XMRig based CoinMiners Spreaded by Blue Mockingbird Group
Image Description
Common Information
Type Value
UUID 8f2c894e-46e4-4031-ad04-a16ec7621dd0
Fingerprint faaf7ae3f0670c2b359f169eb0f2eeba178724568a27047378cec948fac6c01a
Analysis status DONE
Considered CTI value 1
Text language
Published June 1, 2020, 7:22 a.m.
Added to db April 14, 2024, 1:34 a.m.
Last updated Aug. 31, 2024, 6:29 a.m.
Headline XMRig based CoinMiners Spreaded by Blue Mockingbird Group
Title XMRig based CoinMiners Spreaded by Blue Mockingbird Group
Detected Hints/Tags/Attributes 90/3/55
Attributes
Details Type #Events CTI Value
Details CVE 67
cve-2019-18935
Details Domain 13
lifars.com
Details Domain 397
asp.net
Details Domain 4128
github.com
Details Domain 3
xmr-us-east1.nanopool.org
Details Domain 2
xmr-us-west1.nanopool.org
Details Domain 6
xmr-eu1.nanopool.org
Details Domain 21
pool.minexmr.com
Details Domain 1
set.zip
Details Domain 14
analyze.intezer.com
Details Email 8
info@lifars.com
Details File 128
w3wp.exe
Details File 4
wercplsupporte.dll
Details File 6
wercplsupport.dll
Details File 2
dialogex.dll
Details File 2
checkservices.dll
Details File 9
x.bat
Details File 1
build_dll.bat
Details File 1
empty.cs
Details File 3
random.dll
Details File 459
regsvr32.exe
Details File 62
scrobj.dll
Details File 1122
svchost.exe
Details File 1018
rundll32.exe
Details File 2127
cmd.exe
Details File 1
c:\windows\system32\%random1%.dll
Details File 1
c:\windows\system32\%random2%.dll
Details File 1
c:\windows\system32\%random3%.dll
Details File 2
c:\windows\system32\wercplsupporte.dll
Details File 1
c:\windows\system32\%result3%.dll
Details File 7
regsvr32.dll
Details File 1
c:\\windows\\system32\\checkservices.dll
Details File 1
c:\\windows\\system32\\wercplsupporte.dll
Details File 11
mofcomp.exe
Details File 1
zzz.dll
Details File 249
schtasks.exe
Details File 2
rn.bat
Details File 1
comhij.dll
Details File 1
%random%.dll
Details File 2
xg.dll
Details File 4
set.bat
Details File 1
set.zip
Details File 1
c:\programdata directory and via let.exe
Details File 2
let.exe
Details Github username 2
noperator
Details Github username 1
re4lity
Details Github username 3
ohpe
Details Github username 9
xmrig
Details IPv4 1
127.11.11.11
Details Url 1
https://github.com/noperator/cve-2019-18935/.
Details Url 1
https://github.com/re4lity/schtasks-backdoor
Details Url 1
https://github.com/ohpe/juicy-potato
Details Url 1
https://github.com/noperator/cve-2019-18935
Details Url 5
https://github.com/xmrig/xmrig
Details Url 8
https://analyze.intezer.com/#