General

  • Target

    1061052e6af2a0c5b93bd3208b799b53_JaffaCakes118

  • Size

    1.2MB

  • Sample

    240626-cnhjxsyekg

  • MD5

    1061052e6af2a0c5b93bd3208b799b53

  • SHA1

    ae2717741a67a667810bc1acd0d2410fb3f123c7

  • SHA256

    dd52c7558bea0e028364a138ed99a13962d0d8ac14c5c17b8645741ac82792bb

  • SHA512

    53719347af2891281e8152538d700d03f1fe1f8226ad336a2be6d0da6d09c85aaa3c281a59465ea29c5a6e1d87729bd814a15e390e7bc2b19edb95f5aa0913ee

  • SSDEEP

    12288:mmmWpzZDRj6jRPLjRPqjBjjyjBjBjBjBjLjuY1amldaailF/d85+BpNij60ToZUh:E1aAOFJT26IEIXj450RRe9cV

Malware Config

Extracted

Family

snakekeylogger

C2

https://api.telegram.org/bot1634002210:AAGipukUEr-bNBgl2R1_hwFgfb9ez_v6wzE/sendMessage?chat_id=1401219117

Targets

    • Target

      1061052e6af2a0c5b93bd3208b799b53_JaffaCakes118

    • Size

      1.2MB

    • MD5

      1061052e6af2a0c5b93bd3208b799b53

    • SHA1

      ae2717741a67a667810bc1acd0d2410fb3f123c7

    • SHA256

      dd52c7558bea0e028364a138ed99a13962d0d8ac14c5c17b8645741ac82792bb

    • SHA512

      53719347af2891281e8152538d700d03f1fe1f8226ad336a2be6d0da6d09c85aaa3c281a59465ea29c5a6e1d87729bd814a15e390e7bc2b19edb95f5aa0913ee

    • SSDEEP

      12288:mmmWpzZDRj6jRPLjRPqjBjjyjBjBjBjBjLjuY1amldaailF/d85+BpNij60ToZUh:E1aAOFJT26IEIXj450RRe9cV

    • Snake Keylogger

      Keylogger and Infostealer first seen in November 2020.

    • Reads data files stored by FTP clients

      Tries to access configuration files associated with programs like FileZilla.

    • Reads user/profile data of local email clients

      Email clients store some user data on disk where infostealers will often target it.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook profiles

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

3
T1552

Credentials In Files

3
T1552.001

Collection

Data from Local System

3
T1005

Email Collection

1
T1114

Tasks