MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1728be41a6686ac6219165073b2bb476f4f5b8af72d65deafd8a0f8b2f23143f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1728be41a6686ac6219165073b2bb476f4f5b8af72d65deafd8a0f8b2f23143f
SHA3-384 hash: a17e4ad13bdc3fd3d8c9a7900dae450d585391fcc562a563c3cfc1c6a3197c99c28c4648986f0713c99087c8122fa29f
SHA1 hash: f194663ecaa1abdb5f29854e71a43dcaaa47e5b0
MD5 hash: 7c363b72a1f6ebca6589a5f9916fadde
humanhash: ohio-ack-angel-steak
File name:IMG_80137.pdf.img
Download: download sample
Signature SnakeKeylogger
File size:2'293'760 bytes
First seen:2021-01-19 16:20:31 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:5eQQYwyzF/B1eSdILkqEpwAg/Tr1HeLJlr5rvOUCJ6c:5tQYtzJB1bk0LBOUCE
TLSH 01B55B02EA0C8673C5303877459B2B6D2352E9EBE651C3C27B0DBA3EB556FC51B8D198
Reporter abuse_ch
Tags:img SnakeKeylogger


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: klginformatica.com.br
Sending IP: 88.26.195.167
From: AccountsPayable <nilson@klginformatica.com.br>
Subject: L&F- SWIFT EXECUTED RECEIPT
Attachment: IMG_80137.pdf.img (contains "IMG_80137.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
207
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-19 16:21:07 UTC
AV detection:
8 of 46 (17.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

img 1728be41a6686ac6219165073b2bb476f4f5b8af72d65deafd8a0f8b2f23143f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments