MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 be0de5c578271405defd5391355546b521881957b891d7423f1d0a7d04cc6bb3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
SnakeKeylogger
Vendor detections: 13
| SHA256 hash: | be0de5c578271405defd5391355546b521881957b891d7423f1d0a7d04cc6bb3 |
|---|---|
| SHA3-384 hash: | 5333e59738d83c60ed3fdfd50d71ff89ee5d7a0b3558c292f31ea909890166264d8397b309a7751f7b4eef33501c53ab |
| SHA1 hash: | ca64dcd0bb058f8295618fa599cbb42a9774a60c |
| MD5 hash: | 53fa12c9f3b8e6ea29746b988ee914e0 |
| humanhash: | texas-king-hawaii-finch |
| File name: | Teklif Alma-Elekt Malz. sip. AMP282104-2 DİŞİ 2P() 2000 adet..exe |
| Download: | download sample |
| Signature | SnakeKeylogger |
| File size: | 839'168 bytes |
| First seen: | 2025-05-08 14:33:40 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'649 x AgentTesla, 19'454 x Formbook, 12'202 x SnakeKeylogger) |
| ssdeep | 12288:IyZA6yfjh/s7T28+98lNfw/shmhehBrSnxusytHjKFYXR6thnCZ2dgkXqsG:hZGjh/smFQKskheXSxEKCXM3n |
| Threatray | 369 similar samples on MalwareBazaar |
| TLSH | T1C805F19C7780F85FC40387354AA5DE307574AC9A9B17D60387D72DEB780E6EA8E053A2 |
| TrID | 69.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.0% (.EXE) Win64 Executable (generic) (10522/11/4) 6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.2% (.EXE) Win32 Executable (generic) (4504/4/1) 1.9% (.EXE) Win16/32 Executable Delphi generic (2072/23) |
| Magika | pebin |
| dhash icon | 38d8c8c4ccece4e0 (7 x SnakeKeylogger, 6 x Formbook, 2 x MassLogger) |
| Reporter | |
| Tags: | exe geo SnakeKeylogger TUR |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
3213e3ba1ecf7be2adff26e061f17c586902efb10d2c6619d5e9dc1f4e34db68
9dea2c8077ef669f375ee39b3696212613965aa7abc9cd511260700b274fb52e
ad573f8ee01fb3bf0e278c1a8a5a24dd9299ce03a69ef56706148e406a0e71df
641dae29115b5ef163a2d5a5c75cdc8dac0a37aa0e4c5a08ca522ce17b306b39
f91c4c7fd22d1d1ad83e7b8984b7b317689c6c75b3dc5ad29292a72161ab2164
be0de5c578271405defd5391355546b521881957b891d7423f1d0a7d04cc6bb3
29000f325fd7c588f6a80f4b91dda56c86282cf110a1551b61331ab65e29206b
b328153ea8acafcec5716b372a93c387a92a08e603f30e6016b4a93db0c7f90a
63d650d546b161f61474835a6547cfb840de49d7462814879c306cba240dc739
7539e662f669a3436cd5c07186579f1c83f71b16166afe082e764ecf013342d7
4797cb80b22ba0da0ede6593bfc16399a5ffc289400155115c8de7786ea0db49
407d971ab2a45c6b84aea4658827fdf816e4bcc94d97319d813b1a96ad8c3b1e
c6e7f1dfe1147b82aa1a3f872cbfa81183d777911edc6a4623255b7db6cf0d86
840ecbe67b468d355c7a3be951f5875a70b5f6295b5cd599ee7cc4ef9015a794
3c831d32919d82c5b30e3bbe158dff4d2090803e5553248eabdedd95dd085736
0ebfd6beeae72ae9f0a77968d90714146f353a32642c957a4b6774a57dadf287
4f8dff4a98a4dc1e366f3ed7fea7ecb9e241513d53b8c1162b6d10e82f503444
797f44aa209382a598bf62263d36a65d3c0b238c6e056ac1df84dd989d79ff03
299dbcf74564593cca443ee4575c1b28e9df0109799565d7004d99767a6d366e
1df3a2d85ac9bdbfbfae21c062956d5500ae4270bddf5233e72db71527a21585
80c896a08d7847ff7d282d383deb7b753b2bd3e06e6cb3dbe7731adcae32197d
865d757dbd675369b749dd68b1da5f785900d98d39386376e3464422248fa561
024537bcb5cb2e33a164a13fa87e13dfc129efe2dd656084f3954f4ba5a821e1
fe425f034245df80aa7de7f613c39ecc9801077ccb38d23f153ba9076c1e6f35
134c8c01c688d2f6a23765c6f917633d2c9f440e6c37753874ddd938862b1ff0
efa9015c2a50a3b7184d201badbe5037764e8dbf61d4267f1479f2150f219d02
b3b3d2e1dfc77efa21b337da267d93da1e3900625c6670e3629d20340e9f0dd8
f3b03dd677c48f38d3e407c423b77ff7b8e5a51cf096cb4673f6f0f016bd6b3c
e3cb3001029182361258d524410fc51f780eca6363a2fd292856bab3326678d1
31e9d19c8f6d7662f150210f4864740af71b58a9f71350ba27167f403d2bac6a
2f94407595db6811148d80660ae322c360c7c5935adaafde9996b6cb610f26e7
7499f69524a85e3fef6b56b14254f87ba6733de5c21f2b0fac5832aeb095e77e
88edce54585b6fd0c886090c53e8f8db451fe67eb1bbafbeac17fcbd694392e8
d4a33be36cd0905651ce69586542ae9bb5763feddc9d1af98e90ff86a6914c0e
d1c11f1e8bbb7eea6fec0d0cd0657ea9145206b91e7220374b771b7ca4b79010
83cdcf1f7b8b580c62b4bc74e0ec2eb1fb18e2229335179d4f333c6b5f52f4ae
fd0049f3bb1393c8192f8053301b8472a18f1bbedb4011655d756fbf3a0b3aa5
0578eeb29bd6418a75a34d5809cc64bcf903cab949060ad38cb2224d23bec10c
b3752b8138360ee7ab6f3583c942f1d2ee806f7ede9123ada34abbf27a055633
e9dcf2288b4adbbfe01de0f952df0f050ef533fa151e77b786ceee577f51a079
247e21229eb4b45928cb2aaeb92a709c3c1e2ce241d99a189775fed95a781e07
9262bb8d45b86ce3583351d99db66eeb3481102a260477360d93185677da2863
138279e950c38c7a2d3c554bbb5b91ea55e7d0c87241c455650d9cc7262cbf6d
80178f684d8914808b1717c7b39b77bbfe616859cee6e117be0f25a99c02fc76
64f00b4e38add0516c0e601276579334518245702815d8fbb4b7c83a77866058
f6b63b291d9596ec5ab7aa65997850c9ac23feb8e5e67a1bf09dfc84221d10bd
4d7aa33e9b949ab328335825604b5e45050c5a5d947a275c650553e0e9f26132
68f21baa9f00e498b8b31630e46addb81a4b4ef3f86d097708b6d6540fdcc8ac
5f63d86d5175fe1b15194dedb48e5eadb0ae1f4656b3ca86a2055df558bdcafc
071c7e6ccfdfb3e88afad91f2e52148213aeb6c36d11155b940f6eaf57642cf0
fa07c7fc145471495727561a074add9874a3572f46dc6c340c3ed1d8646c032f
01b4740a5c1779f464a381836e4b5e95e8e360b46cd95d492cbee029ef06f029
6a39c812d087f3b770de7c05669007bb83d9fb0fc9563d17ee726c96d872af59
8fac642a58b28ce2d0d152bb0dfefc539f85dcbadc6fcd3de2bd9b060b4625c7
9e3ce6488f70a8cddb11c36dc9dc9cdd9cfffabd699d56237843377df8afa5c0
2d51ee60b5d5dc2bdd5de9319b9d174862af7bb205addfbe895bd59df9ac4a64
fd1f814527b20c677b1d8b366be6b75c08219b5c315f0d0d9f8535a13aba2c47
078cd1b6995a95e2057591899a7050da5799ad226afefd75fd442060efd1b027
083f0da491a84fd49f5abfc07b65d65931c1be5675a6a878495bc80880d98865
be0de5c578271405defd5391355546b521881957b891d7423f1d0a7d04cc6bb3
d4020dbe1d51f7f27e253deeb65f1fed6b788091f5adad460f035256ae198a81
b7c25110371e04e935dffad7ec2364cef2725b474f2d62064a369d0e1d3247ce
de1c33694def3b635687a1be3fd3ea586273ef148a664b566b02b187ef2688db
4b6a5d12756b9e746f8bb79d52298927a1116f659e89b8727d0f3f188e1638d9
96abdb9ad0db8612acab489da720957eb633e12c74e6de77d3e81dab6b7b63b5
83720bec38d91097735649d6c29d406f7c1d7521f67e69cafce0437743cf3ebb
ba9856286b079931468e0a80830ae8855efdf38462f467dc7bc91f8a0ccd39e5
736f86e7a431a4307a6ca7ff1650d32a8cb8d68426f6336f87b2041978541d6e
e22479542da314d41da623dd86740e38da3563ea109c0f258e1f6c8993fd468f
73d47bc6706b395ab8a96c53d23af3eaf4faf4c8b92f595b0714c8040096bd5b
b9b8fb27a1f249497e04a36a2c0add5059138a953982e91fa26b293e7c15ef41
f86c8270277c5a7e0213bd9b864d39602f4e46364323b18ea931eba3573ac2aa
b7c7a3bd36dc7993df91c0a108529dd073751f8dc823672f47e5ba128be0f4db
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
|---|---|
| Author: | XiAnzheng |
| Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.