MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53947d3249013c415585a4bd2ed6f31415f98fa69d50e1720d13c381157a75d4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 53947d3249013c415585a4bd2ed6f31415f98fa69d50e1720d13c381157a75d4
SHA3-384 hash: ba41789c8d59f536307e795d21727a3094e23c4dea6441d7dbb18ad62325335e23974a81ba3b5d40229ab951baa4139c
SHA1 hash: efc809f6858a3c468aa518d17a619229d0999b6f
MD5 hash: d92d722bb448707226a238747a3f6ba4
humanhash: rugby-summer-nine-montana
File name:fishcom2021,2022.zip
Download: download sample
Signature SnakeKeylogger
File size:439'212 bytes
First seen:2022-10-18 07:12:14 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:Q7evVWHTHt/hP+Cki1wcbfrv/mhqUXkSStUDkAb6fgRsw:Q7CVWHps0TryXIMkwyw
TLSH T1219423871BEB31CC2A4E9499D7205611B80FFB05F50B258BAE7A5FC66098DE32F547C8
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter cocaman
Tags:SnakeKeylogger zip


Avatar
cocaman
Malicious email (T1566.001)
From: "Natalija Kramer <natalija.kramer@ema.si>" (likely spoofed)
Received: "from ema.si (unknown [185.222.58.61]) "
Date: "18 Oct 2022 03:15:57 +0200"
Subject: "EMA CUSTOMER ANALYSIS"
Attachment: "fishcom2021,2022.zip"

Intelligence


File Origin
# of uploads :
1
# of downloads :
197
Origin country :
n/a
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:version.txt
File size:1'654 bytes
SHA256 hash: efdacdd2483a616f0f93a0ccba1261787870c7c1f0db19a58c5003a03961fbe9
MD5 hash: 6a96dba59c947963e432eb2d6138987a
MIME type:application/octet-stream
Signature SnakeKeylogger
File name:1
File size:7'427 bytes
SHA256 hash: b48f9b04d522f941c493c074f4792ab3bb0d29c1cf20e5a0accf8383ff1e81e4
MD5 hash: 454a5ccae99b4e6f6068df2e9eae0af9
MIME type:image/png
Signature SnakeKeylogger
File name:32512
File size:20 bytes
SHA256 hash: 808087df126c8c61cd3d908523ea0f1b7a1b5d9e0cece2c7e7b06cbd1c9ed9da
MD5 hash: d24a8e63c78b1f125fbde9780530b06c
MIME type:application/octet-stream
Signature SnakeKeylogger
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.Leonem
Status:
Malicious
First seen:
2022-10-18 02:15:50 UTC
File Type:
Binary (Archive)
Extracted files:
23
AV detection:
21 of 26 (80.77%)
Threat level:
  5/5
Result
Malware family:
snakekeylogger
Score:
  10/10
Tags:
family:snakekeylogger collection keylogger stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Snake Keylogger
Snake Keylogger payload
Malware Config
C2 Extraction:
https://api.telegram.org/bot5495243543:AAG3XPeGW7yqfXF6_EXjGSfO9SWHJTpqVsU/sendMessage?chat_id=1128973051
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

zip 53947d3249013c415585a4bd2ed6f31415f98fa69d50e1720d13c381157a75d4

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
SnakeKeylogger

Comments