MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 313ad26ae426d1f3293c2d78ed3fde9093661e90dc876246e8703f0a20522a21. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
SnakeKeylogger
Vendor detections: 13
| SHA256 hash: | 313ad26ae426d1f3293c2d78ed3fde9093661e90dc876246e8703f0a20522a21 |
|---|---|
| SHA3-384 hash: | 34be223847200d28ca4a42914fa0c2cda710e890fac4f226dc54baf833e32ea6a7b6d9319ccb90edb4f067332941d99d |
| SHA1 hash: | d25b6f6a20238bcb31b36af044428545160375f2 |
| MD5 hash: | f0cbe408045d492ae41ee92ad7c39bea |
| humanhash: | georgia-tennis-alpha-steak |
| File name: | f0cbe408045d492ae41ee92ad7c39bea.exe |
| Download: | download sample |
| Signature | SnakeKeylogger |
| File size: | 982'528 bytes |
| First seen: | 2023-03-29 18:48:37 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'657 x AgentTesla, 19'468 x Formbook, 12'206 x SnakeKeylogger) |
| ssdeep | 12288:x22iNo3XdJVZz5dB3Jf8JjlByZ1WW59xqh5L3tm6UgshB268MMezG4dMzu7eD9vm:x212zVZ97Jf0n6SJiBmMMeZwceDuWS |
| TLSH | T120258A5CE1C572FBC61747B685E1E773A22FDED10A118ACCD9E82DE7B0FB608080A516 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4505/5/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Reporter | |
| Tags: | exe SnakeKeylogger |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
180a541d61bfa4fda318457b0f16f159671b14305b5993e13b4d63c649eed2cb
96b8969e22bf1183fcc6ba3778115801dd2e6ab5d05c46d7e9b03fc95558aa43
777e815415d8a5c55a3ddf78e28d4a50a5517f3938219c197c6e7c60a2f256a1
b33a98ce498846037fd68b2055d835464a1350c9c067e250689a2be1f17dc987
e83c5b4a9fbfb2294eeb8be89c3d871ad2f20b776bf9594bd0b0ecd288ad47f8
313ad26ae426d1f3293c2d78ed3fde9093661e90dc876246e8703f0a20522a21
27379979a480e5ebfe00f58eb1f2fd09836eb8a13a7dde9ac1451e4ef09c73f1
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_SUSPICIOUS_Binary_References_Browsers |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers. |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_DotNetProcHook |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables with potential process hoocking |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many email and collaboration clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_TelegramChatBot |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables using Telegram Chat Bot |
| Rule name: | MALWARE_Win_SnakeKeylogger |
|---|---|
| Author: | ditekSHen |
| Description: | Detects Snake Keylogger |
| Rule name: | MAL_Envrial_Jan18_1 |
|---|---|
| Author: | Florian Roth (Nextron Systems) |
| Description: | Detects Encrial credential stealer malware |
| Reference: | https://twitter.com/malwrhunterteam/status/953313514629853184 |
| Rule name: | MAL_Envrial_Jan18_1_RID2D8C |
|---|---|
| Author: | Florian Roth |
| Description: | Detects Encrial credential stealer malware |
| Reference: | https://twitter.com/malwrhunterteam/status/953313514629853184 |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Windows_Trojan_SnakeKeylogger_af3faa65 |
|---|---|
| Author: | Elastic Security |
| Rule name: | XWorm_Hunter |
|---|---|
| Author: | Potato |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.