MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 53947d3249013c415585a4bd2ed6f31415f98fa69d50e1720d13c381157a75d4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
SnakeKeylogger
Vendor detections: 7
| SHA256 hash: | 53947d3249013c415585a4bd2ed6f31415f98fa69d50e1720d13c381157a75d4 |
|---|---|
| SHA3-384 hash: | ba41789c8d59f536307e795d21727a3094e23c4dea6441d7dbb18ad62325335e23974a81ba3b5d40229ab951baa4139c |
| SHA1 hash: | efc809f6858a3c468aa518d17a619229d0999b6f |
| MD5 hash: | d92d722bb448707226a238747a3f6ba4 |
| humanhash: | rugby-summer-nine-montana |
| File name: | fishcom2021,2022.zip |
| Download: | download sample |
| Signature | SnakeKeylogger |
| File size: | 439'212 bytes |
| First seen: | 2022-10-18 07:12:14 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:Q7evVWHTHt/hP+Cki1wcbfrv/mhqUXkSStUDkAb6fgRsw:Q7CVWHps0TryXIMkwyw |
| TLSH | T1219423871BEB31CC2A4E9499D7205611B80FFB05F50B258BAE7A5FC66098DE32F547C8 |
| TrID | 80.0% (.ZIP) ZIP compressed archive (4000/1) 20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1) |
| Reporter | |
| Tags: | SnakeKeylogger zip |
cocaman
Malicious email (T1566.001)From: "Natalija Kramer <natalija.kramer@ema.si>" (likely spoofed)
Received: "from ema.si (unknown [185.222.58.61]) "
Date: "18 Oct 2022 03:15:57 +0200"
Subject: "EMA CUSTOMER ANALYSIS"
Attachment: "fishcom2021,2022.zip"
Intelligence
File Origin
# of uploads :
1
# of downloads :
197
Origin country :
n/a
File Archive Information
This file archive contains 3 file(s), sorted by their relevance:
| File name: | version.txt |
|---|---|
| File size: | 1'654 bytes |
| SHA256 hash: | efdacdd2483a616f0f93a0ccba1261787870c7c1f0db19a58c5003a03961fbe9 |
| MD5 hash: | 6a96dba59c947963e432eb2d6138987a |
| MIME type: | application/octet-stream |
| Signature | SnakeKeylogger |
| File name: | 1 |
|---|---|
| File size: | 7'427 bytes |
| SHA256 hash: | b48f9b04d522f941c493c074f4792ab3bb0d29c1cf20e5a0accf8383ff1e81e4 |
| MD5 hash: | 454a5ccae99b4e6f6068df2e9eae0af9 |
| MIME type: | image/png |
| Signature | SnakeKeylogger |
| File name: | 32512 |
|---|---|
| File size: | 20 bytes |
| SHA256 hash: | 808087df126c8c61cd3d908523ea0f1b7a1b5d9e0cece2c7e7b06cbd1c9ed9da |
| MD5 hash: | d24a8e63c78b1f125fbde9780530b06c |
| MIME type: | application/octet-stream |
| Signature | SnakeKeylogger |
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
packed
Result
Verdict:
MALICIOUS
Link:
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.Leonem
Status:
Malicious
First seen:
2022-10-18 02:15:50 UTC
File Type:
Binary (Archive)
Extracted files:
23
AV detection:
21 of 26 (80.77%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
snakekeylogger
Score:
10/10
Tags:
family:snakekeylogger collection keylogger stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Snake Keylogger
Snake Keylogger payload
Malware Config
C2 Extraction:
https://api.telegram.org/bot5495243543:AAG3XPeGW7yqfXF6_EXjGSfO9SWHJTpqVsU/sendMessage?chat_id=1128973051
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.55
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
SnakeKeylogger
zip 53947d3249013c415585a4bd2ed6f31415f98fa69d50e1720d13c381157a75d4
(this sample)
Delivery method
Distributed via e-mail attachment
Dropping
SnakeKeylogger
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.