s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932554 high

📛 Threat Title

SnappyClient: URL that delivers a malware payload https://leebin101.com/r

Category: SnappyClient Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: SnappyClient (aliases: SilabRAT). Confidence: 100. First seen: 2026-09-25 06:28:04 UTC. Reporter: freeslugga. Tags: obfuscated-js, SnappyClient.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

url https://leebin101.com/r UrlVoid 3 / 36

IOC database

Type
url
Value
https://leebin101.com/r
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that delivers a malware payload attributed to SnappyClient

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: SnappyClient (aliases: SilabRAT). Confidence: 100. First seen: 2026-09-25 06:28:04 UTC. Reporter: freeslugga. Tags: obfuscated-js, SnappyClient.

Remediations (10)

  • web:any.run

    SnappyClient is a C++-based C2 implant first identified in December 2025, delivered through the HijackLoader malware loader. It combines remote access (terminal, process control, file management) with data theft (keylogging, screenshots, browser and crypto wallet credentials) in a single tool.

  • web:boteraser.com

    SnappyClient uses multi-stage payload delivery: initial infection occurs through spear-phishing emails with Excel files containing malicious VBA macros that retrieve a Snappy-compressed DLL from a remote server.

  • web:cybersecuritynews.com

    A dangerous new malware implant called SnappyClient has quietly emerged as a serious threat to Windows users, combining remote access, data theft, and sophisticated evasion techniques in one compact C++ package.

  • web:gbhackers.com

    A powerful new C2 implant called SnappyClient that blends remote access, credential theft, and stealthy evasion into a single, modular framework targeting Windows systems and cryptocurrency users. ThreatLabz first observed SnappyClient in December 2025, being deployed via the well-known HijackLoader malware family. SnappyClient is written in C++ and operates as a flexible command-and-control ...

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Zscaler, SnappyClient was first observed in December 2025. It is a C++-based C2 implant with the ability to steal data and provide remote access. SnappyClient employs multiple evasion techniques to hinder endpoint security detection, including an Antimalware Scan Interface (AMSI) bypass, as well as implementing Heaven's Gate, direct system calls, and transacted hollowing ...

  • web:maltiverse.com

    SnappyClient First seen 2025-12-01 00:00:00 Malware type rat, backdoor Family Malware family Related IoCs 16 (16 malicious) Last IoC activity 2026-09-15 11:21:28 Profile updated 2026-07-07 15:05:26 Targeted industries: government-and-public-sector technology-and-telecommunications financial-services Context According to Zscaler, SnappyClient was first observed in December 2025. It is a C++ ...

  • web:malwaretips.com

    HijackLoader as the delivery mechanism HijackLoader has been seen repeatedly in malware campaigns, so its use here fits a broader pattern of modular delivery. The loader handles execution and evasion, then deploys the actual payload . SnappyClient as the post-infection implant Based on the quoted summary, this is not just a simple stealer.

  • web:urlhaus.abuse.ch

    URLhaus Database URLhaus tries to identify the malware associated with the payload served by a certain malware URL . In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as SnappyClient . Database Entry

  • web:www.zscaler.com

    Introduction In December 2025, Zscaler ThreatLabz identified a new command-and-control (C2) framework implant that we track as SnappyClient , which was delivered using HijackLoader. SnappyClient has an extended list of capabilities including taking screenshots, keylogging, a remote terminal, and data theft from browsers, extensions, and other applications. In this blog post, ThreatLabz provides ...

  • web:www.zscaler.com

    This HijackLoader sample (if executed by a victim) decrypts and loads SnappyClient . Additional attack chains have also been observed for SnappyClient delivery. In early February, ThreatLabz observed an X (formerly Twitter) post by @Kostastsale describing a GhostPulse/HijackLoader intrusion via ClickFix, with SnappyClient delivered as the payload .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.