MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 9221fe9d8b10dded0ffe2545b8e249b3110834324ae3fff763066f944454473b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
SnakeKeylogger
Vendor detections: 4
| SHA256 hash: | 9221fe9d8b10dded0ffe2545b8e249b3110834324ae3fff763066f944454473b |
|---|---|
| SHA3-384 hash: | 541e5d62595e21d89196ee14955afa3f2de922a97c556a94b3868a23785dfee9e7a009b946f3676df8de155530b3d5d5 |
| SHA1 hash: | 483dda6ad27461ccc0f1d07b6dee84e88b0fbc73 |
| MD5 hash: | 02af62d99e4813a452be33a859fc9e8d |
| humanhash: | lithium-delaware-sad-west |
| File name: | doc20192910887888001990.r00 |
| Download: | download sample |
| Signature | SnakeKeylogger |
| File size: | 546'742 bytes |
| First seen: | 2021-04-07 05:52:56 UTC |
| Last seen: | Never |
| File type: | r00 |
| MIME type: | application/x-rar |
| ssdeep | 12288:3FO2+ISRmj3rsXE/KRX5tcCQeOzNfkqUZm1l6o:3FJXvWht5uSAh |
| TLSH | EBC423A26FD68D87F630558F42181F6490E3DF41806EEE3BBC1659FA01F5EB80689BC5 |
| Reporter | |
| Tags: | geo r00 SnakeKeylogger TUR |
abuse_ch
Malspam distributing SnakeKeylogger:HELO: afkim.com.tr
Sending IP: 45.133.1.167
From: afkim kimya <satis@afkim.com.tr>
Subject: Re: Yeni sorgu
Attachment: doc20192910887888001990.r00 (contains "doc20192910887888001990.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
111
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-04-07 05:53:12 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.35
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
SnakeKeylogger
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.