MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 600a5262392dea3bda77a2f745326fe7fd2bfae2dae19273fcf5e703ae7384f5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 600a5262392dea3bda77a2f745326fe7fd2bfae2dae19273fcf5e703ae7384f5
SHA3-384 hash: b100de0c5ffae7b26cfb2b421892862ee15e994d63bbc978026aab694f452e631c328503923fd41ada5e88d6076726b5
SHA1 hash: 514eff686c38c5773d3bec8cbd51fb88c648f8cd
MD5 hash: b3e5e00f3fcafafe4e5dc1a48e7e9398
humanhash: november-april-berlin-failed
File name:DETALHES DO RASTREAMENTO FedEx-pdf.7z
Download: download sample
Signature HawkEye
File size:1'464'367 bytes
First seen:2020-05-13 10:32:32 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:wLxi0kMu9cZnCQ32Z/cefSOFaTmey3DmJSnga2vtzrvGwqihWNh7bg:wLkKu9cZFkzeLyY+avtzJEr7s
TLSH E26533FA5FD2535EC738FA28801A20E5FC58E9E920597C34F4C364D87A586DB3528DA4
Reporter abuse_ch
Tags:7z FedEx HawkEye


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: linux1447.grserver.gr
Sending IP: 46.4.43.189
From: Marta Slowinska (FedEx) <marta.slowinska.osv@fedex.com>
Reply-To: Marta Slowinska (FedEx) <dustiutd12@hotmail.com>
Subject: NOTIFICAÇÃO DE ENTREGA DA FedEx
Attachment: DETALHES DO RASTREAMENTO FedEx-pdf.7z (contains "DETALHES DO RASTREAMENTO FedEx-pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-AutoIt.Trojan.Zmutzy
Status:
Malicious
First seen:
2020-05-13 08:15:41 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip 600a5262392dea3bda77a2f745326fe7fd2bfae2dae19273fcf5e703ae7384f5

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments