MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eb08d9bc0e2c38804f199a05797f1cc9e9dbf813e73a8f751a6a0cad5bf50192. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: eb08d9bc0e2c38804f199a05797f1cc9e9dbf813e73a8f751a6a0cad5bf50192
SHA3-384 hash: 4a2833c9b98d5f35a5fccf4f6fcf99e42aa6e9e43d1b3a156e53e7266788d40d29da741ba1622835f22651905000de21
SHA1 hash: 1a624c727efd9c78e63da26f72ddd0b03f85bc79
MD5 hash: ed841ad45e31efb16983de6164e3519e
humanhash: burger-bravo-zebra-vermont
File name:59818 STS 939_pdf.rar
Download: download sample
Signature HawkEye
File size:191'924 bytes
First seen:2020-05-04 22:10:20 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:efriZcM700LE5239u3DpwFfM/rhlW9+JoIFi2m0gb2tne0zXYxdX:efr2nn/3aDpwFM/rXK2mlwe0rYL
TLSH 021412D9A498651F07331AB34C09942E3FBB16C5FCEA34619C33C18BA21BBA9174955F
Reporter abuse_ch
Tags:HawkEye rar


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: 049215.vps-10.com
Sending IP: 91.109.4.192
From: Amir <taremiha@hydropolymar.net>
Subject: Re: Invoice: Hydropolymer GmbH - CH-IR-0104-34-2019-V1.0
Attachment: 59818 STS 939_pdf.rar (contains "59818 STS 939_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-04 22:36:46 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
18 of 31 (58.06%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

rar eb08d9bc0e2c38804f199a05797f1cc9e9dbf813e73a8f751a6a0cad5bf50192

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments