MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bf7864e466d73cd8ef950a9c22baeb37b4eae5eae8c0b2b6b0d2917456add689. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 7


Intelligence 7 IOCs YARA 3 File information Comments

SHA256 hash: bf7864e466d73cd8ef950a9c22baeb37b4eae5eae8c0b2b6b0d2917456add689
SHA3-384 hash: b82d087512c3990c17bc6002ee7c8cf19dfbc3f6e1f395495f2229c02394cb5d185df95da3249fc48c752fe3fe994dcd
SHA1 hash: 7ec380a8bd932fef9b86accc9ef6aaee72329b31
MD5 hash: 5b52be1a01f9d52443cec85f8cdaf453
humanhash: batman-oscar-louisiana-cat
File name:Swift_92be67ab-e027-4955-b6fc-64bd720b2ba09.img
Download: download sample
Signature SnakeKeylogger
File size:1'441'792 bytes
First seen:2023-03-11 06:09:03 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:1uOZ6wGkB+e9uf8ndXPEVydJKW0iu+grKonmVk5OK:ddXPEVkJKPrpmVk5OK
TLSH T1C7659E523C98A15FE676CA76D24254BC32351D24F32EECD324C5FEDA3AB1B031692927
TrID 99.6% (.NULL) null bytes (2048000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.ABR) Adobe PhotoShop Brush (1002/3)
0.0% (.SMT) Memo File Apollo Database Engine (88/84)
Reporter cocaman
Tags:img payment SnakeKeylogger SWIFT


Avatar
cocaman
Malicious email (T1566.001)
From: "sales11@agrico.cn" (likely spoofed)
Received: "from agrico.cn (unknown [193.42.32.54]) "
Date: "10 Mar 2023 17:57:54 +0100"
Subject: "RE: Payment "
Attachment: "Swift_92be67ab-e027-4955-b6fc-64bd720b2ba09.img"

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
n/a
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:SWIFT_92.EXE
File size:870'400 bytes
SHA256 hash: 2dba0b58d60c5d50cfbfcae89e54cacf5e9d9f5d7a2cf654ca1e24f7544dbb47
MD5 hash: 91df64db8b0957de35deb0e0883187eb
MIME type:application/x-dosexec
Signature SnakeKeylogger
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
context-iso packed snake snakekeylogger
Result
Verdict:
MALICIOUS
Threat name:
ByteCode-MSIL.Trojan.SnakeKeylogger
Status:
Malicious
First seen:
2023-03-09 15:42:56 UTC
File Type:
Binary (Archive)
Extracted files:
28
AV detection:
14 of 39 (35.90%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_bitcoin
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

img bf7864e466d73cd8ef950a9c22baeb37b4eae5eae8c0b2b6b0d2917456add689

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
SnakeKeylogger

Comments