General

  • Target

    235feecbf39c506144e406ee52d764d830e5124d113280a5e339bf3bdee978a5.exe

  • Size

    3.0MB

  • Sample

    240701-bd3axa1emc

  • MD5

    57cb0d1fbbe7e57e906d9bec624ff50f

  • SHA1

    d8eeb1c8e4530d619c7a5927fec5fcc892e0b24f

  • SHA256

    235feecbf39c506144e406ee52d764d830e5124d113280a5e339bf3bdee978a5

  • SHA512

    7d0be14e10f4174648cb597b9f8b32883088b9fed59cd4812339cdb379746e49b58dfb357d733fcb9b73c725451b64f6588e328518091b6311ef38c1dc41d886

  • SSDEEP

    12288:RaoerDVWSJRvp61xGNoQOgR4FeGQ5fzF2M9PbxyWnnMRGIliKj:RinVl1Yeo0R4FeHX2qwRFj

Malware Config

Extracted

Family

snakekeylogger

Credentials

  • Protocol:
    smtp
  • Host:
    valleycountysar.org
  • Port:
    26
  • Username:
    [email protected]
  • Password:
    fY,FLoadtsiF

Targets

    • Target

      235feecbf39c506144e406ee52d764d830e5124d113280a5e339bf3bdee978a5.exe

    • Size

      3.0MB

    • MD5

      57cb0d1fbbe7e57e906d9bec624ff50f

    • SHA1

      d8eeb1c8e4530d619c7a5927fec5fcc892e0b24f

    • SHA256

      235feecbf39c506144e406ee52d764d830e5124d113280a5e339bf3bdee978a5

    • SHA512

      7d0be14e10f4174648cb597b9f8b32883088b9fed59cd4812339cdb379746e49b58dfb357d733fcb9b73c725451b64f6588e328518091b6311ef38c1dc41d886

    • SSDEEP

      12288:RaoerDVWSJRvp61xGNoQOgR4FeGQ5fzF2M9PbxyWnnMRGIliKj:RinVl1Yeo0R4FeHX2qwRFj

    • Snake Keylogger

      Keylogger and Infostealer first seen in November 2020.

    • Snake Keylogger payload

    • Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.

    • Detects executables packed with or use KoiVM

    • Detects executables referencing many email and collaboration clients. Observed in information stealers

    • Detects executables with potential process hoocking

    • Accesses Microsoft Outlook profiles

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Tasks