Analytics Story: Snake Keylogger
Description
SnakeKeylogger is a stealthy malware designed to secretly record keystrokes on infected devices. It operates covertly in the background, capturing sensitive information such as passwords and credit card details. This keylogging threat poses a significant risk to user privacy and security.
Why it matters
SnakeKeylogger, a notorious malware, first emerged in the early 2010s, gaining infamy for its clandestine ability to capture keystrokes on compromised systems. As a stealthy threat, it infiltrates computers silently, recording every keystroke entered by users, including sensitive information like passwords and financial details. Over time, it has evolved to evade detection mechanisms, posing a persistent threat to cybersecurity. Its widespread use in various cybercrime activities underscores its significance as a tool for espionage and data theft. Despite efforts to combat it, SnakeKeylogger continues to lurk in the shadows, perpetuating its malicious activities with devastating consequences.
Detections
Data Sources
| Name | Platform | Sourcetype | Source | 
|---|---|---|---|
| CrowdStrike ProcessRollup2 | N/A | crowdstrike:events:sensor | crowdstrike | 
| Sysmon EventID 1 | XmlWinEventLog | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational | |
| Sysmon EventID 11 | XmlWinEventLog | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational | |
| Sysmon EventID 13 | XmlWinEventLog | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational | |
| Sysmon EventID 15 | XmlWinEventLog | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational | |
| Sysmon EventID 22 | XmlWinEventLog | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational | |
| Sysmon EventID 3 | XmlWinEventLog | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational | |
| Sysmon EventID 5 | XmlWinEventLog | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational | |
| Sysmon EventID 6 | XmlWinEventLog | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational | |
| Windows Event Log Security 4663 | XmlWinEventLog | XmlWinEventLog:Security | |
| Windows Event Log Security 4688 | XmlWinEventLog | XmlWinEventLog:Security | 
References
- https://malpedia.caad.fkie.fraunhofer.de/details/win.404keylogger
- https://www.checkpoint.com/cyber-hub/threat-prevention/what-is-malware/snake-keylogger-malware/
Source: GitHub | Version: 1