MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2350e1e2b2e641e6da26751fef99faa95e3e91d5c892edeb08170d34ebdb8165. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2350e1e2b2e641e6da26751fef99faa95e3e91d5c892edeb08170d34ebdb8165
SHA3-384 hash: f424d436720637274a6a1994c47e69dc07dcc081775364fd207383e026bd95431fbe8d01883477a7e9339f5b0edf7715
SHA1 hash: 8eb524500b5224cfe01f6f9c7bd25cf90706cad1
MD5 hash: 68a6ff2b2f1354e7d3a4e26e61d79199
humanhash: march-princess-leopard-west
File name:SAL-0908889000.R13
Download: download sample
Signature SnakeKeylogger
File size:8'071 bytes
First seen:2021-02-24 14:42:41 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 192:JlzrGBSfywxBYywCW6OppedpGJk/JB2QFEPWMxJM9H7:zysKUYytkIpG0JB2UEWMx+9b
TLSH AFF1B09AE471BD56C626E23415430B344B4A6DF3718E6313063B17466EB120BDE5F1B2
Reporter abuse_ch
Tags:r13 SnakeKeylogger


Avatar
abuse_ch
Malspam distributing SnakeKeylogger:

HELO: hosted-by.rootlayer.net
Sending IP: 45.137.22.52
From: Sales@bigeastequipment.com
Subject: ORDEN DE COMPRA-0353224
Attachment: SAL-0908889000.R13 (contains "SAL-0908889000.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Downloader.BaseLoader
Status:
Malicious
First seen:
2021-02-24 14:43:05 UTC
AV detection:
8 of 46 (17.39%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

zip 2350e1e2b2e641e6da26751fef99faa95e3e91d5c892edeb08170d34ebdb8165

(this sample)

  
Dropping
SnakeKeylogger
  
Delivery method
Distributed via e-mail attachment

Comments