MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cd56b647814320f00633616f433a629cd956161e388369354f5ace58e045630e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HawkEye


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cd56b647814320f00633616f433a629cd956161e388369354f5ace58e045630e
SHA3-384 hash: c7a60231ad9f9cf7da6f5555fb3b8feeb5c520c9b23fc9ea84ff1f95a35e97b5932867f53f87628c6a864831068e4793
SHA1 hash: 5605144e8b9571a5b0a4f6d6103450e1a4bdd46e
MD5 hash: b3c233cafb495be3c46cf97693e4dce9
humanhash: leopard-romeo-hydrogen-football
File name:order180620203350884322.zip
Download: download sample
Signature HawkEye
File size:589'360 bytes
First seen:2020-06-18 06:20:34 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:pnF77x6uPGUgOMsQcdISOvpiC2PAKKt87QWiqdwOnb3zf:pnFPxBQODIS0ACuAKKtMQKdw+3zf
TLSH 3EC4238BB75FC560D4C6BC839E0FADD5146482E2B18DF4CBB1A4F2693D4F8980E82635
Reporter abuse_ch
Tags:HawkEye zip


Avatar
abuse_ch
Malspam distributing HawkEye:

HELO: shmx.tama5cci.or.jp
Sending IP: 60.32.68.163
From: Purchasing Manager <info@tama5cci.or.jp>
Reply-To: dh_derhawk@126.com
Subject: Re:ORDER-04350316//4183000102292563
Attachment: order180620203350884322.zip (contains "order180620203350884322.exe")

HawkEye SMTP exfil server:
smtp.urban.co.th:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-18 06:22:04 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

HawkEye

zip cd56b647814320f00633616f433a629cd956161e388369354f5ace58e045630e

(this sample)

  
Dropping
HawkEye
  
Delivery method
Distributed via e-mail attachment

Comments