MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c1fd090b422513439ad5ce128fbd7aceb336437462c5b3de6ccafec2e0e4e38c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c1fd090b422513439ad5ce128fbd7aceb336437462c5b3de6ccafec2e0e4e38c
SHA3-384 hash: a094d8af08ed5a4b2f74345a5f97a40ad07b1e5cc9d0c2ac8d322b33d08be3d2ae9af4a4cfb28b62061bf9692d27a616
SHA1 hash: 9a7f2b0ec1f7ad21ee172dd688711c336c6d09ca
MD5 hash: 97cf9e21396dca18c501fa03d471887c
humanhash: arkansas-beryllium-leopard-washington
File name:INVOICE.rar
Download: download sample
Signature HawkEye
File size:454'061 bytes
First seen:2020-08-08 08:15:45 UTC
Last seen:2020-08-13 03:30:58 UTC
File type: rar
MIME type:application/x-rar
ssdeep 12288:sU0bmJOmBwxZachUzbQ3LD9xNPbRNnxI0wiK:34mwFhgbu/9xNVbwiK
TLSH 09A423E998468D45CB0DFAC2124F6B4B778FECD0E0EF1CC45DB2505EA5E6689E4B2603
Reporter abuse_ch
Tags:HawkEye rar


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: seventeen.qservers.net
Sending IP: 72.52.251.1
From: Michela Rubini <info.trade@bhwo.org>
Subject: INVOICE ATTACHED
Attachment: INVOICE.rar (contains "INVOICE.exe")

Intelligence


File Origin
# of uploads :
2
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgnetTesla
Status:
Malicious
First seen:
2020-08-08 08:17:07 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

rar c1fd090b422513439ad5ce128fbd7aceb336437462c5b3de6ccafec2e0e4e38c

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments