MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ac18f1cbdf0303e840e4da9594405257df6300374d748956c8378b07181c6129. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
SnakeKeylogger
Vendor detections: 14
| SHA256 hash: | ac18f1cbdf0303e840e4da9594405257df6300374d748956c8378b07181c6129 |
|---|---|
| SHA3-384 hash: | 97fa9ae61c9da55be410cab190b84565453808f8d07972529cb28a64c446c2686a4fee01bc4548f37489903a772b6956 |
| SHA1 hash: | 9463552f9b848b53738bf72ac905f40b3d7f9f4f |
| MD5 hash: | 8dd3855a63ba85db041f40faf159e6da |
| humanhash: | river-edward-july-enemy |
| File name: | Halkbank_Ekstre_20230523_080804_358439.pdf.exe |
| Download: | download sample |
| Signature | SnakeKeylogger |
| File size: | 615'936 bytes |
| First seen: | 2023-05-24 10:05:04 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'462 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:42N8jiZ4zypIPsLtPplTY6RhKuYDaGKXcAjDneMtPhY2WMOPNo9MD8K6sWgs:42N8jiZ4zypIPsLJTDE1a3XcAjKlhVo7 |
| Threatray | 5'469 similar samples on MalwareBazaar |
| TLSH | T113D41285A3BEAB0AD8BB17F1044495BC433E5D29B432E3475DD7B1DB5A60B480B82F27 |
| TrID | 69.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.0% (.EXE) Win64 Executable (generic) (10523/12/4) 6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.2% (.EXE) Win32 Executable (generic) (4505/5/1) 1.9% (.EXE) Win16/32 Executable Delphi generic (2072/23) |
| Reporter | |
| Tags: | exe geo Halkbank SnakeKeylogger TUR |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
790f8d85765401dc539584fc2075b326e306982adc99010f06637a769bb9443e
ef23c59e01d4ead9ddaf93012c303e5eaf45cb469b2adb64e3e2f950edda0172
823a206dcc8e78823dd154d935da7c7ba7029b9b51adfa1caaaca282fc7df829
c74b241653dd2fbda789f9198ab86773d71603ff64cce3356a4cbbd7f01ce2a4
afd8c936337691ea9b680f253002d428ca216c2056dcf3009ecb566f1e67395c
78875bd0e64072dd764f4de0b576eb4f9bba96db457422699986e9542bde530b
7ade52d9d7e7aa377a7855a6effe236cebdccf32661cbf1329ea4da9951f2df7
80a3bcecad3c5b6fe13c41124af786341400fec9cec151490d7861a3fc83be75
ac18f1cbdf0303e840e4da9594405257df6300374d748956c8378b07181c6129
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_SUSPICIOUS_Binary_References_Browsers |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers. |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_DotNetProcHook |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables with potential process hoocking |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many email and collaboration clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_TelegramChatBot |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables using Telegram Chat Bot |
| Rule name: | MALWARE_Win_SnakeKeylogger |
|---|---|
| Author: | ditekSHen |
| Description: | Detects Snake Keylogger |
| Rule name: | MAL_Envrial_Jan18_1 |
|---|---|
| Author: | Florian Roth (Nextron Systems) |
| Description: | Detects Encrial credential stealer malware |
| Reference: | https://twitter.com/malwrhunterteam/status/953313514629853184 |
| Rule name: | MAL_Envrial_Jan18_1_RID2D8C |
|---|---|
| Author: | Florian Roth |
| Description: | Detects Encrial credential stealer malware |
| Reference: | https://twitter.com/malwrhunterteam/status/953313514629853184 |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Windows_Trojan_SnakeKeylogger_af3faa65 |
|---|---|
| Author: | Elastic Security |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.