MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 467d693051c6f42821ef490674795996c024b896b1f0cf159df21f82bf93021f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 4


Intelligence 4 IOCs YARA 3 File information Comments 1

SHA256 hash: 467d693051c6f42821ef490674795996c024b896b1f0cf159df21f82bf93021f
SHA3-384 hash: cbdc5ea65e8ebe8c08cece3817b03682cc918c966368a722e75442cbe170595125d219e4d37419c5260c5838d4fa916c
SHA1 hash: 5f2a35d12000985aea51fe3f2ef9f1c1cac7902b
MD5 hash: ca8f1d72f7c25e8ff0229ea8bc477073
humanhash: cold-fifteen-fruit-seventeen
File name:Payment receipt.rar
Download: download sample
Signature SnakeKeylogger
File size:633'856 bytes
First seen:2022-11-03 07:26:44 UTC
Last seen:2022-11-05 18:00:08 UTC
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: Rjj2AQnDpIqwRBq
ssdeep 12288:w0Gg3pBxKxEGqUTfQOwxMj2WGe7htTowVbdVjGPbWxIuuoWEduAU:FZ34bvf3bj2WGe7hHvINEdu7
TLSH T162D423521967C10AC492F759F8E4040B543F34D7459BCBAC802A67AA7F26F43DCBB58B
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter cocaman
Tags:payment pw-Rjj2AQnDpIqwRBq rar SnakeKeylogger Ukraine zip


Avatar
cocaman
Malicious email (T1566.001)
From: ""Natalia Maksymenko" <supplierdiversity@cardinalhealth.com>" (likely spoofed)
Received: "from cardinalhealth.com (unknown [41.216.183.177]) "
Date: "05 Nov 2022 03:47:21 +0100"
Subject: "Save the Orphans! Stand with people of Ukraine"
Attachment: "Payment receipt.rar"

Intelligence


File Origin
# of uploads :
3
# of downloads :
129
Origin country :
n/a
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Rjj2AQnDpIqwRBq.exe
File size:773'632 bytes
SHA256 hash: 355738240ad3a3da221045502ecc02acaa057dc81cff9f48b9eb14c0561548bb
MD5 hash: 7db43e8fbdc48900d92ecc4d08f019ad
MIME type:application/x-dosexec
Signature SnakeKeylogger
Vendor Threat Intelligence
Gathering data
Threat name:
Archive.Trojan.Generic
Status:
Suspicious
First seen:
2022-10-26 12:56:20 UTC
File Type:
Binary (Archive)
AV detection:
4 of 26 (15.38%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

zip 467d693051c6f42821ef490674795996c024b896b1f0cf159df21f82bf93021f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments



Avatar
Corsin Camichel commented on 2022-11-04 07:22:58 UTC

password is
Rjj2AQnDpIqwRBq

(the name of the included .exe file)