🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca13d65a37a6a7475a57fa4edb457f4059ba3cea9056d8a0c29bfa7db48ed108. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeBiteAgent


Vendor detections: 9


Intelligence 9 IOCs YARA 10 File information Comments

SHA256 hash: ca13d65a37a6a7475a57fa4edb457f4059ba3cea9056d8a0c29bfa7db48ed108
SHA3-384 hash: ef075b7ffa9ea241bff95e09d43f254690edb022f308b86fc592d4583237171c62114aa6ad96c3a9bc0963e0b8021cb1
SHA1 hash: 86f992b81df9e3d8249909f9517c48761bdec7c1
MD5 hash: d25b13ef5c15e4620a4e0a3008634e3b
humanhash: ceiling-blue-minnesota-eleven
File name:Supply List_Purchase Order.zip
Download: download sample
Signature SnakeBiteAgent
File size:743'448 bytes
First seen:2026-10-01 04:41:05 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:v1qjbz0wlKpaef8UNsOGRaCE0TzU5CLaL5nWX8qJPEacrR7a0wKB8jjjeXX1LaeU:v1qjbz05aefvNsOGRaxaaLsjJParVpwJ
TLSH T1EBF423D922F30F049EB42920D3B588FD7B9A4D0340459A8C2BFDE86F1E07DE6675CA59
Magika zip
Reporter ppppt
Tags:SnakeBiteAgent zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
TH TH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Supply List_Purchase Order.cmd
File size:1'315'821 bytes
SHA256 hash: a822227f2722e9fedd3ef522e13a328cde19b4dca39c1f4c3963f1ed2aa430bf
MD5 hash: 0eb97306234df43a9e17247bf177abcf
MIME type:text/x-msdos-batch
Signature SnakeBiteAgent
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm base64 cmd dropper evasive lolbin masquerade mshta obfuscated powershell
Verdict:
Malware
YARA:
2 match(es)
Tags:
DeObfuscated PowerShell T1027 T1059.001 Zip Archive
Threat name:
Win32.Trojan.Sonbokli
Status:
Malicious
First seen:
2026-10-01 04:41:25 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
3 of 36 (8.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion execution persistence privilege_escalation trojan
Behaviour
NTFS ADS
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
Executes a command shell one-liner
Drops file in Program Files directory
Executes a VBScript file via the Windows Script Host.
Adds Run key to start application
Deobfuscate/Decode Files or Information
Enumerates connected drives
Indicator Removal: File Deletion
Modifies boot configuration data using bcdedit
Checks computer location settings
Creates a file in the Startup directory
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Contains code to disable Windows Defender
Modifies Windows Defender Real-time Protection settings
Turns off Windows Defender SpyNet reporting
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Base64_Encoded_Powershell_Directives
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments