MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 02b0cfbd65605a1af1adf3df8be172111de3f451672666a53bdef36273a7b497. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 02b0cfbd65605a1af1adf3df8be172111de3f451672666a53bdef36273a7b497
SHA3-384 hash: f9b4bc1a96fe2157a92e3fa7f303f0ff9e2507e6dedc73d9d6859ece5f57e5eb7dd7c4d2bc5e43d3c0b2087f73538f92
SHA1 hash: 0a7eb3e3511d863edb025a78ddea737c41c07dbd
MD5 hash: 4de1621b0e8f6c5cc9b82320844afb80
humanhash: maryland-lima-tango-march
File name:New Order2021MK.zip
Download: download sample
Signature SnakeKeylogger
File size:956'686 bytes
First seen:2021-02-19 06:27:49 UTC
Last seen:2021-02-19 20:43:37 UTC
File type: zip
MIME type:application/zip
ssdeep 24576:sZtc8WZ0JVTm85Ghd2AN6QXN0U6YVkB2h0HYjR:sZS8C0JVThStNd0PYVkBd4t
TLSH 3315330929EC633F4BB10E39DB1271B8819247539A47BC57ACBB2D93E4288BD51B3716
Reporter cocaman
Tags:zip


Avatar
cocaman
Malicious email (T1566.001)
From: "Anna<enquiries@pitchup.com>" (likely spoofed)
Received: "from nomikos.gr (unknown [45.137.22.49]) "
Date: "18 Feb 2021 09:23:14 -0800"
Subject: "New Order/2021/MK"
Attachment: "New Order2021MK.zip"

Intelligence


File Origin
# of uploads :
9
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Ymacco
Status:
Malicious
First seen:
2021-02-18 22:14:23 UTC
File Type:
Binary (Archive)
Extracted files:
24
AV detection:
18 of 46 (39.13%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

zip 02b0cfbd65605a1af1adf3df8be172111de3f451672666a53bdef36273a7b497

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments