MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 906d52efbac5dc8f90e27f97266ea89eb2e1e47b51b54e5d4828c9df498dcdb3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 906d52efbac5dc8f90e27f97266ea89eb2e1e47b51b54e5d4828c9df498dcdb3
SHA3-384 hash: c45cc6d57493a50788093e5501d0fa0573bd93f1dcc0ba965cd7c49de9c8934cfeed1d7255dcbe1b2118f6869c2386fb
SHA1 hash: 00bd776ac531698670176b6ebd8b073251108153
MD5 hash: e544accde76f5b008361b8463beae750
humanhash: juliet-two-eight-social
File name:order03JUL2020309557.zip
Download: download sample
Signature HawkEye
File size:695'343 bytes
First seen:2020-07-03 12:24:31 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:OWF8jki9SntnyOKnRzNG/aKqrI20uG/T9MTvLdG+IYxoTp/:OWL9yOiiqrInb/ywigR
TLSH 83E423DA71BE5A11BC1EE850059C1B80CDDD2EE6A7FC820AD4F8D1652D49FBAFE10075
Reporter abuse_ch
Tags:HawkEye zip


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: server02.imanila.ph
Sending IP: 203.167.7.69
From: Purchasing <server@stsoft.com.cn>
Reply-To: sales@shippparts.com
Subject: RE:Order:723 4143300723+7418200723
Attachment: order03JUL2020309557.zip (contains "order03JUL2020309557.exe")

HawkEye SMTP exfil server:
webmail.tos-thailand.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-03 12:26:05 UTC
AV detection:
26 of 48 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip 906d52efbac5dc8f90e27f97266ea89eb2e1e47b51b54e5d4828c9df498dcdb3

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments