Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

WhiteSnake

81
Global rank
91 infographic chevron month
Month rank
127 infographic chevron week
Week rank
0
IOCs

WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.

Stealer
Type
Unknown
Origin
1 September, 2023
First seen
26 August, 2026
Last seen

How to analyze WhiteSnake with ANY.RUN

Type
Unknown
Origin
1 September, 2023
First seen
26 August, 2026
Last seen

IOCs

IP addresses
103.54.153.49
63.40.139.116
202.95.11.181
185.199.110.133
204.242.111.216
140.82.121.4
76.181.127.0
64.89.163.22
88.178.85.213
62.50.124.173
73.178.125.121
178.198.226.213
196.251.107.186
172.245.95.62
85.137.245.141
161.171.54.201
187.208.110.213
157.173.29.19
85.186.8.75
122.42.218.141
Hashes
92804faaab2175dc501d73e814663058c78c0a042675a8937266357bcfb96c50
d3acd72f585872f36d7329faf6146dc2d71c3cbcbd58d94e36da285738adaa68
e728f79439e07df1afbcf03e8788fa0b8b08cf459db31fc8568bc511bf799537
7f0121322785c107bfdfe343e49f06c604c719baff849d07b6e099675d173961
aac73b3148f6d1d7111dbca32099f68d26c644c6813ae1e4f05f6579aa2663fe
5822c2222c4a4121a1667c7d483ff8b91e489a4c5e881c75a4354712bfe6f435
26b4699a7b9eeb16e76305d843d4ab05e94d43f3201436927e13b3ebafa90739
15ffbb8d382cd2ff7b0bd4c87a7c0bffd1541c2fe86865af445123bc0b770d13
14dec7d1c20fc426ad5463d1b658f87a22f7e576ba4a08905caf399551813a72
2d79af8e1ff3465703e1dc73d3ef2182fd269ea2609c8afabdf1b80693405c1d
d30d7676a3b4c91b77d403f81748ebf6b8824749db5f860e114a8a204bca5b8f
96425ae53a5517b9f47e30f6b41fdc883831039e1faba02fe28b2d5f3efcdc29
4ae7d63ec497143c2acde1ba79f1d9eed80086a420b6f0a07b1e2917da0a6c74
b5fc4fd50e4ba69f0c8c8e5c402813c107c605cab659960ac31b3c8356c4e0ec
db0c7e3029fb2a048e7a3e74c9cbf3e8bcec06288b5eafac5aae678d8663bffc
3e59379f585ebf0becb6b4e06d0fbbf806de28a4bb256e837b4555f1b4245571
fc103a323d70caaac475ae1cfcacfd8eec4c6b1e130005c4793f2013b4b019f8
031ed0378f819926d7b5b2c6c9367a0fb1cbae40e1a3959e2652fe30a47d52f2
27f13c4829994b214bb1a26eef474da67c521fd429536cb8421ba2f7c3e02b5f
45791627ae8e67e6b616117cf21f04da381722faf08d07c0c25e0f28c9b8f82b
Domains
fkoqonr2vgbsw7qu.public.blob.vercel-storage.com
dl.natgo.cn
www.benshamcentre.co.uk
1h.vuregyy1.ru
tmcksa.com
cat.dashabi.in
c3436037.salamanderprocessing.pages.dev
vizyonuniversitesi.com.tr
hnjgdl.geps.glodon.com
palharesinformatica.com.br
www.astenterprises.com.pk
imagefiles-backup.oss-ap-southeast-7.aliyuncs.com
practisingcertificateprotection.com
konsor.ru
dcwblida.dz
www.hwgeneralins.com
www.saf-oil.ru
99194034-96-20180108171507.webstarterz.com
www.microsoft.com
local-update.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://45.13.186.37/crypt/21-32/qw1.exe
http://196.251.107.186/clpr11.exe
http://196.251.107.186/asemkiic.exe
http://193.104.58.65/binyu.exe
http://91.92.242.236/files-129312398/files/file_b41995cf38e90365.exe
http://91.92.242.236/files-129312398/files/file_6bbb893ae4adfb7c.exe
http://217.60.195.219/boss/boss.bat
http://196.251.107.186/clpmem.exe
http://85.203.4.64/notepad.exe
http://193.221.200.26:5001/odens.exe
http://217.60.195.219/ty/s.bat
http://85.203.4.64/client.exe
http://91.92.242.236/files-129312398/files/file_a91ac6d4a7389993.exe
http://91.92.242.236/files-129312398/files/file_21aeb275da3bb00b.exe
http://91.92.242.236/files-129312398/files/file_44ef7cc8421220d0.exe
http://196.251.107.186/uniform_4.44_install.exe
http://196.251.107.186/clp4.exe
http://196.251.107.186/2.7.exe
http://178.16.54.109/getit.exe
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2913
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 8173
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10993
comments 0

What is WhiteSnake malware?

WhiteSnake is a stealer malware whose activity was first observed in early 2023. This malware is designed to infiltrate computer systems and exfiltrate a variety of sensitive information to the attacker’s servers, including saved passwords, autofill information, and browsing history.

WhiteSnake operates as a malware-as-a-service (MaaS), a business model where the developers offer the malware to other cybercriminals for a fee. In the case of WhiteSnake, the developers provide a subscription service for several hundred dollars.

According to the threat intelligence researcher @RussianPanda9xx, the malware’s notable feature is the support of different payload formats like BAT, MSI, SCR, etc.

The distribution and sale of WhiteSnake primarily occurs on DarkWeb forums and Telegram. The availability of the malware contributes to its spread and increases its potential impact.

WhiteSnake has been distributed through various vectors like phishing campaigns, where unsuspecting users are tricked into downloading the malware, and even through open-source repositories.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

WhiteSnake malware execution process

Let’s upload a sample of WhiteSnake to the ANY.RUN sandbox.

WhiteSnake analysis in ANY.RUN WhiteSnake analysis in ANY.RUN sandbox

WhiteSnake first performs anti-VM checks to detect if it is running in a virtual environment or sandbox. It does this by querying the Windows Management Instrumentation (WMI) to retrieve the "Manufacturer" and "Model" properties of the system. It then checks if any of these properties contain strings associated with virtual machines or sandboxes, such as "virtual," "vmware," "virtualbox," etc. If any of these strings are detected, the malware will exit to avoid analysis.

WhiteSnake process graph in ANY.RUN WhiteSnake process graph demonstrated by ANY.RUN sandbox

The malware in our task performs system discovery and uses the command line to display information about available Wi-Fi networks, including SSID, BSSID, and signal strength. It also checks if a mutex (a synchronization object) is already present to prevent multiple instances of the malware from running simultaneously. In our sample, the mutex is "lcy9igxycx."

Then WhiteSnake proceeds to gather sensitive information from the infected system. This includes:

  • Browsing data (cookies, autofill, login data, history, etc.) from various web browsers like Chrome, Firefox, Edge, etc.
  • Cryptocurrency wallet data from popular wallets like Ledger, Atomic, Wasabi, Binance, etc.
  • Cryptocurrency browser extension data from extensions like MetaMask, Ronin, Binance Chain, etc.
  • Other system information like username, computer name, etc.

The gathered information is then encrypted and uploaded to one of the attacker-controlled servers specified in the malware's configuration.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

WhiteSnake stealer technical details

Let’s sum up what the WhiteSnake stealer is capable of. Thanks to its remote command execution functionality. attackers can remotely control the infected system and perform various malicious activities that include:

  • Pulling data from browsers, including Chrome and Firefox, and File Transfer Protocol (FTP) clients.
  • Taking screenshots of the infected system, providing attackers with visual information about the user's activities.
  • Recording audio using the machine's microphone.
  • Taking shots using the web camera.
  • Capturing victims’ keystrokes, which lets attackers discover their login credentials, credit card numbers, and other sensitive information entered by the user.
  • Stealing dozens of crypto wallets, including popular extensions like MetaMask and Phantom, and desktop wallets like Exodus.

One of the key features of this malware is its use of mutex to avoid running on systems that have already been infected. This helps prevent detection and conflict with other instances of the malware.

It is also designed to avoid analysis in a sandbox or virtual machine. The malware includes anti-VM functionality that allows it to detect when it is running in a virtual environment and stop its operation.

WhiteSnake can maintain persistence on the infected system. It automatically runs via a scheduled task, ensuring that it remains active even after the system is restarted.

WhiteSnake malware distribution methods

As mentioned, WhiteSnake is distributed through various methods. However, as with most stealers, including Stealc and Amadey, phishing emails with malicious attachments and links constitute the most widespread vector of attack. In one campaign, criminals leveraged fake documents masquerading as official correspondence from a government agency.

In another attack, threat actors attempted to spread the WhiteSnake stealer through the open-source Python Package Index repository. Attackers uploaded malicious code hoping it would be downloaded and executed by unsuspecting users.

Given that WhiteSnake is a MaaS, available for purchase to various criminals, it is likely that new methods of distributing this threat will be used by criminals in the future.

Conclusion

WhiteSnake is a relatively new but serious cybersecurity threat for organizations worldwide. To prevent infection, it's important to have good security measures in place. One important part of a strong security plan is using a malware analysis sandbox.

ANY.RUN’s interactive sandbox has many features that make analyzing malware easier and faster. It can:

  • Identify threats in files and URLs in less than 40 seconds.
  • Let you interact with samples and the system, just like on a regular computer.
  • Give you customizable Windows and Linux virtual machines to fit your needs.
  • Create detailed reports that explain the threats that were found.
  • Show all activities related to the network, registry, files, and processes.

Create your FREE ANY.RUN account today!

HAVE A LOOK AT

SolarisLoader screenshot
SolarisLoader
solaris
SolarisLoader is a malware loader designed to neutralize security infrastructure before deploying high-risk secondary payloads. It utilizes a "Bring Your Own Vulnerable Driver" technique to gain kernel-level access and terminate antivirus processes. To remain undetected, the malware patches internal Windows monitoring interfaces and isolates the machine from security updates. Finally, it establishes a resilient three-layer persistence mechanism involving scheduled tasks, registry backups, and a watchdog component.
Read More
Orcus RAT screenshot
Orcus RAT
orcus rat trojan
Orcus is a modular Remote Access Trojan with some unusual functions. This RAT enables attackers to create plugins using a custom development library and offers a robust core feature set that makes it one of the most dangerous malicious programs in its class.
Read More
Adware screenshot
Adware
adware
Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.
Read More
Trojan screenshot
Trojan
trojan trojan horse
Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.
Read More
Xeno RAT screenshot
Xeno RAT
xenorat
Xeno RAT is an open-source malware mainly distributed through drive-by downloads. The core capabilities of this threat include remote control, keystroke logging, webcam and microphone access. Equipped with advanced utilities, such as Hidden Virtual Network Computing and Socks5 reverse proxy, Xeno RAT is most frequently used in attacks against individual users.
Read More
Roning Loader screenshot
Roning Loader
roning
RoningLoader is a multi-stage Windows loader designed to operate quietly while preparing systems for deeper compromise. It abuses trusted system tools and interferes with security controls to reduce the chances of early detection. Instead of acting as a final payload, it creates conditions for follow-on malware to execute more effectively. Its use of staged execution and code injection allows attackers to blend into legitimate activity and escalate impact. This makes early behavioral detection critical before the attack chain progresses further.
Read More