MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 33e62b7eaf037008183c8c91f650b57416c11d3be5957194dc1a44906cf4e4f5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 33e62b7eaf037008183c8c91f650b57416c11d3be5957194dc1a44906cf4e4f5
SHA3-384 hash: 4890deab7c451517caee11e26f455ebab9681c13cf420bced4beaa9f50b9acfa41a17ac2a1aee64ad61a98d5e1792523
SHA1 hash: d1605550625936f5507d10d77b4e7096cd42e5db
MD5 hash: 52cb6b9b0fdf40a5ac39bf2e03094ae5
humanhash: glucose-hot-indigo-nine
File name:IMG_05752003.IMG
Download: download sample
Signature SnakeKeylogger
File size:1'310'720 bytes
First seen:2021-01-29 16:32:56 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:0KTzxN72nTO6CMcdff4qhyVaMBPpS6R6W99leDxcE+IjT:3zxN7aTO6MwqwXBPpRJPleDWu
TLSH 2C554958EB64FA12C417B27601D92A081373BFCBB6E1C915234877F32B723E52B5E5A4
Reporter abuse_ch
Tags:img SnakeKeylogger


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: whitemountains.99cloudhosting.com
Sending IP: 219.90.65.155
From: ccmsservice@bbl.co.th
Subject: Pre-advice of payment to your account on 29-JAN-21
Attachment: IMG_05752003.IMG (contains "IMG_05752003.scr")

Intelligence


File Origin
# of uploads :
1
# of downloads :
194
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Zmutzy
Status:
Malicious
First seen:
2021-01-29 16:34:15 UTC
AV detection:
8 of 46 (17.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

img 33e62b7eaf037008183c8c91f650b57416c11d3be5957194dc1a44906cf4e4f5

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments