Advertisement
ExecuteMalware

2021-08-12 Snake Keylogger IOCs

Aug 12th, 2021
11,251
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.88 KB | None | 0 0
  1. THREAT IDENTIFICATION: SNAKE KEYLOGGER
  2.  
  3. SUBJECTS OBSERVED
  4. RFQ/ITB PROVISION TO SUPPLY AND DELIVERY FOR INSTRUMENT ITEMS, SPRING HANGER, INSTRUMENT BULKS AND PIPING BULKS FOR WD-A05/A17 AT WEST DESARU (WSS)_Rev 1 (PQR-7943-377) - PIPE FITTING REV 01
  5.  
  6. SENDERS OBSERVED
  7. tendersecretaryhuc@pbjv.com.my
  8.  
  9. MALDOC FILE HASHES
  10. BE-IZ-Q-1278-21 - COMMERCIAL.IMG
  11. 3a348dae64cf2f9acf78a43031a72cf2
  12.  
  13. BE-IZ-Q-1278-21 - TECHNICAL.IMG
  14. 3b62ecfc2e494f28cddc9cd39e7ddf3f
  15.  
  16. SNAKE KEYLOGGER PAYLOAD FILE HASHES
  17. BE-IZ-Q-1278-21 - COMMERCIAL.exe
  18. a9a010a85cb57506786a428c95b7a982
  19.  
  20. BE-IZ-Q-1278-21 - TECHNICAL.exe
  21. a9a010a85cb57506786a428c95b7a982
  22.  
  23. SNAKE KEYLOGGER C2
  24. Not observed
  25.  
  26. EXFILTRATION EMAIL ADDRESSES
  27. From strings in memory:
  28. worshippersnake@fireacoustics.com
  29.  
  30. SUPPORTING EVIDENCE
  31. https://www.virustotal.com/gui/file/50e5974917f1a96891cc54b4eada0c5b3f955df6d6dbeb4772ff05e2f203ee9d/detection
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement