ExecuteMalware

2021-08-10 Snake Keylogger IOCs

Aug 10th, 2021 (edited)
14,917
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.98 KB | None | 0 0
  1. THREAT ATTRIBUTION: SNAKE KEYLOGGER
  2.  
  3. SUBJECTS OBSERVED
  4. (RFQ) - ATTIQ - 10230-2413_TEMPORARY CONSTRUCTION FACILITIES-TWO WAREHOUSES AND OTHERS - MARJAN INCREMENT PROGRAM TANAJIB GAS PLANT PROJECT - PACKAGES 09 AND 11
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. (RFQ) - ATTIQ - 10230-2413_TEMPORARY CONSTRUCTION FACILITIES.IMG
  10. cc2bcba266b5fa7bccaf7592df6c1837
  11.  
  12. SNAKE KEYLOGGER PAYLOAD FILE HASHES
  13. (RFQ) - ATTIQ - 10230-2413_TEMPORARY CONSTRUCTION FACILITIES.exe
  14. 519f9833658acf4cbfc0139b990f1411
  15.  
  16. STOLEN DATA EXFILTRATED VIA EMAIL TO:
  17. us2.smtp.mailhostbox.com:587
  18.  
  19. EXFILTRATION EMAIL ADDRESSES
  20.  
  21. STRINGS IN MEMORY FOR MSBUILD.EXE
  22. 0x419ba1 (56): https://api.telegram.org/bot
  23. 0x419ce8 (52): http://checkip.dyndns.org/
  24. 0x419dd8 (52): https://freegeoip.app/xml/
  25.  
  26. SUPPORTING EVIDENCE
  27. https://www.virustotal.com/gui/file/5e38e3d0a442ea94f31e31b53084f904ab45661dc50c9abec49c0a016dea64a4/detection
  28.  
Add Comment
Please, Sign In to add comment