MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54966bb2a140389566c079581b547fdccf9f35f6a076e6b81a28c9fa38fdaf44. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 54966bb2a140389566c079581b547fdccf9f35f6a076e6b81a28c9fa38fdaf44
SHA3-384 hash: db046b7315344b96431130811a93d92660db82f094c9c93a03c564acc73bd4a500e98209c07dea2e93b691802bb10e0b
SHA1 hash: 69398bc7e61eb464c885f3e3efaeffb683853ad9
MD5 hash: b43265dab63b64b46c925788ccf39d86
humanhash: grey-johnny-bulldog-dakota
File name:SSGLPOJ6212202.zip
Download: download sample
Signature SnakeKeylogger
File size:400'474 bytes
First seen:2021-02-23 16:02:41 UTC
Last seen:2021-02-26 04:35:34 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:rcxMQ77sHM6lQSNoxIqpDYF1Xim8XqaK1FwM0+dvFlFG6HuAqfGrANl4N/cm3bH8:r2MW7hPpg1y1EoMdNJnIGoG/PDY
TLSH F0842315AA6BE8E5FDF71F9F99202ACA392DBD021706014DF182C7938B443819793F76
Reporter abuse_ch
Tags:SnakeKeylogger zip


Avatar
abuse_ch
Malspam distributing SnakeKeylogger:

HELO: 6sigma-mc.com
Sending IP: 103.99.1.158
From: sonia sibi <sonia.s@6sigma-mc.com>
Subject: NEW SSG/LPO/J6/21/2202
Attachment: SSGLPOJ6212202.zip (contains "SSGLPOJ6212202.exe")

Intelligence


File Origin
# of uploads :
5
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-23 16:03:08 UTC
AV detection:
18 of 47 (38.30%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

zip 54966bb2a140389566c079581b547fdccf9f35f6a076e6b81a28c9fa38fdaf44

(this sample)

  
Dropping
SnakeKeylogger
  
Delivery method
Distributed via e-mail attachment

Comments