Snake Keylogger - Indicators of Compromise

Last updated: 2026-05-10

Malicious URLs (50)

http://91.92.242.3:7777/noesisllc.online/wealt1818/wealtt/nerdfwiqtwqhdgfrwt6fntdwrgonht.js
http://144.172.105.88/img_085906.png
https://blue-oceans.net/ENCRYTPT.Ps1
http://91.92.243.254:7777/91.92.243.254/yugo25/yugo/etkmy6kupbnt14m9hcekv2Ntfi.js
http://158.94.211.63/dealer/ugooilnewsnake.txt
https://bvaco.com/arquivo_20260223164236.txt
https://eishin-kk-co.asia/dev/ENCRYPTEDS.ps1
http://91.92.243.152/dealer/ugooilnewsnake.txt
http://91.92.243.254:7777/91.92.243.254/ugofour/ugox/FfgGD2hgtDEGHwog.js
https://vdfccjpnedujhrzscjtq.supabase.co/storage/v1/object/public/image/v4.msi
https://gelisimtrans.sbs/arquivo_20251215012807.txt
https://ia601702.us.archive.org/9/items/optimized_msi_20251214_2105/optimized_MSI.png
https://s3.wasabisys.com/kiessler/v4.msi
http://91.92.240.104/TAqUmN21pWTFfka.exe
http://91.92.240.104/NLxHm2QLwG0rMot.exe
http://213.209.150.18/ciLCAwjocX86fCG.exe
http://213.209.150.18/WvBmPzgn2CdVlHV.exe
https://estartem.ro/test/image_00102pdf.z
http://66.63.187.170/vqweeer.exe
http://172.245.123.11/new/mexx.exe
http://213.209.150.18/obihh3.exe
http://213.209.150.18/plugmanff2.exe
http://213.209.150.18/xtonyee2.exe
http://213.209.150.18/agodee.exe
http://213.209.150.18/agodee2.exe
http://176.65.142.222/web/build.exe
https://107.175.246.32/xampp/crp/wegotbetterperofmancefromu.txt
http://107.175.246.32/xampp/crp/wegotbetterperofmancefromu.txt
https://firebasestorage.googleapis.com/v0/b/atom2024-84ea3.appspot.com/o/cryptdavidsnake.txt?alt=media&token=3aecbbfa-2376-44c3-80aa-98b578f95ab3
http://213.209.150.18/obicrypttwo.exe
https://3007.filemail.com/api/file/get?filekey=2Ozff1-KPBiqcig7LjWaykQCx0j3xLrqgYBc-C6uAQMsa6JVzXetSezXyTyOPGM&pk_vid=8e2aec8f065dac991745384207c1eb95
https://www.grupodulcemar.pe/GD098765670000800.bat
http://213.209.150.89/nedux.exe
http://176.65.134.217/HSS.exe
https://176.65.134.79/HOST/bagsnake.ps1
http://176.65.134.79/HOST/bagsnake.ps1
http://176.65.134.79/HOST/BAGSNAKE.aska
http://161.248.239.119/ADOLF/Opguyxbxpbd.wav
http://161.248.239.119/ADOLF/Btjfpuda.pdf
http://161.248.239.119/ADOLF/Caaeumx.wav
http://161.248.239.119/ADOLF/Hgdntl.wav
http://161.248.239.119/ADOLF/Srrwube.pdf
http://161.248.239.119/ADOLF/Whdhhn.mp4
http://161.248.239.119/ADOLF/Uhnadt.mp3
http://161.248.239.119/ADOLF/Ormkfe.vdf
http://161.248.239.119/ADOLF/Zrddb.mp3
http://161.248.239.119/ADOLF/Bxmlbneayw.mp3
http://161.248.239.119/ADOLF/Tuvjj.mp4
http://161.248.239.119/ADOLF/Cgucdebkfi.mp4
http://161.248.239.119/ADOLF/Ohuhcttyat.mp4

SHA256 Hashes (27)

6f156b9664a0f933075436c8f3a123635005ed059fc88bf5e053d76cd619f1db
fa8bed9286024914510fafdfc2eb70dcfe8999f8f768e19b7fa98d64d8035a76
a0ae3275aed9137a9a36c7dc0e8ab950281ae8bb26573ad7233be06f2ad5ea6d
6e2c7b90b921e3a70b16d29b9dde6fc06d0798849d09cd1420c99a76abca6908
1741fe897473e7b6f70d5fe19918ea3e41deb9babe12dc8b0a041c8ac71c767c
28e6160a0c931d0731823e752dc32659a51dc2b9abd3d75b9000366d3e2070a4
475134fd1bd6af31bbb8f76aaa1db2aa9eeb9bde747de1e8d04b399707f063f2
70b8e9cd74923561cdb965439c5b4c150c7c6cdb4f5fe6e91a8e87f44aa6ca88
be06aab9e611d76a76f37a89cdef1df2ea59e591ff2654c8c679bfed0f7710bb
7d90636465939a1a5782cc67053d0bed02988df0aca5f9b39a36d2799b3f2bf6
a4e9bbd5382dd359ead97183d42c9e19171e24ab8daec58096e67a19cdf80db8
99f0cef71d37176ef7b40badd2beb4a4d75fd4501188c9362a5c17479c6d6f56
31ee885db60cd91170f384856bcdda68ef7fd3014149d4905eefcccd6f0ee906
ce6fb377a643909b666592bbe920ea4ef9d7abc50fbe14f8ecbbc3cd059bebc4
bbe37ae6c1d6534ddeb3b9f28d59150b7e43f82a3fa6259152581e5fc0d3e3bc
84ae4d3d39fa01c512659e6aaf5546f3b767d59a6dfe1fd7821c6da92c7743e9
132fbaa338bf578298d0b8abb9439896b97edae9840c5ba93d9b8475a4a6cd76
419b24867a2cdba9a8587f577baf832b04ac4aa07c706afb97b50d98b1868644
b9552a61439efa4fd9680202397d790306d88d393b73a6be6171403cdd35a0dd
2525aba3aa0c6896fc70910540eeb06f0df4b23105e5ee521bce057d6e41c8c6
83bbbf8a6bf9ea4459e8b1be75a8ca18f3aa6878373c1dbf8202be56ba585e6c
ec628a344ca23797543cc30fb41ad4e016e3c7c2c9803d802e961adadf407d5e
671839c24c52d9e13182fc4ff5e6b2d97bd62c94dde47b17e35ace78d8de22e1
8a93756d5216c93984b74f02f27b5c434dc8535492cf5c1d477a742af374435d
79e6b2c3d010500745a6a5a68b89b3453e16eca3ff359477718453301c17b034
88d63b0589f9ccb2caec7f55aedd7137a5b25fe010d9318737c6bfe0777ba7bf
348237414eee4aa489c5177650309e35d10f87e693cba723f49b068665a7acbc

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)