MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 878b86d0a52cd92060b6b09d181c0f597850a8faada738763a8c9fc3e33fd953. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 878b86d0a52cd92060b6b09d181c0f597850a8faada738763a8c9fc3e33fd953
SHA3-384 hash: 3253c858f5d3ed6c5fc94e973657be5f0aaa4c738b4045392610a421778f9ad852dbe9d3bf39ac1f239cebfff0b2702c
SHA1 hash: 88bc121a2046045c9e1d4c508527bf0bb740d802
MD5 hash: bc5e0e7f22df0f554276a60601c6522d
humanhash: colorado-oven-emma-romeo
File name:SWIFT mensaje.zip
Download: download sample
Signature HawkEye
File size:665'870 bytes
First seen:2020-11-07 09:42:37 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:dTpUGtw7fHz2TMfH2jecasUwmBLrXJjsS05L5N01vQFCbA:d1V++TMP2jJuub5L0Zc/
TLSH 6CE423E570F7FA27875787ACC502B85800BDEB907892B9D1EC64044ADB739C85BD2FA4
Reporter abuse_ch
Tags:ESP geo HawkEye zip


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: imscp.swebians.com
Sending IP: 144.76.175.181
From: AC Tomelloso <support@rieth-kg.de>
Reply-To: dh_derhawk@126.com
Subject: RV:justificación de transferencia
Attachment: SWIFT mensaje.zip (contains "SWIFT mensaje.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-11-06 11:31:52 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip 878b86d0a52cd92060b6b09d181c0f597850a8faada738763a8c9fc3e33fd953

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments