top title background image
flash

matiex.exe

Status: finished
Submission Time: 2020-07-31 18:34:40 +02:00
Malicious
Trojan
Spyware
AgentTesla Matiex

Comments

Tags

  • exe

Details

  • Analysis ID:
    255481
  • API (Web) ID:
    406408
  • Analysis Started:
    2020-08-01 00:59:12 +02:00
  • Analysis Finished:
    2020-08-01 01:06:00 +02:00
  • MD5:
    d1af1a8b0975b5c62a095f147e785535
  • SHA1:
    c98a74a0d5e41e07fc8ec2e35fa4f491abdd11d7
  • SHA256:
    4ea222802308d610bd7d4cc4034b7d29258c65bbd42580a87a8b1fec227fb11d
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 72
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
131.186.113.70
United States
149.154.167.220
United Kingdom
104.28.5.151
United States

Domains

Name IP Detection
checkip.dyndns.org
0.0.0.0
freegeoip.app
104.28.5.151
api.telegram.org
149.154.167.220
Click to see the 2 hidden entries
checkip.dyndns.com
131.186.113.70
g.msn.com
0.0.0.0

URLs

Name Detection
http://crl.godaddy.com/gdroot-g2.crl0F
http://freegeoip.app
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Click to see the 28 hidden entries
http://certificates.godaddy.com/repository/gdig2.crt0
http://api.telegram.org
https://freegeoip.app/xml/91.132.136.174
https://www.geodatatool.com/en/?ip=91.132.136.174
http://checkip.dyndns.com
https://freegeoip.app4
https://api.telegram.org/bot/sendMessage?chat_id=&text=Createutf-8Win32_ComputerSystemModelManufactu
https://freegeoip.appD8
https://freegeoip.app/xml/LoadTimeZoneCountryNameCountryCodehttps://www.geodatatool.com/en/?ip=/
http://crl.godaddy.com/gdroot.crl0F
https://freegeoip.app/xml/91.132.136.174x
http://checkip.dyndns.org/
https://api.telegram.org4
https://freegeoip.app/xml/
http://checkip.dyndns.org4
https://api.telegram.org/bot962940633:AAFWOS5PMSGq49vE3MQVWuNLcoWDhmmugxg/sendDocument?chat_id=13926
http://checkip.dyndns.orgD8
https://certs.godaddy.com/repository/0
http://crl.godaddy.com/gdig2s1-1823.crl0
http://checkip.dyndns.org
https://www.geodatatool.com/en/?ip=
https://freegeoip.app
http://checkip.dyndns.org/HB;jd
http://certs.godaddy.com/repository/1301
http://certificates.godaddy.com/repository/0
https://api.telegram.org/bot
https://api.telegram.org
https://i.imgur.com/GJD7Q5y.png