MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9b665e3a9bf7e5fb967be0c1d54c19967250e796a190d2bc55380fbdfa7e426a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 9b665e3a9bf7e5fb967be0c1d54c19967250e796a190d2bc55380fbdfa7e426a
SHA3-384 hash: 0b0e11f3fb6a251debfcc22fff2c5f1c0034d71318d9f02f0bb16b61fc68e0b7ccf9a8be2c116b2abf37919f84ed2209
SHA1 hash: 46aee4fe73e41515604f0becf7f0aa73a118e96b
MD5 hash: bf430deddf941c66699e61dabe99161c
humanhash: venus-ten-aspen-kitten
File name:TDX Drawing 07482#.r00
Download: download sample
Signature SnakeKeylogger
File size:654'998 bytes
First seen:2021-06-25 06:34:52 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:WRtvAX4FFa6/Bop0V3gCru9HbtZFeY4yb/TNReIgwD9f:WHvARp0V3gCru3eY404AJ
TLSH 80D423F89048F8DD6E18E47C99B48511BC9A00DEE7E2FBA35FD200165BE16507B896CA
Reporter cocaman
Tags:r00 SnakeKeylogger

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-06-24 21:27:40 UTC
AV detection:
10 of 46 (21.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

r00 9b665e3a9bf7e5fb967be0c1d54c19967250e796a190d2bc55380fbdfa7e426a

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
SnakeKeylogger

Comments