PULSE NAME
Inside SnipBot: The Latest RomCom Malware Variant
WHITE RomCom AlienVault 2024-09-24 Modified: 2024-10-24
28
IOCs
MEDIUM VOLUME
A novel version of the RomCom malware family called SnipBot has been discovered, revealing post-infection activity from attackers on victim systems. This new strain employs new tricks and unique code obfuscation methods beyond those seen in previous RomCom versions. The infection chain begins with a downloader disguised as a PDF, followed by multiple stages including DLLs injected into explorer.exe. SnipBot provides backdoor capabilities allowing command execution, file exfiltration, and additional payload downloads. Analysis of attacker post-infection activity shows attempts to gather network information, exfiltrate files, and explore Active Directory. The malware authors appear experienced but not elite, with some minor code flaws present. SnipBot has evolved from earlier RomCom versions, with samples dating back to December 2023.
Indicators of Compromise (2 / 28 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 983332a5660ec6c28123e745023b41105775ab6f 2024-09-24
FileHash-SHA1 cb3d3a7e39e7cdc8501ae0eff77d02a1c995bc31 2024-09-24