MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0c1cd859638323706a90c1e1ebb383ad09481e2ab7f34738a3fed0582b12bd34. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0c1cd859638323706a90c1e1ebb383ad09481e2ab7f34738a3fed0582b12bd34
SHA3-384 hash: 54ae873bbcd0f40e08c80022a2097632f787b1f826c2b9a8e97d47fe3f86e92bdbd67564ec7060d8c58f79275c67b2ff
SHA1 hash: d0388d9ea097669b1dfe77cace8c84dbe61c79c0
MD5 hash: 584a1ba1f2b00a843777393b8b928fa1
humanhash: carpet-paris-foxtrot-ink
File name:order.rar
Download: download sample
Signature SnakeKeylogger
File size:535'284 bytes
First seen:2021-02-26 06:15:14 UTC
Last seen:2021-02-26 10:59:20 UTC
File type: rar
MIME type:application/x-rar
ssdeep 12288:9c1FjIZOlLzlQMjwmu2kDMjq/plJa0H/YW0hz:9K9I81zlo92kP7HHgWWz
TLSH E8B42375421192F45DC4F2E0ACDFD9CE6798D83E249B8BCE1ED3A036291356A1C78F16
Reporter abuse_ch
Tags:rar SnakeKeylogger


Avatar
abuse_ch
Malspam distributing SnakeKeylogger:

HELO: tabletsindia.com
Sending IP: 103.99.1.142
From: purchase@tabletsindia.com
Subject: Purchase Order (Ref: PO-11059021022021) - Project: Redhill L14 
Attachment: order.rar (contains "order.exe")

Intelligence


File Origin
# of uploads :
2
# of downloads :
99
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-25 21:27:05 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

rar 0c1cd859638323706a90c1e1ebb383ad09481e2ab7f34738a3fed0582b12bd34

(this sample)

  
Dropping
SnakeKeylogger
  
Delivery method
Distributed via e-mail attachment

Comments