MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 68b8668e48221ed9b6e66d92a338c9585a642ee90afbff26b25e4af085baf455. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 68b8668e48221ed9b6e66d92a338c9585a642ee90afbff26b25e4af085baf455
SHA3-384 hash: 49c5d15b5d1d563fa7c000cbcb8fa08cc1f4bb802858d86a79d957a442a33427e53d6ed51cc82678c6b038c953b57957
SHA1 hash: 08e598b3dc007da39c63f2cca2515167667efb22
MD5 hash: e8c1f3785a11aa3c9358f2c017574755
humanhash: muppet-orange-speaker-six
File name:PO0193882.zip
Download: download sample
Signature HawkEye
File size:582'212 bytes
First seen:2020-05-06 10:42:48 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:Ti/KE22BX9leWl2uIH5kKnh9Gte7BD0oYQLiIA:T/P2XPl2ugRndD4xIA
TLSH 7DC42329BF9953BD9BC2343A4EFBA914682FD96B05788934CD1E4D8BEF5417804C205F
Reporter abuse_ch
Tags:HawkEye zip


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: combytellc.com
Sending IP: 37.49.230.215
From: "Linda" <sandeepgill@combytellc.com>
Reply-To: "Linda" <sandeepgill@combytellc.com>
Subject: RE: Purchase Order Confirmation
Attachment: PO0193882.zip (contains "PO#0193882.exe")

HawkEye SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Heye
Status:
Malicious
First seen:
2020-05-06 09:48:26 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
22 of 48 (45.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip 68b8668e48221ed9b6e66d92a338c9585a642ee90afbff26b25e4af085baf455

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments