General

  • Target

    bed407ef928f705eb4662c4acdd0c422b059e8486165f3e0fb27c700b2da1a22.exe

  • Size

    668KB

  • Sample

    240703-pl6vysvamf

  • MD5

    35548be9c773b276bbe493d9e143a0c1

  • SHA1

    0392f6ec9fceb2a6bfd19cd7aebe0edc92384fbc

  • SHA256

    bed407ef928f705eb4662c4acdd0c422b059e8486165f3e0fb27c700b2da1a22

  • SHA512

    69cd9017f7f8ca26233e42c4e81d9119c6910a0b9e5161d58532e14549cfd7dcb6d03f33271d08a66837b0e854b452c3406803a3e5b5734ea503a4cce127c74c

  • SSDEEP

    12288:wpUeoUEz8a0qCpxN5BZMrtuj1+Q/AYH7dUtzCWuw9SXwFxw:YOz8wQxN56KYQ/3H7dUt39SUw

Malware Config

Extracted

Family

snakekeylogger

Credentials
C2

https://scratchdreams.tk

Targets

    • Target

      bed407ef928f705eb4662c4acdd0c422b059e8486165f3e0fb27c700b2da1a22.exe

    • Size

      668KB

    • MD5

      35548be9c773b276bbe493d9e143a0c1

    • SHA1

      0392f6ec9fceb2a6bfd19cd7aebe0edc92384fbc

    • SHA256

      bed407ef928f705eb4662c4acdd0c422b059e8486165f3e0fb27c700b2da1a22

    • SHA512

      69cd9017f7f8ca26233e42c4e81d9119c6910a0b9e5161d58532e14549cfd7dcb6d03f33271d08a66837b0e854b452c3406803a3e5b5734ea503a4cce127c74c

    • SSDEEP

      12288:wpUeoUEz8a0qCpxN5BZMrtuj1+Q/AYH7dUtzCWuw9SXwFxw:YOz8wQxN56KYQ/3H7dUt39SUw

    • Snake Keylogger

      Keylogger and Infostealer first seen in November 2020.

    • Snake Keylogger payload

    • Reads user/profile data of local email clients

      Email clients store some user data on disk where infostealers will often target it.

    • Reads user/profile data of web browsers

      Infostealers often target stored browser data, which can include saved credentials etc.

    • Accesses Microsoft Outlook profiles

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix ATT&CK v13

Credential Access

Unsecured Credentials

2
T1552

Credentials In Files

2
T1552.001

Collection

Data from Local System

2
T1005

Email Collection

1
T1114

Tasks