MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 041c0094827037ddee70c1fca832fe21bc156ebb406797e8438f416fbf03af78. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 041c0094827037ddee70c1fca832fe21bc156ebb406797e8438f416fbf03af78
SHA3-384 hash: 7915ec487cc56944c3b90014b69f755bb32f03b3f32c0c6eaff9bc988ecdccfb3af2297590d94051796fa107b524783d
SHA1 hash: d1ead8fef130b9c5c66eb154d29f0ef41c5a6ed3
MD5 hash: 93b406725d88832d492a41500a1d1819
humanhash: mountain-undress-ceiling-michigan
File name:PO-n19877.001
Download: download sample
Signature HawkEye
File size:944'578 bytes
First seen:2020-07-20 08:52:50 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:cFZkt2gWDYnd3oB9enfo+b4wX1Ghs7R8vB+2MqEl7Wue6/bS9:QKAYnNxnA24Lhsl8JjEl7d/i
TLSH CF15338C092CF3094E8A265E09521B3BC2775FB1B943531AB0D5B5BC3985B4DD51CBEB
Reporter abuse_ch
Tags:001 HawkEye


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: vps.daneielcom.com
Sending IP: 45.95.169.86
From: info@daneielcom.com
Subject: Re: ORDER(RFQ)
Attachment: PO-n19877.001 (contains "PO-n19877.exe")

HawkEye SMTP exfil server:
smtp.mail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-20 08:54:07 UTC
AV detection:
7 of 48 (14.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

rar 041c0094827037ddee70c1fca832fe21bc156ebb406797e8438f416fbf03af78

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments