XMRig based CoinMiners Spreaded by Blue Mockingbird Group
Common Information
Type | Value |
---|---|
UUID | 8f2c894e-46e4-4031-ad04-a16ec7621dd0 |
Fingerprint | faaf7ae3f0670c2b359f169eb0f2eeba178724568a27047378cec948fac6c01a |
Analysis status | DONE |
Considered CTI value | 1 |
Text language | |
Published | June 1, 2020, 7:22 a.m. |
Added to db | April 14, 2024, 1:34 a.m. |
Last updated | Aug. 31, 2024, 6:29 a.m. |
Headline | XMRig based CoinMiners Spreaded by Blue Mockingbird Group |
Title | XMRig based CoinMiners Spreaded by Blue Mockingbird Group |
Detected Hints/Tags/Attributes | 90/3/55 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 67 | cve-2019-18935 |
|
Details | Domain | 13 | lifars.com |
|
Details | Domain | 397 | asp.net |
|
Details | Domain | 4128 | github.com |
|
Details | Domain | 3 | xmr-us-east1.nanopool.org |
|
Details | Domain | 2 | xmr-us-west1.nanopool.org |
|
Details | Domain | 6 | xmr-eu1.nanopool.org |
|
Details | Domain | 21 | pool.minexmr.com |
|
Details | Domain | 1 | set.zip |
|
Details | Domain | 14 | analyze.intezer.com |
|
Details | 8 | info@lifars.com |
||
Details | File | 128 | w3wp.exe |
|
Details | File | 4 | wercplsupporte.dll |
|
Details | File | 6 | wercplsupport.dll |
|
Details | File | 2 | dialogex.dll |
|
Details | File | 2 | checkservices.dll |
|
Details | File | 9 | x.bat |
|
Details | File | 1 | build_dll.bat |
|
Details | File | 1 | empty.cs |
|
Details | File | 3 | random.dll |
|
Details | File | 459 | regsvr32.exe |
|
Details | File | 62 | scrobj.dll |
|
Details | File | 1122 | svchost.exe |
|
Details | File | 1018 | rundll32.exe |
|
Details | File | 2127 | cmd.exe |
|
Details | File | 1 | c:\windows\system32\%random1%.dll |
|
Details | File | 1 | c:\windows\system32\%random2%.dll |
|
Details | File | 1 | c:\windows\system32\%random3%.dll |
|
Details | File | 2 | c:\windows\system32\wercplsupporte.dll |
|
Details | File | 1 | c:\windows\system32\%result3%.dll |
|
Details | File | 7 | regsvr32.dll |
|
Details | File | 1 | c:\\windows\\system32\\checkservices.dll |
|
Details | File | 1 | c:\\windows\\system32\\wercplsupporte.dll |
|
Details | File | 11 | mofcomp.exe |
|
Details | File | 1 | zzz.dll |
|
Details | File | 249 | schtasks.exe |
|
Details | File | 2 | rn.bat |
|
Details | File | 1 | comhij.dll |
|
Details | File | 1 | %random%.dll |
|
Details | File | 2 | xg.dll |
|
Details | File | 4 | set.bat |
|
Details | File | 1 | set.zip |
|
Details | File | 1 | c:\programdata directory and via let.exe |
|
Details | File | 2 | let.exe |
|
Details | Github username | 2 | noperator |
|
Details | Github username | 1 | re4lity |
|
Details | Github username | 3 | ohpe |
|
Details | Github username | 9 | xmrig |
|
Details | IPv4 | 1 | 127.11.11.11 |
|
Details | Url | 1 | https://github.com/noperator/cve-2019-18935/. |
|
Details | Url | 1 | https://github.com/re4lity/schtasks-backdoor |
|
Details | Url | 1 | https://github.com/ohpe/juicy-potato |
|
Details | Url | 1 | https://github.com/noperator/cve-2019-18935 |
|
Details | Url | 5 | https://github.com/xmrig/xmrig |
|
Details | Url | 8 | https://analyze.intezer.com/# |