MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9f341c2ed70d1aaa62fb12544a03889c855eac8b8a322ae103fd1559a5101176. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 9f341c2ed70d1aaa62fb12544a03889c855eac8b8a322ae103fd1559a5101176
SHA3-384 hash: 8dae9aeee66a20e16ddb51a07582366c850658d08a634726d0afc70dad593797e6238fa69d251a2c6803c2a53ab7915b
SHA1 hash: 5e7cedfeec528b72e327d999a83649c055505c15
MD5 hash: 823dbcb9f7b5746179395a93623330ab
humanhash: whiskey-mango-mobile-hydrogen
File name:New Purchase Order.gz
Download: download sample
Signature SnakeKeylogger
File size:293'800 bytes
First seen:2021-02-11 07:23:19 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:IQkAJujISX0/J+8JI7d1LFF8/Yi1vQlxtnYr+4yCLWj9d4y2WH:IQfJ+fEx1I7d1LrIYi1vcnYrXyYWjUyH
TLSH 7D542355FF175A113FA1188FE8081918750B9DE4B0B6F67223003AC4B95FA587D6FF26
Reporter abuse_ch
Tags:gz SnakeKeylogger


Avatar
abuse_ch
Malspam distributing SnakeKeylogger:

HELO: wgsomias.com
Sending IP: 46.183.220.42
From: Barbara Barker <abdelghani.mekhelfi@wgsomias.com>
Subject: RE: Purchase Order
Attachment: New Purchase Order.gz (contains "New Purchase Order.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-11 20:07:30 UTC
AV detection:
21 of 47 (44.68%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

gz 9f341c2ed70d1aaa62fb12544a03889c855eac8b8a322ae103fd1559a5101176

(this sample)

  
Dropping
SnakeKeylogger
  
Delivery method
Distributed via e-mail attachment

Comments