MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e887db1fb45fb5e4fb5f361b6d2e29243f5929c27e5e12379e9b1035b9745134. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e887db1fb45fb5e4fb5f361b6d2e29243f5929c27e5e12379e9b1035b9745134
SHA3-384 hash: 985441bd8567989948b4b1c981068ca7ad56ad95188114a1eced1d8fef210a2ec08a978aa21bb2285c3a90e83cc60dfa
SHA1 hash: 9c7a6eadd6db9f3d43b529da3bb983f94ecb2784
MD5 hash: cd58f6faf2102179dc627bca30ce3dfb
humanhash: bakerloo-sink-mexico-mexico
File name:INQUIRY.zip
Download: download sample
Signature HawkEye
File size:631'036 bytes
First seen:2020-11-18 12:09:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:1XxNjF7EtUB99aGSlqjN936ha9JmABI8V5YVze2YQJO7UwJCA64xHinF4lpyqyjN:ZFYtUL9axY93wkJmCHY1rOowEOphvo
TLSH A9D433FA115EAFDFA55DBA28FC0D82587A7CC0903FC5D5C418B8605A0F934C8B46657B
Reporter abuse_ch
Tags:HawkEye zip


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: planet.tn
Sending IP: 176.123.7.141
From: Tarek Chouchane < t.chouchene@planet.tn>
Subject: Demande urgente 18-11-2020
Attachment: INQUIRY.zip (contains "INQUIRY.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-18 09:44:55 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip e887db1fb45fb5e4fb5f361b6d2e29243f5929c27e5e12379e9b1035b9745134

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments