flash

matiex.exe

Status: finished
Submission Time: 31.07.2020 18:34:40
Malicious
Trojan
Spyware
AgentTesla Matiex

Comments

Tags

  • exe

Details

  • Analysis ID:
    255481
  • API (Web) ID:
    406408
  • Analysis Started:
    01.08.2020 00:59:12
  • Analysis Finished:
    01.08.2020 01:06:00
  • MD5:
    d1af1a8b0975b5c62a095f147e785535
  • SHA1:
    c98a74a0d5e41e07fc8ec2e35fa4f491abdd11d7
  • SHA256:
    4ea222802308d610bd7d4cc4034b7d29258c65bbd42580a87a8b1fec227fb11d
  • Technologies:
Full Report Engine Info Verdict Score Reports

malicious

System: w10x64 Windows 10 64 bit v1803 with Office Professional Plus 2016, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
72/100

IPs

IP Country Detection
131.186.113.70
United States
149.154.167.220
United Kingdom
104.28.5.151
United States

Domains

Name IP Detection
checkip.dyndns.org
0.0.0.0
freegeoip.app
104.28.5.151
api.telegram.org
149.154.167.220
Click to see the 2 hidden entries
checkip.dyndns.com
131.186.113.70
g.msn.com
0.0.0.0

URLs

Name Detection
http://certificates.godaddy.com/repository/0
http://certs.godaddy.com/repository/1301
http://checkip.dyndns.org/HB;jd
Click to see the 28 hidden entries
https://freegeoip.app
https://www.geodatatool.com/en/?ip=
http://checkip.dyndns.org
http://crl.godaddy.com/gdig2s1-1823.crl0
https://certs.godaddy.com/repository/0
http://checkip.dyndns.orgD8
https://api.telegram.org/bot962940633:AAFWOS5PMSGq49vE3MQVWuNLcoWDhmmugxg/sendDocument?chat_id=13926
http://checkip.dyndns.org4
http://crl.godaddy.com/gdroot-g2.crl0F
https://api.telegram.org4
http://checkip.dyndns.org/
https://freegeoip.app/xml/91.132.136.174x
http://crl.godaddy.com/gdroot.crl0F
https://freegeoip.app/xml/LoadTimeZoneCountryNameCountryCodehttps://www.geodatatool.com/en/?ip=/
https://freegeoip.appD8
https://api.telegram.org/bot/sendMessage?chat_id=&text=Createutf-8Win32_ComputerSystemModelManufactu
https://freegeoip.app4
http://checkip.dyndns.com
https://www.geodatatool.com/en/?ip=91.132.136.174
https://freegeoip.app/xml/91.132.136.174
http://api.telegram.org
http://certificates.godaddy.com/repository/gdig2.crt0
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
http://freegeoip.app
https://freegeoip.app/xml/
https://i.imgur.com/GJD7Q5y.png
https://api.telegram.org
https://api.telegram.org/bot