PULSE NAME
Inside SnipBot: The Latest RomCom Malware Variant
WHITE RomCom AlienVault 2024-09-24 Modified: 2024-10-24
28
IOCs
MEDIUM VOLUME
A novel version of the RomCom malware family called SnipBot has been discovered, revealing post-infection activity from attackers on victim systems. This new strain employs new tricks and unique code obfuscation methods beyond those seen in previous RomCom versions. The infection chain begins with a downloader disguised as a PDF, followed by multiple stages including DLLs injected into explorer.exe. SnipBot provides backdoor capabilities allowing command execution, file exfiltration, and additional payload downloads. Analysis of attacker post-infection activity shows attempts to gather network information, exfiltrate files, and explore Active Directory. The malware authors appear experienced but not elite, with some minor code flaws present. SnipBot has evolved from earlier RomCom versions, with samples dating back to December 2023.
Indicators of Compromise (28)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 7f2e4a44445b977ef8917cc0fb79035b 2024-09-24
FileHash-MD5 c0e499402acb6c302228b4a7923d5db6 2024-09-24
FileHash-SHA1 983332a5660ec6c28123e745023b41105775ab6f 2024-09-24
FileHash-SHA1 cb3d3a7e39e7cdc8501ae0eff77d02a1c995bc31 2024-09-24
FileHash-SHA256 0be3116a3edc063283f3693591c388eec67801cdd140a90c4270679e01677501 2024-09-24
FileHash-SHA256 1cb4ff70f69c988196052eaacf438b1d453bbfb08392e1db3df97c82ed35c154 2024-09-24
FileHash-SHA256 2c327087b063e89c376fd84d48af7b855e686936765876da2433485d496cb3a4 2024-09-24
FileHash-SHA256 5390ba094cf556f9d7bbb00f90c9ca9e04044847c3293d6e468cb0aaeb688129 2024-09-24
FileHash-SHA256 57e59b156a3ff2a3333075baef684f49c63069d296b3b036ced9ed781fd42312 2024-09-24
FileHash-SHA256 5b30a5b71ef795e07c91b7a43b3c1113894a82ddffc212a2fa71eebc078f5118 2024-09-24
FileHash-SHA256 5c71601717bed14da74980ad554ad35d751691b2510653223c699e1f006195b8 2024-09-24
FileHash-SHA256 60d96087c35dadca805b9f0ad1e53b414bcd3341d25d36e0190f1b2bbfd66315 2024-09-24
FileHash-SHA256 92c8b63b2dd31cf3ac6512f0da60dabd0ce179023ab68b8838e7dc16ef7e363d 2024-09-24
FileHash-SHA256 a2f2e88a5e2a3d81f4b130a2f93fb60b3de34550a7332895a084099d99a3d436 2024-09-24
FileHash-SHA256 b9677c50b20a1ed951962edcb593cce5f1ed9c742bc7bff827a6fc420202b045 2024-09-24
FileHash-SHA256 cfb1e3cc05d575b86db6c85267a52d8f1e6785b106797319a72dd6d19b4dc317 2024-09-24
FileHash-SHA256 e5812860a92edca97a2a04a3151d1247c066ed29ae6bbcf327d713fbad7e79e8 2024-09-24
FileHash-SHA256 f74ebf0506dc3aebc9ba6ca1e7460d9d84543d7dadb5e9912b86b843e8a5b671 2024-09-24
domain cloudcreative.digital 2024-09-24
domain dns-msn.com 2024-09-24
domain drvmcprotect.com 2024-09-24
domain fastshare.click 2024-09-24
domain ilogicflow.com 2024-09-24
domain mcprotect.cloud 2024-09-24
domain publicshare.link 2024-09-24
domain sitepanel.top 2024-09-24
hostname 1drv.fileshare.direct 2024-09-24
hostname adobe.cloudcreative.digital 2024-09-24