Explore tweets tagged as #SnakeKeyLogger
@Unit42_Intel
Unit 42
10 months
2024-09-16 (Monday): Saw an #infostealer calling itself "VIP Recovery" which some might call #VIPKeyLogger. Further investigation indicates it's actually #SnakeKeyLogger. Indicators and more info available at #TimelyThreatIntel #Unit42ThreatIntel
Tweet media one
Tweet media two
Tweet media three
Tweet media four
2
36
99
@James_inthe_box
James
25 days
Been seeing a spate of side-loaded dll's. usually #snakekeylogger as of late:.
Tweet media one
2
5
46
@Gi7w0rm
Gi7w0rm
2 years
Malware infra spotted: . Staging Server: payorderreceipt[.]info.#XWorm and #Snakekeylogger. XWorm C2s:.xwormfresh[.]duckdns[.]org:7002.homesafe1000[.]duckdns[.]org:7000.Pattern aligns with #DDGroup. #SnakeKeylogger . ftp://ftp.product-secured[.]com/. Actively changing.
Tweet media one
Tweet media two
3
27
88
@Gi7w0rm
Gi7w0rm
1 year
#SnakeKeylogger using #Telegram #C2.1652 unique Victim IPs identified,.Actor Telegram Information:.id: 5262627523.first_name: 30315.last_name: New Hope. Bot Info: .id: 6291795537.first_name: Aku1.username: Aku2bababot
Tweet media one
0
9
46
@Jane_0sint
Jane
5 months
GuLoader Payloads:.AgentTesla - SnakeKeylogger - Remcos - HTTP Headers:
Tweet media one
0
9
22
@ryodan0x
xRY0D4N
2 years
#snakekeylogger sample > executable in resource > .NET obfuscated executable .deobfuscate with de4dot.malware decrypt API key and chat Id of a telegram bot and communicate with it. yara rule and decryption script:
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
14
48
@bomccss
bom
1 month
日本語のマルウェア付きメールが確認されています。.■日時.2025/06/27.■件名.注文書([会社名省略]).■添付ファイル.製品お見積り依頼.zip -> .exe.情報窃取マルウェア #VIPKeyLogger ( #SnakeKeyLogger )
Tweet media one
0
9
19
@tccontre18
Br3akp0int
1 year
happy to share our latest #STRT Blog on #SnakeKeylogger! This includes the intriguing loader variant, Malware Analysis, TTPs we've extracted and a comprehensive list of our developed detections! 😊 #splunk #RE #int3 #blueteam #detectionengineering .
Tweet media one
Tweet media two
Tweet media three
0
29
68
@nextronresearch
Nextron Research ⚡️
4 months
Ever wondered what malware really looks like - literally? A dropper did the honors, pixel by pixel. This technique has been spotted in many types of malware stealers, such as SnakeKeylogger, VIPKeyLogger, MassLogger. Its dropper hides the second-stage payload in a bitmap
Tweet media one
Tweet media two
0
14
49
@vxunderground
vx-underground
11 months
Updates:. Families: .- AgentTesla.- AsyncRAT.- CryptBot.- DarkComet.- DCRat.- FormBook.- GuLoader.- Latrodectus.- LummaStealer.- Mirai.- OxyPumper.- RedLine.- Remcos.- RevengeRAT.- SnakeKeylogger.- STRRAT.- TrickBot.- XMRig.- XWorm.- ZharkRAT. Papers:.- 2012-10-02 - Blackhole
Tweet media one
5
13
116
@1ZRR4H
Germán Fernández
2 years
⚠️ MALSPAM en progreso, dirigido a empresas en Colombia 🇨🇴 y suplantando a @UNALOficial (Universidad Nacional de Colombia). Remote template: .http://104.168.32.152/O__O.DOC.#SnakeKeylogger + #opendir. http://104.168.32.152/8787/.
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
18
39
@anyrun_app
ANY.RUN
4 days
🚨 Control-Flow Flattening Obfuscated #JavaScript Drops #SnakeKeylogger. The #malware uses layered obfuscation to hide execution logic and evade traditional detection. ⚠️ Our data shows banking is the most affected sector among our users, nearly matching all the other industries
Tweet media one
0
7
21
@banthisguy9349
Fox_threatintel
5 months
8af777d0f92cef2d9040a634527c3753669235589c23129f09855ad0ebe10c6f. GoogleUpdateSetup.exe. Guys. 'googleupdatesetup.exe' has been spread by a actor that uses Snakekeylogger. I suspect this certificate to be abused. Tag Cert Abuse Specialist into this post please.
Tweet media one
5
16
71
@osipov_ar
Arnold Osipov
2 years
#Snakekeylogger - .eml -> .onepkg -> .one -> .vbs -> .ps1 -> .exe. Displays a lure PDF downloaded from #opendir http://37.139.128[.]83/golden.pdf. hash:ab7cf645055bcfc176ce50c7b2702231ac2070185b0e173551c18232ad596d7d
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
6
23
@ShanHolo
Shanholo
9 months
🚨#Opendir #Malware🚨. hxxp://172.245.123.45/292/. ⚠️#Snakekeylogger #Stealer.☣️wlanext.exe➡️dab02bda6040baa9dd55a267c40ef2ed.📡:hxxps://api.telegram.org/bot8129252196:AAFb_vUYwennKVolbwpXf3vnDfT_yhozHns/sendMessage?chat_id=7004340450
Tweet media one
0
1
4
@anyrun_app
ANY.RUN
7 months
🚨 #PureCrypter is a stealthy loader malware actively distributing threats like #AgentTesla, #RedLine stealer, and #SnakeKeylogger. It disguises malicious files as videos or documents. Learn more and gather #IOCs & samples.👉
Tweet media one
0
13
44
@bomccss
bom
1 month
日本語のマルウェア付きメールが確認されています。. ■日時.2025/06/20.■件名.見積依頼. ■添付ファイル.見積依頼.zip-> .exe.情��窃取マルウェア #VIPkeylogger ( #SnakeKeyLogger )
Tweet media one
0
7
15
@bomccss
bom
4 months
日本語のマルウェア付きメールが確認されています。. ■日時.2025/03/18.■件名.見積依頼 関電プラント向け. ■添付ファイル.見積依頼 関電プラント向け_pdf.r00 -> .exe.情報窃取マルウェア #SnakeKeyLogger (#vipkeylogger)
Tweet media one
2
23
54
@AndreaDraghetti
Andrea (Drego) Draghetti 👨🏻‍💻 🎣
1 year
⚠️ Attenzione! ⚠️ . Un #malware si sta diffondendo tramite un'e-mail con oggetto "ORDINE DI ACQUISTO N. 741 DEL 22.07.2024". Non aprite l'allegato! . 🛑 Questo malware invia i dati delle vittime via Telegram. IoC:.- 9d4d51bc544f2b09082fa76d8652eacb. #mwitaly #SnakeKeylogger
Tweet media one
2
10
18
@bomccss
bom
4 months
日本語のマルウェア付きメールが確認されています。. ■日時.2025/03/31.■件名.見積依頼 関電プラント向け-RFQ0610922.■添付ファイル.RFQ0610922. ケーブル注文。 AMP282104-2 メス 2P(TMB) 500個.7z -> .exe.情報窃取マルウェア #SnakeKeyLogger
Tweet media one
0
20
54