MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 26e69d5cea2a00f353bc26191b00fc79d6a697655d3096741a12f96b9a9e2955. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 26e69d5cea2a00f353bc26191b00fc79d6a697655d3096741a12f96b9a9e2955
SHA3-384 hash: a098422cdb6fc685045a52e63cc9bc918332a6c57e1c591081f901a8c916e05aa265a396f9d8235c0844cbeccb924586
SHA1 hash: 13e239c3bdb0d4cb5de2d539cb4e972c364601c5
MD5 hash: 0e2d2be62f005ab0cca7ac8201607b43
humanhash: delta-foxtrot-august-twelve
File name:PO.zip
Download: download sample
Signature HawkEye
File size:679'913 bytes
First seen:2020-06-04 09:00:35 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:TnQzDEyPz4FBGW6QBm8euqxUleJ3R30KUrRWmpVU/0ySlL:TnQzDtP8t6Cev8eFFkRWxeR
TLSH BCE423C434112BA8E7CFBC86AD6DCC8431AAAD1DC285C49739EC9264E7A5F4C776610F
Reporter abuse_ch
Tags:HawkEye zip


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: halleycables.com
Sending IP: 156.96.151.244
From: Radu DOBRE Sales Manager HALLEY CABLES<radu@halleycables.com>
Reply-To: HALLEY CABLES <williechang1@yahoo.com>
Subject: Re: Drawing & P/O for your reference article no: ROTCASA56
Attachment: PO.zip (contains "PO.exe")

HawkEye SMTP exfil server:
mail.eagleeyeapparels.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-04 09:36:19 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip 26e69d5cea2a00f353bc26191b00fc79d6a697655d3096741a12f96b9a9e2955

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments