MALWARE-OTHER --
MALWARE-OTHER Win.Injector.Generic download attempt
This rule alerts on known process injectors associated with the Win.Keylogger.Snake malware family. This file is responsible for injecting the Snake keylogger into memory and establishing persistence. The indicated endpoint is likely compromised with an initial malicious downloader file.
This rule alerts on known process injectors associated with the Win.Keylogger.Snake malware family.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Execution::User Execution::Malicious File
MITRE::ATT&CK Framework::Enterprise::Command and Control::Application Layer Protocol
None
No information provided
None