MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ad114591e0cd90c86e8f29c80a9bcb7d71a82cf9597cca6ed8b84a77c2af36b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1ad114591e0cd90c86e8f29c80a9bcb7d71a82cf9597cca6ed8b84a77c2af36b
SHA3-384 hash: 542328603ccee384fe323d22170a1e02d6b6951f479b349666b888cb3c1e727d49d2ac7e55ce9a44b98fcf219177d51c
SHA1 hash: 1ab59a7486b4c63df06ee3d828c2133ab5cae794
MD5 hash: a9bc3dfec8ca3b4b27031332141e801a
humanhash: failed-carpet-uranus-minnesota
File name:CPRNC20420511_FreightArrival.r15
Download: download sample
Signature SnakeKeylogger
File size:564'681 bytes
First seen:2021-02-09 06:34:26 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:T2G39OjCn/Mnyk7sHDhRDTSukhMfRdZnwQvTa17/71O+qL/3oJF1:T2E8G/MndqhRDTSZwqQ7e5qLq1
TLSH E7C423D863340259F815A0988E9E6A10C9F2A1AA1745E363B6D1FBB7D3DD7F60B14E30
Reporter abuse_ch
Tags:r15 SnakeKeylogger


Avatar
abuse_ch
Malspam distributing SnakeKeylogger:

HELO: mail.fpcci.org.pk
Sending IP: 124.29.202.181
From: Sales Covein <sales@covein.com>
Reply-To: itall_machine2013@yahoo.com
Subject: ARRIVAL NOTICE / FREIGHT INVOICE [FORM ORDER-CPRNC20420511]
Attachment: CPRNC20420511_FreightArrival.r15 (contains "CPRNC20420511_FreightArrival.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-09 06:35:09 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

rar 1ad114591e0cd90c86e8f29c80a9bcb7d71a82cf9597cca6ed8b84a77c2af36b

(this sample)

  
Dropping
SnakeKeylogger
  
Delivery method
Distributed via e-mail attachment

Comments