General

  • Target

    90c2430071000bba0378a0e404c636df13958a02fa97b4ed19c1230da402da8f.exe

  • Size

    821KB

  • Sample

    240702-b5nxlavhmk

  • MD5

    70081b623e77616333b19e7bc186dd66

  • SHA1

    bc730c03095bbb3fb85773d564774b7fa2a4f2c9

  • SHA256

    90c2430071000bba0378a0e404c636df13958a02fa97b4ed19c1230da402da8f

  • SHA512

    1e34aa19d8299387e54fe9764ab9c5334a0b91049ed31a7333c3b1fbbeb43dd0b449eb7b538a64ae7c2ebc13dc2ed63e2a8a9667e0b472edff2d7dc50f2251d6

  • SSDEEP

    12288:cj2+TW+8LeXbSIrEPrWgeBG9BH79/UXQU4PIFQhIe8Gk1zesgqkkdR9CTt9XQo:cWLe+9oG9poQU47leeYkK9CTt9XQ

Malware Config

Extracted

Family

snakekeylogger

C2

https://api.telegram.org/bot6660014548:AAH8CVYDbJ7NB6q8RItwZQxjcAXTPkK63gc/sendMessage?chat_id=2142414120

Targets

    • Target

      90c2430071000bba0378a0e404c636df13958a02fa97b4ed19c1230da402da8f.exe

    • Size

      821KB

    • MD5

      70081b623e77616333b19e7bc186dd66

    • SHA1

      bc730c03095bbb3fb85773d564774b7fa2a4f2c9

    • SHA256

      90c2430071000bba0378a0e404c636df13958a02fa97b4ed19c1230da402da8f

    • SHA512

      1e34aa19d8299387e54fe9764ab9c5334a0b91049ed31a7333c3b1fbbeb43dd0b449eb7b538a64ae7c2ebc13dc2ed63e2a8a9667e0b472edff2d7dc50f2251d6

    • SSDEEP

      12288:cj2+TW+8LeXbSIrEPrWgeBG9BH79/UXQU4PIFQhIe8Gk1zesgqkkdR9CTt9XQo:cWLe+9oG9poQU47leeYkK9CTt9XQ

    • Snake Keylogger

      Keylogger and Infostealer first seen in November 2020.

    • Snake Keylogger payload

    • Reads user/profile data of local email clients

      Email clients store some user data on disk where infostealers will often target it.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook profiles

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Collection

Data from Local System

2
T1005

Email Collection

1
T1114

Tasks