MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5c689e51184bcd6919cf32c481db807153ebdd24bcc5f3641803000fd6b2eef1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5c689e51184bcd6919cf32c481db807153ebdd24bcc5f3641803000fd6b2eef1
SHA3-384 hash: a757748d17f6ac1c57ac76e3f7b32f5a4197aa1d0c00bdc96c10887e01c7d85cc5080e8a0653d2163b80f1aa61a56044
SHA1 hash: 14c0b9da96bde03e3cff739c38ff5c1e496b039e
MD5 hash: 0c1fcb521493add24ed5c6680bba9f58
humanhash: aspen-minnesota-pip-kansas
File name:VP 17164 RAL 7030 in B Basis doc.zip
Download: download sample
Signature HawkEye
File size:827'954 bytes
First seen:2020-05-05 11:16:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:yrunVddw7yastK0DgLiVJjmeAViyfj4jlaK5:ypFstbzjahViyfj4UK5
TLSH EF05339413680B5913A8B67B70F43BD7958C5D7D7A216EA0D0520201F43EEBDDF62BE2
Reporter abuse_ch
Tags:HawkEye zip


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: server.linux69.papaki.gr
Sending IP: 88.99.0.236
From: Petra Dunzweiler <petra.dunzweiler@rhenocoll.de>
Subject: WG: -Request and availability
Attachment: VP 17164 RAL 7030 in B Basis doc.zip (contains "VP 17164 RAL 7030 in B Basis doc.exe")

HawkEye SMTP exfil server:
mail.crdd.mx:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
97
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-05 11:36:56 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
24 of 48 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip 5c689e51184bcd6919cf32c481db807153ebdd24bcc5f3641803000fd6b2eef1

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments