MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a994226e31e64a5c6f4419df4773d11930ddbdb4d216910dfbb23339de1c5745. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: a994226e31e64a5c6f4419df4773d11930ddbdb4d216910dfbb23339de1c5745
SHA3-384 hash: 4fed37fcfc55d9e1407ba2719a030602cb3b3673bc037ab96c3877e7f44f8ab984b0376027ab9ce24ec709cbe0ffef58
SHA1 hash: 2821137a820c726aa1722f62520c0c5240178d43
MD5 hash: a3af1e7f424d5eb69066adacf35b91ec
humanhash: pizza-bakerloo-romeo-moon
File name:Vessel Particulars.rar
Download: download sample
Signature SnakeKeylogger
File size:57'938 bytes
First seen:2022-05-31 09:54:29 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 1536:Y4bJXJUT9Fs7xkjvc4uyePTZOxTDsxy/dY5MZBn:YKJXqT9FsSjJuhdQTwYmKF
TLSH T1E34312D5700C356EE3C3A341F123A9E1DC3AD11C756C24D5EC897AA38F1A995879AEC3
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter cocaman
Tags:rar SnakeKeylogger


Avatar
cocaman
Malicious email (T1566.001)
From: "BainBridge Navigation <operation@bainbridgenav.com>" (likely spoofed)
Received: "from bainbridgenav.com (unknown [212.193.30.101]) "
Date: "31 May 2022 02:53:53 -0700"
Subject: "MV VICTORIOUS / BBN - LOAD PORT AGENCY APPOINTMENT"
Attachment: "Vessel Particulars.rar"

Intelligence


File Origin
# of uploads :
1
# of downloads :
256
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
formbook obfuscated packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.Seraph
Status:
Malicious
First seen:
2022-05-30 20:03:20 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
18 of 26 (69.23%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Delays execution with timeout.exe
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

rar a994226e31e64a5c6f4419df4773d11930ddbdb4d216910dfbb23339de1c5745

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
SnakeKeylogger

Comments