MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1276d69291b917af55a996adf07d0157379b7afa227d51d2ff86d4e06311afed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
SnakeKeylogger
Vendor detections: 15
| SHA256 hash: | 1276d69291b917af55a996adf07d0157379b7afa227d51d2ff86d4e06311afed |
|---|---|
| SHA3-384 hash: | 1b6576e38c6076eaa81fd70760060f374cc52df65de8a5748da2aa4da3bd9593db71953c8d855afc69908be4c8ed1641 |
| SHA1 hash: | 7452d2d6765580c591ab921032bc42b3da9dc79d |
| MD5 hash: | 9451b64c517dd1cdf73f9ea6e931e693 |
| humanhash: | pizza-burger-virginia-louisiana |
| File name: | 9451b64c517dd1cdf73f9ea6e931e693.exe |
| Download: | download sample |
| Signature | SnakeKeylogger |
| File size: | 721'408 bytes |
| First seen: | 2022-11-10 12:33:36 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'649 x AgentTesla, 19'461 x Formbook, 12'202 x SnakeKeylogger) |
| ssdeep | 12288:tiD8plm3BEHlO9BeZM/6+ONck2Fxt8tG8InQNue9WeXZjGi:tFObW+OyF8tPB5zjGi |
| Threatray | 8'271 similar samples on MalwareBazaar |
| TLSH | T1D4E48C68A156C89AF61F4372A0ECFFB013F271E3D1C9C65792A46285D7D9BD70E4028E |
| TrID | 64.2% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 11.5% (.SCR) Windows screen saver (13097/50/3) 9.2% (.EXE) Win64 Executable (generic) (10523/12/4) 5.7% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 3.9% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | 0ce4d09ecefc799a (13 x Formbook, 9 x AgentTesla, 6 x SnakeKeylogger) |
| Reporter | |
| Tags: | exe SnakeKeylogger |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
0f6df37b515f330df516df24a8023025514d88fea9371ff96491003dffdc9b09
e94981ca0da699cd4c54ceae54a7f713ca999003aa5fd023aa8fa94707877f6e
f0579298f475e4a98ec491ff10dc3bbab6ceac3b4f376a297ae03d36c177a09d
521e9db681ade0e368a3e99d735333c0d18df6087aa1f2fe6984c84ce1e4a1d8
a3465cca56d61a376078e6ac2d7466fae46bf7d073b9145b768f77ff33a3da0d
25d396ebf0cb796a432bff994c74ea79e44b629584b98515eea9fb7b92019a4d
576aa02b24864b2430af14fbbb6958ff3689b783b7e91012ccb247af6c4a29f2
2afad9ad588a3219b1b36b0096ff4a8db8d70082fd09a612dc6f5935e46f0d4b
73237e3aa90060dbd999b15b39d48db44b63a5d23fd9b2c279fc97cd43a862fe
4832ccbb9379c4046a7478c3cba20a47cb978f37f11ace9afe0d8adb73e17003
9187704232908ac59df2c41f8129eb02fd895817abbce1c6d961a8024ebeb092
6fd62542f92cfcd09af0b2ad8f007a9dc110d64c16cfaab24a9ffd6552a754e8
178f92100449f71a893b39f99b0b3b434d54bd2b2833aaefeb0ab4415f7fb713
df757778956e59dda13ed21877d89a7b55902f285c5958d248300e2e9cfffb83
552b11b82396419c3efd98ecb70657b2d7652d061bbd5d626e478812a65925ee
7b3466885a3f5a38211cd4b6991a384b4a9d8747d5498f4762183e2a48a7fd23
ed31c7e7fc9f786ba9afc2d2885da4db73c4cef7c4514ce69089f57732f5b1ae
68869812f8a2684414348ecc16579fb740a8bfc179957641ee2c39db6ad271d1
397664877d247f7eafbf36c917d6a619e4032e1f04da16c6211e3f8f0a6f2b0f
c8b129ddf3b6fbe3a7fe51c48706375b0a3c90711fdbb0111e215076bbfeef58
78f1957ff80044cf3cee3e4efbedbb55f3b64814ed8804fd076822d4ffcbcb6a
17c4cd880779f7dc3b48f6a2e097770b8b078fcc25f06286874233b3fbcb5099
3c78d5139a49e3f81272c1c7e7eae14f22ed3f7e89b8675663a574153d803eef
875ec0c37d9c973142c00da42bb1b6b6e58115cf85ba0e4e231d7bed7df3b21e
fc994ac728ca7b5d34d00f167b331c187110c45d4911572adc1eb279eb158b00
6381387fc80de027985e11c349120a3ee36724617ccbd2fb67b2d72663f8f93e
18743d67309b9042dccd7fc9b27dfdf6860b11745831d891fb64142836e3fc77
1276d69291b917af55a996adf07d0157379b7afa227d51d2ff86d4e06311afed
585d258b90d3d045c1bd5e5858cc174a51bb25a425612934cd7f167e9a5029af
45ee7fd677dda19356451ef24de0d55b3ccdb5b54c47b5b053a1cf7a280736dc
b2dbb7bcb28f662354fe87b0d2fc0915dfdc12d16987ab6e7bf64beaa24bc077
7bbb472561d41124f3f71db30e605a89f15ce6b39f472130524149dc450c74cd
5bbeb09102c0876fc3d18a31c5aefdfc6f42a4354422611bfefedba2d51da208
cb252bdd63776400aa0f5b41de8ea075a2acb0ef25bcbcc430adb2d356b9e751
489ceb676e0e15e5e5c277ccb679b4508c7ac746e36ec21d4c7d9a52f8f1c88b
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.