MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 90efa048359cf92a3587ab4d217d41a4e4f00e926c86ebe3d5dd08d7c9296c43. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 90efa048359cf92a3587ab4d217d41a4e4f00e926c86ebe3d5dd08d7c9296c43
SHA3-384 hash: 718ba7c34ecc58db334abf61a5f71da1fc23cc8fde3b6d67f541e02ccb846d3a8288d500fe11cd7f8e8eaa202259aaca
SHA1 hash: 8d98ef9608d0f27e6191fb8771675f959206d090
MD5 hash: 082ad856e2c7b756138bdaf18db166fa
humanhash: victor-victor-jig-blue
File name:payment 1.zip
Download: download sample
Signature HawkEye
File size:483'265 bytes
First seen:2020-06-05 07:28:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:qLUnwEglnNMP2G8mk3wTaSPZrya3dqX0r2gJfltd:qLR5+k3hEZry4hyg1bd
TLSH 60A423E2B033F443548D690B22E658F9A56EF66E1614F8B5F57C119699202809FCEF0F
Reporter abuse_ch
Tags:HawkEye zip


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: linux1287.grserver.gr
Sending IP: 138.201.129.95
From: Bank Technologies Inc <green@eshoes.gr>
Subject: pagamento
Attachment: payment 1.zip (contains "payment.exe")

HawkEye SMTP exfil server:
server165.web-hosting.com:26

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip 90efa048359cf92a3587ab4d217d41a4e4f00e926c86ebe3d5dd08d7c9296c43

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments