General

  • Target

    f3c462280fd1964d68c76ff6889bd3c766fa7140c07962dda32c0cb488188695.exe

  • Size

    1.5MB

  • Sample

    240701-bsajfasaqh

  • MD5

    ec3fe16c54946213c717a27606f70243

  • SHA1

    d11efe4e0f949ff6b14929cd30ae146c1b4a11c9

  • SHA256

    f3c462280fd1964d68c76ff6889bd3c766fa7140c07962dda32c0cb488188695

  • SHA512

    66125f727ec27d3e1da5c87953e46e928b000d564c784b919ba0b558efe4aa080a2f310e729f03b113ab02bc5aea390bb60a6829d3d586fab414b430d40eab04

  • SSDEEP

    12288:1hNsCbYGek5/68cYvmjZxVcsK3SCv6vcuqVuMDCqg0h+:14CF/6V1xNK3SnUrRh+

Malware Config

Extracted

Family

snakekeylogger

Credentials

  • Protocol:
    smtp
  • Host:
    valleycountysar.org
  • Port:
    26
  • Username:
    [email protected]
  • Password:
    fY,FLoadtsiF

Targets

    • Target

      f3c462280fd1964d68c76ff6889bd3c766fa7140c07962dda32c0cb488188695.exe

    • Size

      1.5MB

    • MD5

      ec3fe16c54946213c717a27606f70243

    • SHA1

      d11efe4e0f949ff6b14929cd30ae146c1b4a11c9

    • SHA256

      f3c462280fd1964d68c76ff6889bd3c766fa7140c07962dda32c0cb488188695

    • SHA512

      66125f727ec27d3e1da5c87953e46e928b000d564c784b919ba0b558efe4aa080a2f310e729f03b113ab02bc5aea390bb60a6829d3d586fab414b430d40eab04

    • SSDEEP

      12288:1hNsCbYGek5/68cYvmjZxVcsK3SCv6vcuqVuMDCqg0h+:14CF/6V1xNK3SnUrRh+

    • Snake Keylogger

      Keylogger and Infostealer first seen in November 2020.

    • Snake Keylogger payload

    • Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.

    • Detects executables packed with or use KoiVM

    • Detects executables referencing many email and collaboration clients. Observed in information stealers

    • Detects executables with potential process hoocking

    • Accesses Microsoft Outlook profiles

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Tasks