s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932555 high

📛 Threat Title

SnappyClient: URL that delivers a malware payload https://leebin101.com/g.php

Category: SnappyClient Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: SnappyClient (aliases: SilabRAT). Confidence: 100. First seen: 2026-09-25 06:28:04 UTC. Reporter: freeslugga. Tags: obfuscated-js, SnappyClient.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

url https://leebin101.com/g.php UrlVoid 3 / 36

IOC database

Type
url
Value
https://leebin101.com/g.php
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that delivers a malware payload attributed to SnappyClient

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: SnappyClient (aliases: SilabRAT). Confidence: 100. First seen: 2026-09-25 06:28:04 UTC. Reporter: freeslugga. Tags: obfuscated-js, SnappyClient.

Remediations (10)

  • web:any.run

    SnappyClient is a C++-based C2 implant first identified in December 2025, delivered through the HijackLoader malware loader. It combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, browser and crypto wallet credentials) in a single tool.

  • web:community.gurucul.com

    In December 2025, Labz discovered a new C2 implant called SnappyClient , delivered via HijackLoader. SnappyClient is a C++-based malware that enables remote access and extensive data theft. Its capabilities include keylogging, screenshots, remote terminal access, and stealing data from browsers and applications.

  • web:cyberpress.org

    In December 2025, security researchers at Zscaler ThreatLabz discovered a new command-and-control (C2) framework implant named SnappyClient . Attackers deliver this malicious tool using the known HijackLoader malware . Once installed, SnappyClient provides hackers with extensive control over a victim ...

  • web:cybersecuritynews.com

    A dangerous new malware implant called SnappyClient has quietly emerged as a serious threat to Windows users, combining remote access, data theft, and sophisticated evasion techniques in one compact C++ package. First spotted in December 2025, this command-and-control (C2) framework implant can log keystrokes, take screenshots, launch a remote terminal, and pull sensitive data from browsers ...

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Zscaler, SnappyClient was first observed in December 2025. It is a C++-based C2 implant with the ability to steal data and provide remote access. SnappyClient employs multiple evasion techniques to hinder endpoint security detection, including an Antimalware Scan Interface (AMSI) bypass, as well as implementing Heaven's Gate, direct system calls, and transacted hollowing ...

  • web:malware.news

    IntroductionIn December 2025, Zscaler ThreatLabz identified a new command-and-control (C2) framework implant that we track as SnappyClient , which was delivered using HijackLoader. SnappyClient has an extended list of capabilities including taking screenshots, keylogging, a remote terminal, and data theft from browsers, extensions, and other applications. In this blog post, ThreatLabz provides ...

  • web:undercodenews.com

    The malware is delivered using HijackLoader, a known malware loader often used to deploy second-stage payloads while evading detection systems. SnappyClient stands out due to its strong focus on stealth and persistence.

  • web:vpncentral.com

    A newly documented malware implant called SnappyClient gives attackers remote access to infected Windows systems, steals data from browsers and crypto apps, and uses several anti-detection tricks to stay hidden. Zscaler ThreatLabz says it first identified SnappyClient in December 2025 and found that attackers delivered it through HijackLoader in campaigns that included a fake Telefónica […]

  • web:www.darkreading.com

    C2 Implant 'SnappyClient' Targets Crypto Wallets In addition to enabling remote access, the malware supports a wide range of capabilities, including data theft and spying.

  • web:www.zscaler.com

    Introduction In December 2025, Zscaler ThreatLabz identified a new command-and-control (C2) framework implant that we track as SnappyClient , which was delivered using HijackLoader. SnappyClient has an extended list of capabilities including taking screenshots, keylogging, a remote terminal, and data theft from browsers, extensions, and other applications. In this blog post, ThreatLabz provides ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.