Snake Keylogger - Indicators of Compromise

Last updated: 2026-04-18

Malicious URLs (50)

http://91.92.242.3:7777/noesisllc.online/wealt1818/wealtt/nerdfwiqtwqhdgfrwt6fntdwrgonht.js
http://144.172.105.88/img_085906.png
https://blue-oceans.net/ENCRYTPT.Ps1
http://91.92.243.254:7777/91.92.243.254/yugo25/yugo/etkmy6kupbnt14m9hcekv2Ntfi.js
http://158.94.211.63/dealer/ugooilnewsnake.txt
https://bvaco.com/arquivo_20260223164236.txt
https://eishin-kk-co.asia/dev/ENCRYPTEDS.ps1
http://91.92.243.152/dealer/ugooilnewsnake.txt
http://91.92.243.254:7777/91.92.243.254/ugofour/ugox/FfgGD2hgtDEGHwog.js
https://vdfccjpnedujhrzscjtq.supabase.co/storage/v1/object/public/image/v4.msi
https://gelisimtrans.sbs/arquivo_20251215012807.txt
https://ia601702.us.archive.org/9/items/optimized_msi_20251214_2105/optimized_MSI.png
https://s3.wasabisys.com/kiessler/v4.msi
http://91.92.240.104/TAqUmN21pWTFfka.exe
http://91.92.240.104/NLxHm2QLwG0rMot.exe
http://213.209.150.18/ciLCAwjocX86fCG.exe
http://213.209.150.18/WvBmPzgn2CdVlHV.exe
https://estartem.ro/test/image_00102pdf.z
http://66.63.187.170/vqweeer.exe
http://172.245.123.11/new/mexx.exe
http://213.209.150.18/obihh3.exe
http://213.209.150.18/plugmanff2.exe
http://213.209.150.18/xtonyee2.exe
http://213.209.150.18/agodee.exe
http://213.209.150.18/agodee2.exe
http://176.65.142.222/web/build.exe
https://107.175.246.32/xampp/crp/wegotbetterperofmancefromu.txt
http://107.175.246.32/xampp/crp/wegotbetterperofmancefromu.txt
https://firebasestorage.googleapis.com/v0/b/atom2024-84ea3.appspot.com/o/cryptdavidsnake.txt?alt=media&token=3aecbbfa-2376-44c3-80aa-98b578f95ab3
http://213.209.150.18/obicrypttwo.exe
https://3007.filemail.com/api/file/get?filekey=2Ozff1-KPBiqcig7LjWaykQCx0j3xLrqgYBc-C6uAQMsa6JVzXetSezXyTyOPGM&pk_vid=8e2aec8f065dac991745384207c1eb95
https://www.grupodulcemar.pe/GD098765670000800.bat
http://213.209.150.89/nedux.exe
http://176.65.134.217/HSS.exe
https://176.65.134.79/HOST/bagsnake.ps1
http://176.65.134.79/HOST/bagsnake.ps1
http://176.65.134.79/HOST/BAGSNAKE.aska
http://161.248.239.119/ADOLF/Opguyxbxpbd.wav
http://161.248.239.119/ADOLF/Btjfpuda.pdf
http://161.248.239.119/ADOLF/Caaeumx.wav
http://161.248.239.119/ADOLF/Hgdntl.wav
http://161.248.239.119/ADOLF/Srrwube.pdf
http://161.248.239.119/ADOLF/Whdhhn.mp4
http://161.248.239.119/ADOLF/Uhnadt.mp3
http://161.248.239.119/ADOLF/Ormkfe.vdf
http://161.248.239.119/ADOLF/Zrddb.mp3
http://161.248.239.119/ADOLF/Bxmlbneayw.mp3
http://161.248.239.119/ADOLF/Tuvjj.mp4
http://161.248.239.119/ADOLF/Cgucdebkfi.mp4
http://161.248.239.119/ADOLF/Ohuhcttyat.mp4

SHA256 Hashes (4)

8a93756d5216c93984b74f02f27b5c434dc8535492cf5c1d477a742af374435d
79e6b2c3d010500745a6a5a68b89b3453e16eca3ff359477718453301c17b034
88d63b0589f9ccb2caec7f55aedd7137a5b25fe010d9318737c6bfe0777ba7bf
348237414eee4aa489c5177650309e35d10f87e693cba723f49b068665a7acbc

Data Sources

MalwareBazaar (abuse.ch) ThreatFox (abuse.ch) URLhaus (abuse.ch)