MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6dae4ecaceca3e45ba6ed8d0c685ad3f7b3ac081eec01c654c277597e653fb04. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6dae4ecaceca3e45ba6ed8d0c685ad3f7b3ac081eec01c654c277597e653fb04
SHA3-384 hash: e10e78828599daa5ec24764849fbffdff0cc2035d42f5052688063a4f5b92bf2a3716ac891a7d21ea5a7d6a5f72a3719
SHA1 hash: 084ea7ddeae48fbb73145db4fff4c06df0c0d14c
MD5 hash: c1d3b5ef152d27d1a9c09255761b76d9
humanhash: east-august-grey-seventeen
File name:DETALHES DO RASTREAMENTO FedEx-pdf.7z
Download: download sample
Signature HawkEye
File size:1'760'160 bytes
First seen:2020-05-05 10:31:46 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 49152:fP10/PFTIFROh+7fHIy7kln6jatbY/a2k3cwBXt:fgtTIFRc5X2O9d
TLSH 42853345C8AAB7085637FE4587BC4C39B9D8023BD711EBCD33AA4B2D848F0EE956851C
Reporter abuse_ch
Tags:7z FedEx geo HawkEye PRT


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: server.linux69.papaki.gr
Sending IP: 88.99.0.236
From: Marta Slowinska (FedEx) <marta.slowinska.osv@fedex.com>
Reply-To: Marta Slowinska (FedEx) <dustiutd12@hotmail.com>
Subject: NOTIFICAÇÃO DE ENTREGA DA FedEx
Attachment: DETALHES DO RASTREAMENTO FedEx-pdf.7z (contains "DETALHES DO RASTREAMENTO FedEx-pdf.exe")

HawkEye FTP exilf server:
ftp.kassohome.com.tr:21

HawkEye FTP exilf user name:
Ernest2020@kassohome.com.tr

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Aitinject
Status:
Malicious
First seen:
2020-05-05 10:36:27 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
30 of 48 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip 6dae4ecaceca3e45ba6ed8d0c685ad3f7b3ac081eec01c654c277597e653fb04

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments