MD5 hash: cdc211338f75932b5c09553b331c0427
humanhash: may-king-mockingbird-virginia
File name:Purchase_Order_11_19_20.gz
Download: download sample
Signature Matiex
File size:600'631 bytes
First seen:2020-11-19 06:52:01 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:P7ROQqrQOLYB5BrNHm8ossznBS6dl+pqDra5tDPtvd8W/qW+ZVg7z7C:P7+QOLm/XszN6p1fPFd1qWmVqz7C
TLSH 11D423C555ED6AF4EA0ABC34BC46621B73D32D0EB6CAE92D6A435F87D40104AFC1D8D2
Reporter abuse_ch
Tags:gz Matiex


Avatar
abuse_ch
Malspam distributing Matiex:

HELO: hosted-by.rootlayer.net
Sending IP: 185.222.58.152
From: purchasing.shipping@gcrieber.no
Subject: New purchase order No. 5000019156
Attachment: Purchase_Order_11_19_20.gz (contains "Purchase_Order_11_19_20.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-19 06:52:12 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Matiex

zip 9d52c8bf2681f26a9942ff0ad4ea89eb87be69a86ea8fc5228eece4c127cdc06

(this sample)

  
Dropping
Matiex
  
Delivery method
Distributed via e-mail attachment

Comments