Analysis of Nova: A Snake Keylogger Fork - ANY.RUN's Cybersecurity Blog
Tags
Common Information
Type | Value |
---|---|
UUID | f98eca06-ca1b-4693-8240-7d5a77fc1f31 |
Fingerprint | 2e147935b9f6ae89 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Dec. 11, 2024, 10:31 a.m. |
Added to db | Dec. 11, 2024, 12:04 p.m. |
Last updated | Dec. 18, 2024, 2:14 p.m. |
Headline | Analysis of Nova: A Snake Keylogger Fork |
Title | Analysis of Nova: A Snake Keylogger Fork - ANY.RUN's Cybersecurity Blog |
Detected Hints/Tags/Attributes | 77/3/13 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://any.run/cybersecurity-blog/nova-keylogger-malware-analysis/ |
URL Provider
Details | Provider | Source level domain |
---|---|---|
Details | any.run | any.run |
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 14 | ✔ | ANY.RUN's Cybersecurity Blog | https://any.run/cybersecurity-blog/feed/ | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 1130 | any.run |
|
Details | Domain | 49 | checkip.dyndns.org |
|
Details | Domain | 3 | reallyfreegeoip.org |
|
Details | Domain | 151 | api.telegram.org |
|
Details | Domain | 60 | vb.net |
|
Details | File | 2 | c:\users\admin\appdata\local\temp\fondaco afb1dae7a6f2396c3d136e60144b02dd03c59ab10704918185d12ef8c6d7ec93 c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\neophobia.vbs |
|
Details | md5 | 15 | 9375CFF0413111d3B88A00104B2A6676 |
|
Details | sha256 | 3 | 68f5247bd24e8d5d121902a2701448fe135e696f8f65f29e9115923c8efebee4 |
|
Details | sha256 | 3 | afb1dae7a6f2396c3d136e60144b02dd03c59ab10704918185d12ef8c6d7ec93 |
|
Details | sha256 | 3 | 66dbb9c8deadea9f848b1b55405738d8a65a733c804f1444533607c20584643e |
|
Details | Url | 6 | http://checkip.dyndns.org |
|
Details | Url | 3 | https://reallyfreegeoip.org/xml |
|
Details | Url | 2 | https://api.telegram.org/bot7479124552 |