Snake Keylogger - Malware Samples

27 samples tracked (rolling 30 days)

Last updated: 2026-05-08

This page lists the most recent Snake Keylogger malware samples collected from MalwareBazaar. Each entry includes the SHA256 hash (linked to the MalwareBazaar sample page), original file name, file type, size, and VirusTotal detection rate where available. Samples are updated daily and retained for a rolling 30-day window.

How to Use This Data

Security teams can use these hashes in several ways. Import them into your SIEM or EDR platform to detect known Snake Keylogger variants in your environment. Cross-reference file names against your email gateway logs to identify phishing campaigns delivering this family. The file type distribution reveals which delivery formats are currently in use - a shift from .exe to .msi or .js may indicate the operators are adapting to your defenses. Samples with low or missing VirusTotal detection rates are the most dangerous - these are fresh variants that may bypass signature-based protection.

About the Data

All samples are sourced from MalwareBazaar, a free malware sample sharing platform operated by abuse.ch. Detection rates come from VirusTotal. This data is provided for defensive purposes only. For the latest Snake Keylogger indicators of compromise including C2 servers and domains, see the IOC page.

SHA256 File Name Type Size Detection First Seen Country
6f156b9664a0f933... 6f156b9664a0f933075436c8f3a123635005ed059fc88bf5e053d76cd619f1db exe 1.1 MB 53/71 2026-05-08 -
fa8bed9286024914... fa8bed9286024914510fafdfc2eb70dcfe8999f8f768e19b7fa98d64d8035a76 exe 1.0 MB 50/72 2026-05-08 -
a0ae3275aed9137a... a0ae3275aed9137a9a36c7dc0e8ab950281ae8bb26573ad7233be06f2ad5ea6d exe 1.0 MB 51/68 2026-05-08 -
6e2c7b90b921e3a7... 6e2c7b90b921e3a70b16d29b9dde6fc06d0798849d09cd1420c99a76abca6908 exe 936.5 KB 55/71 2026-05-08 -
1741fe897473e7b6... 1741fe897473e7b6f70d5fe19918ea3e41deb9babe12dc8b0a041c8ac71c767c exe 1.0 MB 45/63 2026-05-08 -
28e6160a0c931d07... 28e6160a0c931d0731823e752dc32659a51dc2b9abd3d75b9000366d3e2070a4 exe 1.1 MB 50/66 2026-05-08 -
475134fd1bd6af31... 475134fd1bd6af31bbb8f76aaa1db2aa9eeb9bde747de1e8d04b399707f063f2 exe 1.1 MB 53/71 2026-05-08 -
70b8e9cd74923561... RFQ-09580-MQ-05868-PR-0686-04-2026-ADNC-05868.bat exe 962.5 KB 25/66 2026-05-05 -
be06aab9e611d76a... Payment_Advise00383567.exe exe 1.1 MB 29/69 2026-05-04 -
7d90636465939a1a... msedge_elf.dll exe 1.5 MB 22/69 2026-04-29 -
a4e9bbd5382dd359... VirtualProcess.bat bat 181.3 KB 14/58 2026-04-28 -
99f0cef71d37176e... OrbitalProtocol.bat bat 181.3 KB 12/61 2026-04-28 -
31ee885db60cd911... ps_FpvsSrwVngoR_1776784364633.ps1 ps1 569.6 KB 13/55 2026-04-28 -
ce6fb377a643909b... KPUUGPIE.ps1 ps1 553.5 KB 18/60 2026-04-28 -
bbe37ae6c1d6534d... ps_HnlGI71CktiE_1776149876718.ps1 ps1 636.7 KB 22/61 2026-04-25 -
84ae4d3d39fa01c5... ltqai.ps1 ps1 16.6 MB 7/61 2026-04-25 -
132fbaa338bf5782... ps_5GUHlnbLV7jA_1776699154658.ps1 ps1 569.6 KB 14/61 2026-04-25 -
419b24867a2cdba9... SILENCE.ps1 ps1 218.5 KB 20/63 2026-04-23 -
b9552a61439efa4f... MV_LIBRETY_KING_V_MAIN_INFO.bat bat 296.3 KB 28/62 2026-04-23 -
2525aba3aa0c6896... RFQ_ORDER02384334.bat bat 8.6 KB 25/61 2026-04-23 -
83bbbf8a6bf9ea44... RFQ_PURCHASE_ORDER0966789.js js 808.3 KB 18/62 2026-04-21 -
ec628a344ca23797... RFQ_Order092374589458.js js 825.4 KB 19/59 2026-04-20 -
671839c24c52d9e1... RFQ-AJC-QINHP5-TIS-L0009.js js 774.8 KB 14/52 2026-04-20 -
8a93756d5216c939... Cipada.xlam xlsx 2.0 MB 34/66 2026-04-16 -
79e6b2c3d0105007... MV_GARDENIA_K_VESSEL_PARTICULARS.exe exe 649.5 KB 29/72 2026-04-15 -
88d63b0589f9ccb2... PO 65090663(KB34).pdf.js js 907.7 KB 23/62 2026-04-14 -
348237414eee4aa4... Dekonk.exe exe 1.2 MB 54/71 2026-04-08 -