MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1574ff8e68265e9612dfc18a0420bb9b30c875fc1902fcafd4a1a8f425dbe44c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1574ff8e68265e9612dfc18a0420bb9b30c875fc1902fcafd4a1a8f425dbe44c
SHA3-384 hash: 5825f786b3e384a3e077a57555f4ac2091f4e91d07b2431c778d4218626d8e6dd8cda1fdd0c76c8d536c53337797e60a
SHA1 hash: 49b6caa914ec2c6824f2b4156b86cac751ae208e
MD5 hash: 0c31b6e37bf20e388ab4038c90c61112
humanhash: music-mango-echo-magazine
File name:PO 2010029_pdf Quotation from Alibaba Ale.z
Download: download sample
Signature HawkEye
File size:812'475 bytes
First seen:2021-01-19 07:38:01 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:fTMjokkdurPXOaJpVj+1Co+8MpClSry6glBJaf8kY7ea+6GQJXgvWKpQ9LHl75qM:7Mj9kahJxw3DsbOFGA+1Qxj1
TLSH C9052398D9E5F64D1ECD114D2C998AB712E5B707B2F630CBA47DCA3BE793186CC48842
Reporter abuse_ch
Tags:z


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: connectto.com
Sending IP: 104.152.185.194
From: keith collins Bunn services <karenn@connectto.com>
Subject: New Order_PO#060317_007
Attachment: PO 2010029_pdf Quotation from Alibaba Ale.z (contains "PO 2010029_pdf Quotation from Alibaba Ale.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
177
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.NanoBot
Status:
Malicious
First seen:
2021-01-19 07:38:21 UTC
AV detection:
16 of 44 (36.36%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip 1574ff8e68265e9612dfc18a0420bb9b30c875fc1902fcafd4a1a8f425dbe44c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments