MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 9f341c2ed70d1aaa62fb12544a03889c855eac8b8a322ae103fd1559a5101176. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
SnakeKeylogger
Vendor detections: 5
| SHA256 hash: | 9f341c2ed70d1aaa62fb12544a03889c855eac8b8a322ae103fd1559a5101176 |
|---|---|
| SHA3-384 hash: | 8dae9aeee66a20e16ddb51a07582366c850658d08a634726d0afc70dad593797e6238fa69d251a2c6803c2a53ab7915b |
| SHA1 hash: | 5e7cedfeec528b72e327d999a83649c055505c15 |
| MD5 hash: | 823dbcb9f7b5746179395a93623330ab |
| humanhash: | whiskey-mango-mobile-hydrogen |
| File name: | New Purchase Order.gz |
| Download: | download sample |
| Signature | SnakeKeylogger |
| File size: | 293'800 bytes |
| First seen: | 2021-02-11 07:23:19 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 6144:IQkAJujISX0/J+8JI7d1LFF8/Yi1vQlxtnYr+4yCLWj9d4y2WH:IQfJ+fEx1I7d1LrIYi1vcnYrXyYWjUyH |
| TLSH | 7D542355FF175A113FA1188FE8081918750B9DE4B0B6F67223003AC4B95FA587D6FF26 |
| Reporter | |
| Tags: | gz SnakeKeylogger |
abuse_ch
Malspam distributing SnakeKeylogger:HELO: wgsomias.com
Sending IP: 46.183.220.42
From: Barbara Barker <abdelghani.mekhelfi@wgsomias.com>
Subject: RE: Purchase Order
Attachment: New Purchase Order.gz (contains "New Purchase Order.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-11 20:07:30 UTC
AV detection:
21 of 47 (44.68%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
SnakeKeylogger
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.