MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 432ed4f549a0d6e1e674e3542ede6f59027c26586f9497192312bb778bc1f889. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
SnakeKeylogger
Vendor detections: 18
| SHA256 hash: | 432ed4f549a0d6e1e674e3542ede6f59027c26586f9497192312bb778bc1f889 |
|---|---|
| SHA3-384 hash: | a552e797a1bbfd3b8139ad1ca4f048917fb3e7ecf67f5749f13f024c849cba65b6e00243836749b98b730b0b8bc42d99 |
| SHA1 hash: | e2a31457e3660d3e4faf900d183517bd7f74487f |
| MD5 hash: | e647ed7ef0559cc91f7d934f4c0bc90b |
| humanhash: | montana-twenty-lake-single |
| File name: | Remittance Advice.exe |
| Download: | download sample |
| Signature | SnakeKeylogger |
| File size: | 811'008 bytes |
| First seen: | 2024-07-31 14:18:52 UTC |
| Last seen: | 2024-07-31 14:28:05 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'661 x AgentTesla, 19'474 x Formbook, 12'208 x SnakeKeylogger) |
| ssdeep | 24576:+L3cLAGUhFOeQKgm3SJsrYHLHgWrUN5Bqa3XOZS:+iAGUhFOeQH1erYm5BqVI |
| Threatray | 5'562 similar samples on MalwareBazaar |
| TLSH | T11B05BE02B3E86A3BC68F4775E032141A43B1F44B7912D74F5998F27E5C9376B8C22A97 |
| TrID | 66.5% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 9.5% (.EXE) Win64 Executable (generic) (10523/12/4) 5.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.5% (.EXE) Win16 NE executable (generic) (5038/12/1) 4.0% (.EXE) Win32 Executable (generic) (4504/4/1) |
| File icon (PE): | |
| dhash icon | c4c4c4ccfcccf670 (5 x AgentTesla, 4 x SnakeKeylogger, 4 x NetWire) |
| Reporter | |
| Tags: | exe SnakeKeylogger |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
432ed4f549a0d6e1e674e3542ede6f59027c26586f9497192312bb778bc1f889
5d691afca26ebbdcf9bc73673667580f07a47cd63b5061831ad1a8fb5eccd1d0
8ee90a49d860205395973a7810661081a76a3a120962375e6a67d39a1e669429
4ecf58f56c8a8bcee9ac95a7b0d8b3012fd8319d309461cf4c3109de97f14e2c
407e8ed9551050f2ab146bf170daad390f1beab7ce1a5a07e34b055f6dd40ed8
328a09676b78f9b7b5686511b491f3d16dd6e58783a051e45fa49377eb8b8e81
fa3abba5968db877ff3aa4341799f3ae6b88f874373e973ec7d4ed04446ef78a
0349048171e2fd2bf0846ee08771f8249cff266457d363829859f0141a6b4703
c0023cf70e7f34a4adb24a59fae7b4796f11b5c5e889588618237ed47651b293
fa28f86180684ba58f4fb1ed6e1fce0ddc1061a3a858150a18891202fcd36a05
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.