MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 04aa55e1600b801ddda368268eaf6f2ab9858f402b526468d727a943eadfb122. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
SnakeKeylogger
Vendor detections: 15
| SHA256 hash: | 04aa55e1600b801ddda368268eaf6f2ab9858f402b526468d727a943eadfb122 |
|---|---|
| SHA3-384 hash: | d27e03ec5e86f3a010c86b87e51fbf3e65e58def35f96df91ce8abaf772e237159d611f4b6903c7b1bc096e959ac1baa |
| SHA1 hash: | 7be2847cccca04184b860c5a59ce64002faf399b |
| MD5 hash: | 8a5c5e9c32f4321602c58fa73bed5583 |
| humanhash: | vermont-glucose-massachusetts-romeo |
| File name: | aO4531DgkGtMPOE.exe |
| Download: | download sample |
| Signature | SnakeKeylogger |
| File size: | 1'293'824 bytes |
| First seen: | 2023-04-11 13:13:39 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'649 x AgentTesla, 19'452 x Formbook, 12'202 x SnakeKeylogger) |
| ssdeep | 24576:BCgp2MjsjbaTTFnRfmCProMwes+CQM1lE4Dt+B6ef+mg8zvWNo:BCgp2MjjThRRrop/TQElt+B6B+Si |
| Threatray | 64 similar samples on MalwareBazaar |
| TLSH | T10255226D43B0DB69F46C0FF1646454812378F249B960EAA99CE353E38776BA220593F3 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4505/5/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Reporter | |
| Tags: | exe SnakeKeylogger |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
9d0618a3a6027f47ebd85a126770e86f37e6e47b35f2175e7fde30acf1d73020
578873c16060e04fcfe43f9c9c04d2779a09a7566b3b4e97c1b18d87ac381057
04aa55e1600b801ddda368268eaf6f2ab9858f402b526468d727a943eadfb122
ce3c9c47d811745d5534bf268331382438b274a112d2327396cdc8623e82f98b
c7b06e2840e703c98fbe1fbfd9f33f5478e58840112d85c1e94c27a34474c95f
149c80ebeeead2dff7b45f8a627d5396b995f6afc82f18487d7c6eb4bf071205
578873c16060e04fcfe43f9c9c04d2779a09a7566b3b4e97c1b18d87ac381057
04aa55e1600b801ddda368268eaf6f2ab9858f402b526468d727a943eadfb122
ce3c9c47d811745d5534bf268331382438b274a112d2327396cdc8623e82f98b
c7b06e2840e703c98fbe1fbfd9f33f5478e58840112d85c1e94c27a34474c95f
149c80ebeeead2dff7b45f8a627d5396b995f6afc82f18487d7c6eb4bf071205
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | BitcoinAddress |
|---|---|
| Author: | Didier Stevens (@DidierStevens) |
| Description: | Contains a valid Bitcoin address |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.