PULSE NAME
Inside SnipBot: The Latest RomCom Malware Variant
WHITE RomCom AlienVault 2024-09-24 Modified: 2024-10-24
28
IOCs
MEDIUM VOLUME
A novel version of the RomCom malware family called SnipBot has been discovered, revealing post-infection activity from attackers on victim systems. This new strain employs new tricks and unique code obfuscation methods beyond those seen in previous RomCom versions. The infection chain begins with a downloader disguised as a PDF, followed by multiple stages including DLLs injected into explorer.exe. SnipBot provides backdoor capabilities allowing command execution, file exfiltration, and additional payload downloads. Analysis of attacker post-infection activity shows attempts to gather network information, exfiltrate files, and explore Active Directory. The malware authors appear experienced but not elite, with some minor code flaws present. SnipBot has evolved from earlier RomCom versions, with samples dating back to December 2023.
Indicators of Compromise (2 / 28 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 7f2e4a44445b977ef8917cc0fb79035b 2024-09-24
FileHash-MD5 c0e499402acb6c302228b4a7923d5db6 2024-09-24