MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5c883c457a3dc0ddd6ae66380087c57fb714bdf90ff79185ae0cac329677fe26. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: 5c883c457a3dc0ddd6ae66380087c57fb714bdf90ff79185ae0cac329677fe26
SHA3-384 hash: c9a2a5f4df5b518442b7284e37fc9224e9860dd0909671664c12b7aec0ca3dee66c2f649f332cd6ccd58537b6f9173c6
SHA1 hash: c0b2265af90d783810d03fdc13a409e226817eaa
MD5 hash: 8d775d7163a4d1ded56891bd42721e4d
humanhash: winter-bulldog-asparagus-angel
File name:Balance_Payment.exe
Download: download sample
Signature HawkEye
File size:667'648 bytes
First seen:2020-04-30 07:34:27 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2a5ebfebad9cd98aaf1b2c00374db25e (1 x HawkEye)
ssdeep 12288:N1sZz0HadY02OzfepgNBl0cO/jokYt9h0H6S32:NiW902OypgKjshu32
Threatray 775 similar samples on MalwareBazaar
TLSH 06E4E02327FE0A7FD2D982B9182741315450102CAADA7F7FA6EAB52F35F06E506C107B
Reporter jarumlus
Tags:HawkEye

Intelligence


File Origin
# of uploads :
1
# of downloads :
101
Origin country :
n/a
Vendor Threat Intelligence

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:win_blackremote_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator
Rule name:with_sqlite
Author:Julian J. Gonzalez <info@seguridadparatodos.es>
Description:Rule to detect the presence of SQLite data in raw image
Reference:http://www.st2labs.com

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaSetSystemError
MSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef
MSVBVM60.DLL::__vbaFileOpen
MSVBVM60.DLL::__vbaErrorOverflow

Comments