MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 203754c6e511e0678e98b709deb230b6ee0a7c83e5c368a3c2e3e2bcc692f80b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 203754c6e511e0678e98b709deb230b6ee0a7c83e5c368a3c2e3e2bcc692f80b
SHA3-384 hash: 1c64794f630448060777775484636730870e39e2f6575e9ffb6121eebfb926b92892bd136b5f2089eeccb5e9054c6f59
SHA1 hash: e335ebb8ed5dbb536e5323dc55d0c9c907587c31
MD5 hash: aa069cd0c4942ccf4416b434930abdc0
humanhash: winner-fanta-winner-table
File name:Yeni sipariş _WJO-001, pdf.exe
Download: download sample
Signature SnakeKeylogger
File size:781'690 bytes
First seen:2021-08-17 14:03:28 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f21b9f4ed04fb68076e88d1363ed51e4 (10 x Formbook, 3 x RemcosRAT, 2 x Loki)
ssdeep 12288:vdKqRTBltDn9lzAKp5yNMzljAYxudZC9QmRItTWzbR0:vdKCBbplDp5FljAxY800
Threatray 5 similar samples on MalwareBazaar
TLSH T1A4F4AF707108E8B1D56B89B97334C221BF7DB831CB0AE8CF10CA5EDE65B2790947659E
dhash icon 8084a48cbc8ce4f8 (44 x Formbook, 20 x AveMariaRAT, 11 x SnakeKeylogger)
Reporter abuse_ch
Tags:exe SnakeKeylogger

Intelligence


File Origin
# of uploads :
1
# of downloads :
118
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Yeni sipariş _WJO-001, pdf.exe
Verdict:
No threats detected
Analysis date:
2021-08-17 14:59:18 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Snake Keylogger
Detection:
malicious
Classification:
troj.spyw.evad
Score:
92 / 100
Signature
Found malware configuration
Maps a DLL or memory area into another process
May check the online IP address of the machine
Multi AV Scanner detection for submitted file
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file access)
Yara detected Beds Obfuscator
Yara detected Snake Keylogger
Yara detected Telegram RAT
Behaviour
Behavior Graph:
Threat name:
Win32.Infostealer.Snakkel
Status:
Malicious
First seen:
2021-08-17 14:04:27 UTC
AV detection:
17 of 46 (36.96%)
Threat level:
  5/5
Result
Malware family:
snakekeylogger
Score:
  10/10
Tags:
family:snakekeylogger keylogger stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Looks up external IP address via web service
Snake Keylogger
Snake Keylogger Payload
Unpacked files
SH256 hash:
203754c6e511e0678e98b709deb230b6ee0a7c83e5c368a3c2e3e2bcc692f80b
MD5 hash:
aa069cd0c4942ccf4416b434930abdc0
SHA1 hash:
e335ebb8ed5dbb536e5323dc55d0c9c907587c31
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments