General

  • Target

    SecuriteInfo.com.TrojanLoader.MSIL.DaVinci.Heur.23220.28486.exe

  • Size

    549KB

  • Sample

    240625-j8er4a1hpn

  • MD5

    22904e3e98cfffa5ab2d97946ed9a296

  • SHA1

    d26763273d5c6df29f8ca95b14c57edd1509a6e8

  • SHA256

    7f0f2c04a5204bcb0314fe9fdf9a3369e516e19b0ead44c8f1d3319d59010e0d

  • SHA512

    e2de712dd61066fe21c2b7071a021ee9a2253229da32b706daf7b30b090a6043179eadf6e80d34f42970362ed72d2a88cb95877d7c70692be93adee7c0eff8cb

  • SSDEEP

    12288:AemD5wtNuLZWQHNOsZQnYt/ccdAqicTZZlBxAjVBuq:5+FZWQHTZ2id2c1PAjVP

Malware Config

Extracted

Family

snakekeylogger

C2

https://api.telegram.org/bot7301432976:AAH31iVg7cEj_CK4xnKcLgyVuIYziQoJStE/sendMessage?chat_id=1182519128

Targets

    • Target

      SecuriteInfo.com.TrojanLoader.MSIL.DaVinci.Heur.23220.28486.exe

    • Size

      549KB

    • MD5

      22904e3e98cfffa5ab2d97946ed9a296

    • SHA1

      d26763273d5c6df29f8ca95b14c57edd1509a6e8

    • SHA256

      7f0f2c04a5204bcb0314fe9fdf9a3369e516e19b0ead44c8f1d3319d59010e0d

    • SHA512

      e2de712dd61066fe21c2b7071a021ee9a2253229da32b706daf7b30b090a6043179eadf6e80d34f42970362ed72d2a88cb95877d7c70692be93adee7c0eff8cb

    • SSDEEP

      12288:AemD5wtNuLZWQHNOsZQnYt/ccdAqicTZZlBxAjVBuq:5+FZWQHTZ2id2c1PAjVP

    • Snake Keylogger

      Keylogger and Infostealer first seen in November 2020.

    • Snake Keylogger payload

    • Reads user/profile data of local email clients

      Email clients store some user data on disk where infostealers will often target it.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook profiles

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Collection

Data from Local System

2
T1005

Email Collection

1
T1114

Tasks