Snake Keylogger - Detection Rate

VirusTotal detection statistics across 91 analyzed samples.

Last updated: 2026-10-06

Detection rates show how many antivirus engines on VirusTotal identify Snake Keylogger samples as malicious. A high detection rate (30+ engines) means most AV vendors have signatures for the variant. Low or zero detection indicates recently packed or obfuscated samples that may bypass signature-based endpoint protection.

Why Detection Rate Matters

For SOC analysts and threat hunters, detection rate is a key indicator of variant freshness and evasion capability. When Snake Keylogger operators release a new build with updated packing or obfuscation, detection rates drop temporarily until AV vendors update their signatures. This window of low detection is when organizations are most vulnerable. Monitoring this page helps you understand how well your current defenses cover Snake Keylogger variants.

Recommended Actions

If you see undetected or low-detection samples, consider submitting them to your sandbox for behavioral analysis. Update your YARA rules to catch Snake Keylogger patterns that signature-based detection misses. For the latest sample hashes to cross-reference, visit the Snake Keylogger samples page. For network-level indicators, check the IOC page.

36/64
Avg Detection
91
Samples Analyzed
51
High Detection
0
Undetected

Detection Distribution

High (30+) 51 (56%)
Medium (15-29) 30 (33%)
Low (1-14) 10 (11%)
Undetected (0) 0 (0%)

Per-Sample Detection

SHA256 Detection Threat Name
62d45c2346c9751e... 59/69 trojan.msil/chaos
db4426920fe2de2b... 58/70 trojan.msil/bplogger
ce0e09e88dd736d2... 56/70 trojan.msil/passwordstealer
b4991986b29c3882... 56/69 trojan.msil/vipkeylogger
d274af0fcf513c3d... 56/71 trojan.msil/noon
905875f98083af8c... 56/71 trojan.msil/noon
6e2c7b90b921e3a7... 55/71 trojan.msil/powershell
803d6aeb37985741... 55/70 trojan.msil/injuke
348237414eee4aa4... 54/71 trojan.msil/remcos
b6a901fba50ca305... 54/69 trojan.msil/formbook
da95e9481a7bf541... 54/71 trojan.msil/noon
6f156b9664a0f933... 53/71 trojan.msil/cryp
475134fd1bd6af31... 53/71 trojan.autoit/scrop
84e6f00fa7997051... 53/70 trojan.msil/noon
d0285d9b5584f7af... 53/69 trojan.msil/zusy
1ce77218079adad6... 53/69 trojan.msil/dnoper
d7234ff3482f7559... 52/70 trojan.msil/noon
c95048957b30f210... 52/68 trojan.msil/noon
7037a728d1eec6d7... 52/71 trojan.msil/checksumcontroller
66d3101e3b2207ac... 52/70 trojan.msil/noon
a0ae3275aed9137a... 51/68 trojan.autoit/auitinj
609c95b0b3d7ced9... 51/70 trojan.killav/negasteal
fa8bed9286024914... 50/72 trojan.msil/genie
28e6160a0c931d07... 50/66 trojan.autoit/scrop
5c1525ef7994d3a6... 50/69 trojan.msil/stealer
970d178fff5e535e... 50/69 trojan.msil/agensla
f2f79abe92741664... 50/69 trojan.msil/sonbokli
d6c16e5772a95542... 49/60 trojan.msil/passwordstealer
b7558d75d5cb4d8b... 49/63 trojan.msil/formbook
a15c1851d9a6b891... 49/70 trojan.heracles/mintluks
8ceb2c538d49fe52... 48/63 trojan.msil/xworm
14fa42318591e0dc... 48/71 trojan.msil/noon
cc3417c2cdd3d0a9... 48/69 trojan.msil/agenttesla
994e3908823894f6... 48/69 trojan.shelm/usbliu26
a9de89f097322550... 46/64 trojan.msil/formbook
d89531356bff0441... 46/66 trojan.yogi/msil
1741fe897473e7b6... 45/63 trojan.msil/darkcloud
1a56264052af72a5... 45/66 trojan.msil/noon
e9a3825e87a0b0a5... 44/65 trojan.msil/formbook
7c277911b85879bd... 43/71 trojan.msil/formbook
589ad55861e3bbb4... 42/61 trojan.msil/spynoon
c363e567a04e86db... 42/66 trojan.msil/gen2
c9548996fd7c80f4... 41/70 trojan.msil/genie8dn
69c218ebccd88de6... 40/59 trojan.msil/formbook
fcf5dbce80dd9046... 37/71 trojan.msil/noon
39c8c95325a5a1cb... 37/71 trojan.abtrojan/crackmapexec
790a90d32a32e769... 37/70 trojan.abtrojan/crackmapexec
2263046083f6f559... 36/70 trojan.msil/agensla
8a93756d5216c939... 34/66 trojan.mathtype/obfs
a6a05ef0ec845029... 33/48 trojan.msil/noon