MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 15e8a21b4626316c44f1dc593fe879aafe93942483445459cd0f41239ab9b678. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 15e8a21b4626316c44f1dc593fe879aafe93942483445459cd0f41239ab9b678
SHA3-384 hash: 258adb05e212270a59f6df06aca4a6f282a6a2d518a07faa09f265c6018faf91de1b6cb3737d91897985c19d947f8fd1
SHA1 hash: 4afb49726241d2a20444840e69b0958b5d9186b9
MD5 hash: 680f9082c49909f13b14b364ed016fe5
humanhash: lima-don-blossom-fourteen
File name:po22JUN2020.zip
Download: download sample
Signature HawkEye
File size:608'841 bytes
First seen:2020-06-23 14:51:36 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:2yyaG1J5sXgZL+lpkA4XbkeU76hbRdKwURKZmGNjVAuQx8CP8F+c5:2L6Za/X87SdyQZN6u28CP8r5
TLSH B3D42318ACE252BF21C79A1470EB4FE9B0B1954AB2CB101533F257FB97B9687770B508
Reporter abuse_ch
Tags:HawkEye zip


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: www.lazzeri.com
Sending IP: 82.184.89.138
From: Purchasing Manager <info@lazzeri.com>
Reply-To: dh_derhawk@126.com
Subject: RE:New Order:723 4143300723+7418200723
Attachment: po22JUN2020.zip (contains "po22JUN2020.exe")

HawkEye SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-23 14:53:04 UTC
AV detection:
35 of 48 (72.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip 15e8a21b4626316c44f1dc593fe879aafe93942483445459cd0f41239ab9b678

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments