🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ac37b8347e06593e9c8c06b60782b3560a85dd2a02f694bc43c6b05fa09e67bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeBiteStealer


Vendor detections: 10


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: ac37b8347e06593e9c8c06b60782b3560a85dd2a02f694bc43c6b05fa09e67bc
SHA3-384 hash: c5577b2ca6d4f8e95f3996745542b8c72e25ab025dbc66e5fb54f43e6feb03e869d847df1167c27b4792e0cc71250488
SHA1 hash: 9fe34abdae9bac8711ec2e3793426d1f3f8d600c
MD5 hash: 7936699d4629dd47e74d3e6a60476a3b
humanhash: arizona-saturn-one-mobile
File name:SUPPLIER_DATASHEETS_W1262feca_d2a2_set.vbs
Download: download sample
Signature SnakeBiteStealer
File size:481'094 bytes
First seen:2026-08-18 04:22:44 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 12288:3J9K/CuxnJ3R76vSWgn4iyifij2RI5rCB02:3PKlP7cStXfij2MX2
TLSH T12BA412CE59487A5598D640610F3FBF8803C1DB7BF322A56ECE1D8E9E8B411C64577E22
Magika vba
Reporter ppppt
Tags:SnakeBiteStealer vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
116
Origin country :
TH TH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm base64 base64 cmd cmdkey dropper encrypted evasive evasive explorer fingerprint hacktool lolbin macros-on-open msconfig obfuscated obfuscated packed powershell reconnaissance regedit rundll32 runonce sc schtasks wmic wscript
Verdict:
Malware
YARA:
3 match(es)
Tags:
Batch Command DeObfuscated PowerShell PowerShell Call Scripting.FileSystemObject Shell.Application T1027 T1059.001 T1059.005 VBScript WScript.Shell
Threat name:
Script-WScript.Trojan.Heuristic
Status:
Malicious
First seen:
2026-08-18 04:23:34 UTC
File Type:
Text (VBS)
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Verdict:
malicious
Label(s):
SnakeBiteStealer
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution persistence privilege_escalation
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
Executes a VBScript file via the Windows Script Host.
Adds Run key to start application
Checks computer location settings
Creates a file in the Startup directory
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Contains code to disable Windows Defender
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SnakeBiteStealer

Visual Basic Script (vbs) vbs ac37b8347e06593e9c8c06b60782b3560a85dd2a02f694bc43c6b05fa09e67bc

(this sample)

  
Delivery method
Distributed via web download

Comments