MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 50262502a3e46ba4761d75063e9f2d2d96aa24f323ca0a5515327f74ffe41ca6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 50262502a3e46ba4761d75063e9f2d2d96aa24f323ca0a5515327f74ffe41ca6
SHA3-384 hash: 09119920625edea27070bcd4d24f12fbaa086e676d179ff510e67033e31c0667142e1dca7419ee0d6df12449e952683c
SHA1 hash: 75ea8d66342b9834df289c428011c0257c7b3dc1
MD5 hash: 29901bfc82e62e1dce42cfc0664bc68d
humanhash: tango-river-high-mississippi
File name:000909000000000000.xz
Download: download sample
Signature SnakeKeylogger
File size:278'325 bytes
First seen:2021-01-18 16:25:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:ur/XKZ3D4VdJ4fpDwX8Y2hwFDdMVfvFujKI5/DX8TfDRL9Rye:urvK4TS1ftuOI5/DMTbRLqe
TLSH 8F442368587E61D900F1AFF75EEA06C082F96CC54B8CDBA791C544873B0C9E97CE884E
Reporter abuse_ch
Tags:ESP geo SnakeKeylogger xz


Avatar
abuse_ch
Malspam distributing SnakeKeylogger:

HELO: hosted-by.rootlayer.net
Sending IP: 45.137.22.52
From: ventas@inmermek.com.mx
Subject: Fwd: Final Invoice - ¡Información bancaria de la nueva empresa!
Attachment: 000909000000000000.xz (contains "000909000000000000.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
137
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Zmutzy
Status:
Malicious
First seen:
2021-01-18 16:26:05 UTC
AV detection:
5 of 46 (10.87%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

zip 50262502a3e46ba4761d75063e9f2d2d96aa24f323ca0a5515327f74ffe41ca6

(this sample)

  
Dropping
SnakeKeylogger
  
Delivery method
Distributed via e-mail attachment

Comments