MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53ad5eee0c42cf1ebeccdc0f801c96ed85c39151710cc4d6acac44d3b7dd55da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 53ad5eee0c42cf1ebeccdc0f801c96ed85c39151710cc4d6acac44d3b7dd55da
SHA3-384 hash: 1ea17bc616bc3dc1c3920b7846106755ff191512d9b50d59f7cfa4736ddf4156e328eeb411d6b1a1cf03b198237beb2c
SHA1 hash: 7e65c50b9f1638bc6be5994dce9eccad7d8878ca
MD5 hash: 016e7a92aa8a04398a75caf0d581d062
humanhash: speaker-fish-utah-king
File name:1405207846532100.PDF.z
Download: download sample
Signature HawkEye
File size:545'295 bytes
First seen:2020-05-14 11:42:05 UTC
Last seen:Never
File type: z
MIME type:application/gzip
ssdeep 12288:JBfW9XVXWjvBZFnSch1p/XA32Y0/KyHnaZ2YoWg65g8Hqp7:JUFXGJmcC32YFyHn+274bHqp7
TLSH 2CC423EF9A7905C0487DEE0FC2435D31AD918A2A794BA0C4B333C323676D9AE74E5B45
Reporter abuse_ch
Tags:HawkEye z


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: bbl.com
Sending IP: 192.129.189.208
From: ccmsservice<ccmsservice@bbl.com>
Subject: Pre-advice of payment to your account
Attachment: 1405207846532100.PDF.z (contains "gunzipped")

HawkEye FTP exfil server:
ftp.mjtex-kr.com:21

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-14 12:35:51 UTC
File Type:
Binary (Archive)
Extracted files:
317
AV detection:
20 of 31 (64.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

z 53ad5eee0c42cf1ebeccdc0f801c96ed85c39151710cc4d6acac44d3b7dd55da

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments