Hare is a destructive computer virus active in the 1990s that targets DOS and Microsoft Windows systems. The content describes it as a virus that can overwrite all data on infected hard drives when triggered, displaying the message "HDEuthanasia by Demon Emperor: Hare Krsna, hare, hare . . ." on affected machines. Reported trigger dates were Aug. 22 and Sept. 22. Infection vectors mentioned in the content include booting from an infected floppy disk and running infected programs downloaded from the Internet. Macintosh systems are described as unaffected. The malware was first found in New Zealand according to the content, and unknown creators were assessed as most likely being in Europe or New Zealand. Contemporary reporting cited limited spread at the time of discovery, with Symantec noting at least a half dozen customer infections, while other historical content characterizes Hare as widely publicized, buggy, mediocre, and unlikely to spread extensively despite Internet-driven attention. Hare is also listed in historical 1990s malware timelines alongside families such as CIH, Happy99, KAK, Melissa, Michelangelo, and Staog.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content includes a 'Malware' list under 'Hacking in the 1990s' that names: 'CIH, Happy99, Hare, KAK, Melissa, Michelangelo, Staog'.
Timeline ... Malware ... CIH ... Happy99 ... Hare ... KAK ... Melissa ... Michelangelo ... Staog
The content includes a 1990s timeline section listing malware, including: "Malware CIH Happy99 Hare KAK Melissa Michelangelo Staog".
... Malware ... Hare ...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.