MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e03e15cc28cb2a064596a96e533a36b3f8133a30b4485d58a45f33bc55d67d35. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
SnakeKeylogger
Vendor detections: 15
| SHA256 hash: | e03e15cc28cb2a064596a96e533a36b3f8133a30b4485d58a45f33bc55d67d35 |
|---|---|
| SHA3-384 hash: | 83ac2902ab97490a070a1454081a81e5ce17c18f9ca94467f34e6e78e3c53ad328c7c35027a0ea11ec4e059a1efa002f |
| SHA1 hash: | 3b777eb3422f17f64f179df02389f38c977be73d |
| MD5 hash: | de45e89629b9f9b7cc619099decd76b2 |
| humanhash: | six-wisconsin-blue-salami |
| File name: | mor.exe |
| Download: | download sample |
| Signature | SnakeKeylogger |
| File size: | 601'088 bytes |
| First seen: | 2023-09-12 07:34:21 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'462 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:LODphClGCx5AisUOkFX0sMpBKCUt35dxC:LDD8ZUl5dxC |
| Threatray | 5'509 similar samples on MalwareBazaar |
| TLSH | T187D44C0123F59B10E57E6BF5DA74812287B93956652EF31D9CC0A8CA1EA1F139BC3B07 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4505/5/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Reporter | |
| Tags: | exe SnakeKeylogger |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Behaviour
Unpacked files
2ea95697b79458479ff70e389a34ed1c57adaa2563afec01696c8315e98ce48f
e03e15cc28cb2a064596a96e533a36b3f8133a30b4485d58a45f33bc55d67d35
b21eec609d669ee05193d8d07beedf3436c8ee340e6fb83ea874340753957feb
f9dc0ae354f8db63f7cf68e7bc5139a7e9f24dc16c333206269c45f7e3c4e2a9
b7cf6d12593237cf95e4b425719811880084b0e71871f124ea64b57955af4051
acad9e6b6a2cc70dde6fc6ba4d85171429ca4afc10a3c397937db5e209caf856
d0659f8d337232622688d25aca3c38e2e8766cba24836f4c9f76774a1a5ba370
d0018553788684559db6376fe759c7eb91b56532f24fcdee4468dae430511231
3f17b75014b3eb38b7c62f4ced6ba7777733bdd04a164194afde81369ab9fb9f
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | crime_snake_keylogger |
|---|---|
| Author: | Rony (r0ny_123) |
| Description: | Detects Snake keylogger payload |
| Rule name: | INDICATOR_SUSPICIOUS_Binary_References_Browsers |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers. |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_DotNetProcHook |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables with potential process hoocking |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_TelegramChatBot |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables using Telegram Chat Bot |
| Rule name: | MALWARE_Win_SnakeKeylogger |
|---|---|
| Author: | ditekSHen |
| Description: | Detects Snake Keylogger |
| Rule name: | MAL_Envrial_Jan18_1 |
|---|---|
| Author: | Florian Roth (Nextron Systems) |
| Description: | Detects Encrial credential stealer malware |
| Reference: | https://twitter.com/malwrhunterteam/status/953313514629853184 |
| Rule name: | MAL_Envrial_Jan18_1_RID2D8C |
|---|---|
| Author: | Florian Roth |
| Description: | Detects Encrial credential stealer malware |
| Reference: | https://twitter.com/malwrhunterteam/status/953313514629853184 |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Windows_Trojan_SnakeKeylogger_af3faa65 |
|---|---|
| Author: | Elastic Security |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.