MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c0ddd3020b0f17182da19ec1359f29aaf4248050f1130afc1e37c250e69b73eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
SnakeKeylogger
Vendor detections: 3
| SHA256 hash: | c0ddd3020b0f17182da19ec1359f29aaf4248050f1130afc1e37c250e69b73eb |
|---|---|
| SHA3-384 hash: | 3e2676e852507e69553f873235548f0e677901879e35a144b873e8480545d326a61ee1e98c09ddc039864270a7a9d3f4 |
| SHA1 hash: | f34490e32aeb51f9dd9585ab930cea8845b76276 |
| MD5 hash: | a764ca752bdc9c05129b61c1dcddb9bd |
| humanhash: | sink-wyoming-berlin-hot |
| File name: | INV000185.r09 |
| Download: | download sample |
| Signature | SnakeKeylogger |
| File size: | 316'520 bytes |
| First seen: | 2021-02-10 07:06:35 UTC |
| Last seen: | Never |
| File type: | r09 |
| MIME type: | application/x-rar |
| ssdeep | 6144:sDnvtVgC893+8qZAE8lxlLp847Hw/xeeJ6dsO+y4/qkZXWxt24Oz6afmniaJcF:wvtyCUueE8lxc47HddslrxU2gniak |
| TLSH | 8E6423D39E1F6599BD05F122A4EB1E91B74270377801F2F25039D4F6620AB527CCE26E |
| Reporter | |
| Tags: | r09 SnakeKeylogger |
abuse_ch
Malspam distributing SnakeKeylogger:HELO: secureserver.digitaledgekenya.com
Sending IP: 148.251.164.94
From: Alice Lin <mike@howw.com>
Subject: Re: Overdue Balance// INV#2021-000185
Attachment: INV000185.r09 (contains "INV#000185.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
111
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Infostealer.Stelega
Status:
Malicious
First seen:
2021-02-10 01:23:07 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
SnakeKeylogger
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.