MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f50d60a63c84a6c33ad036b98eb9da7441a68355859f8ba5d1ab4bb2baffdd11. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SnakeKeylogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f50d60a63c84a6c33ad036b98eb9da7441a68355859f8ba5d1ab4bb2baffdd11
SHA3-384 hash: cce5999e29e2f604bf3db5a5997975d3243a3ee458cfc3b8097253669a2af9a6cfb5f7e89878a5e1653af723c7c5b7b0
SHA1 hash: c839c6f8d4797ba1c657ae967affa66bf583c96e
MD5 hash: 5eb61838ce24d785ae25d6dd0593be6a
humanhash: twenty-yankee-angel-artist
File name:Request for Quote RFQ No. 8889.img
Download: download sample
Signature SnakeKeylogger
File size:1'572'864 bytes
First seen:2021-03-01 13:05:23 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:4GGMmLsmDcsWKmVofGzpVwJRyvt13aKHHWEAcooM47stnl72W41gZItPvaaaocy1:/GAmDsEWPwJIvF2dRotenl
TLSH 40750629626C7ED4E46DF374E030D130A2E6ED42A2EBC908E8D93C8B7DFA5837593515
Reporter abuse_ch
Tags:img SnakeKeylogger


Avatar
abuse_ch
Malspam distributing SnakeKeylogger:

HELO: mx.larkin.com.co
Sending IP: 190.90.167.24
From: Iris M. Bernal Moreno <irisbernal@larkin.com.co>
Subject: Request for Quote (RFQ) No. 8889
Attachment: Request for Quote RFQ No. 8889.img (contains "Request for Quote (RFQ) No. 8889.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
99
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

SnakeKeylogger

img f50d60a63c84a6c33ad036b98eb9da7441a68355859f8ba5d1ab4bb2baffdd11

(this sample)

  
Dropping
SnakeKeylogger
  
Delivery method
Distributed via e-mail attachment

Comments