MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53b3042e983116c6ce0204fbae52daeb4390b76954c250b68e5db9a4ee45b61d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 53b3042e983116c6ce0204fbae52daeb4390b76954c250b68e5db9a4ee45b61d
SHA3-384 hash: 255a9fb9d852a2bfb271a040e3f5990bab52ef5a039c278caabb906a8675e687b69d4b1293d8ef3344b3879bc065c94a
SHA1 hash: aceb8856a78b0835968bc104232df611848dee27
MD5 hash: 069d32cf373d1f744a1d44bcce8865aa
humanhash: princess-zebra-louisiana-solar
File name:order13102020.zip
Download: download sample
Signature HawkEye
File size:604'753 bytes
First seen:2020-10-13 17:50:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:+xMSqF5d4ZZjx8avepRADm4oTBNw5j5yu07gfaLoq28QVAsk2Zhxd1lLz/:+xxqFkyavejDeB5/fG3km+djLz/
TLSH D0D433DC9CF1F8F6248F9103623360994A33B48162EDEB34859EC51457ACBA5A8C25FA
Reporter abuse_ch
Tags:HawkEye zip


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: server.ittronhosting.com
Sending IP: 128.199.114.0
From: EXPORT <support@docs.ittron.web.id>
Reply-To: dh_derhawk@126.com
Subject: Re:RV: INVOICE PACKING LIST
Attachment: order13102020.zip (contains "order13102020.exe")

HawkEye SMTP exfil server:
smtp.guerrayfernandez.es:587

HawkEye SMTP exfil email address:
adelina@guerrayfernandez.es

Intelligence


File Origin
# of uploads :
1
# of downloads :
122
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-13 15:47:05 UTC
AV detection:
34 of 48 (70.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip 53b3042e983116c6ce0204fbae52daeb4390b76954c250b68e5db9a4ee45b61d

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments