General

  • Target

    PETUNJUK-PENGISIAN DAN PENGIRIMAN KONFIRMASI EDITED.xlsx.scr.exe

  • Size

    610KB

  • Sample

    240702-ka911sxgnm

  • MD5

    fe67d87f3efefadb38a76aca77820504

  • SHA1

    08c9f9f3c9be5b3fb9fbe6dfc3b6875323c3a4ad

  • SHA256

    b740d4c07f1bfd42085caf8c5df442634f5415bcaffe2050c52a0f3379a5f03f

  • SHA512

    b19a43da549d0234b1aedc718eef6781d9f5fe7d06eb41fdb0a19b9d35c7627f660b9c956e2411fe94fe5d97ab7c273ef83ecc168c1ae1d28d683433e14414da

  • SSDEEP

    12288:xOaEg1tQwjJ3pOpHY2/KCnmJMh9NbMAs0Dmf5a93CjUlNqph:xpPtQwj7OhmJMh7b1siSKsU3y

Malware Config

Extracted

Family

snakekeylogger

C2

https://api.telegram.org/bot7049924735:AAGvjcq8A7Onlbh1XDN_9YUW9tENxnyOWZ4/sendMessage?chat_id=5144477649

Targets

    • Target

      PETUNJUK-PENGISIAN DAN PENGIRIMAN KONFIRMASI EDITED.xlsx.scr.exe

    • Size

      610KB

    • MD5

      fe67d87f3efefadb38a76aca77820504

    • SHA1

      08c9f9f3c9be5b3fb9fbe6dfc3b6875323c3a4ad

    • SHA256

      b740d4c07f1bfd42085caf8c5df442634f5415bcaffe2050c52a0f3379a5f03f

    • SHA512

      b19a43da549d0234b1aedc718eef6781d9f5fe7d06eb41fdb0a19b9d35c7627f660b9c956e2411fe94fe5d97ab7c273ef83ecc168c1ae1d28d683433e14414da

    • SSDEEP

      12288:xOaEg1tQwjJ3pOpHY2/KCnmJMh9NbMAs0Dmf5a93CjUlNqph:xpPtQwj7OhmJMh7b1siSKsU3y

    • Snake Keylogger

      Keylogger and Infostealer first seen in November 2020.

    • Snake Keylogger payload

    • Reads user/profile data of local email clients

      Email clients store some user data on disk where infostealers will often target it.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook profiles

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Collection

Data from Local System

2
T1005

Email Collection

1
T1114

Tasks