MALWARE-OTHER --
MALWARE-OTHER Win.Loader.Generic download attempt
This rule alerts on malicious files known to distribute the Win.Keylogger.Snake malware family. Snake is a credential stealer and keylogging application that exfiltrates via SMTP, Telegram, and FTP. The indicated endpoint is likely compromised with a malicious Microsoft Office file.
This rule alerts on malicious files known to distribute the Win.Keylogger.Snake malware family.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Execution::User Execution::Malicious File
MITRE::ATT&CK Framework::Enterprise::Command and Control::Application Layer Protocol
None
No information provided
None