MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e26dfc27c5d8597a2a64bcab378c8a47946274b04df424aad3d157ac40534ffe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e26dfc27c5d8597a2a64bcab378c8a47946274b04df424aad3d157ac40534ffe
SHA3-384 hash: 5076269e00f065dce90338b5a2b8879c74d47a405f7d54716f5689fb2ae8f0e3cbf80f149c626c10b7d2d2d50b668a72
SHA1 hash: a6fe726d267c8737c118edab75d8540ebcb33e7b
MD5 hash: bc9ab3140d89a8b7200730d3308f1681
humanhash: jig-dakota-angel-hawaii
File name:910023458.zip
Download: download sample
Signature SnakeKeylogger
File size:305'260 bytes
First seen:2021-01-30 13:00:41 UTC
Last seen:2021-02-09 15:29:42 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:GFHlPvDlbqjrZfxPN7rKOAKW6EyKNq3bDXA1QjJs:GbPBbqjrVrKnguIXESJs
TLSH C854237D56E360F515D382B636FB1F5C9388988538DC7A65D062CD42A8F3A1FBF60A80
Reporter abuse_ch
Tags:zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: TRANSUNIVERSE.BE
Sending IP: 185.222.58.152
From: ACCOUNT <accounts@TRANSUNIVERSE.BE>
Subject: Pending Invoices
Attachment: 910023458.zip (contains "910023458.exe")

Intelligence


File Origin
# of uploads :
17
# of downloads :
219
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-30 08:37:13 UTC
AV detection:
14 of 46 (30.43%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

zip e26dfc27c5d8597a2a64bcab378c8a47946274b04df424aad3d157ac40534ffe

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments