MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ea9756d4672cb051f15f3b03de40f13f67c523e699001d1514cfcb3f57edfd2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3ea9756d4672cb051f15f3b03de40f13f67c523e699001d1514cfcb3f57edfd2
SHA3-384 hash: 42d73cee21e0151fbc95ae48396000e733a62e1f44f6e7ff448616aee5dea4875d5e73eb85db35873433c36f2d99360c
SHA1 hash: f4daa133bb5b731dcbb7f00c3e372e79090b9405
MD5 hash: cc8e8a4d4a856c95c70065af76b8e928
humanhash: lake-mirror-south-steak
File name:SHIPMENT DOCUMENT.IMG
Download: download sample
Signature SnakeKeylogger
File size:1'245'184 bytes
First seen:2021-03-01 07:29:08 UTC
Last seen:2021-03-01 12:10:58 UTC
File type: img
MIME type:application/x-iso9660-image
ssdeep 384:cvYx5ftHxvjE7cjt/IBFfO8xJrKrmY8Rxq/MCTfRVuWnp80EUAFScv9p58Jnztqc:cg3eoI/vqv8HqE6Vzp80XAFVTcnzIhO
TLSH 9B45E49073E68616F57A0F3429B37E226A7CBA51DFD1C56E3C5C090F2B7C7404928E6A
Reporter abuse_ch
Tags:DHL img


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: orange.fr
Sending IP: 77.247.110.185
From: DHL SHIPMENT <un765454@orange.fr>
Subject: Shipping Documents / Original BL, Invoice & Packing List
Attachment: SHIPMENT DOCUMENT.IMG (contains "SHIPMENT DOCUMENT.exe")

Intelligence


File Origin
# of uploads :
2
# of downloads :
108
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

img 3ea9756d4672cb051f15f3b03de40f13f67c523e699001d1514cfcb3f57edfd2

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments