Minas — a multi-stage cryptocurrency miner infection
Tags
attack-pattern: | Data Malware - T1587.001 Malware - T1588.001 Powershell - T1059.001 Scheduled Task - T1053.005 Server - T1583.004 Server - T1584.004 Powershell - T1086 Scheduled Task - T1053 |
Common Information
Type | Value |
---|---|
UUID | 0b1c0538-af74-49bf-a72d-15d5a3707a93 |
Fingerprint | afad9d30a4b70648 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | May 17, 2023, 10 a.m. |
Added to db | June 5, 2023, 11:36 a.m. |
Last updated | Nov. 17, 2024, 6:55 p.m. |
Headline | Minas – on the way to complexity |
Title | Minas — a multi-stage cryptocurrency miner infection |
Detected Hints/Tags/Attributes | 39/1/14 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 99 | ✔ | Cyware News - Latest Cyber News | https://cyware.com/allnews/feed | 2024-08-30 22:08 |
Details | 223 | ✔ | Securelist | https://securelist.com/feed/ | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 285 | microsoft.net |
|
Details | Domain | 338 | kaspersky.com |
|
Details | 147 | intelreports@kaspersky.com |
||
Details | File | 1 | lgntoerr.gif |
|
Details | File | 8 | ilasm.exe |
|
Details | File | 2 | fusion.dll |
|
Details | File | 172 | dllhost.exe |
|
Details | md5 | 1 | 143e256609bcb0be5b9f9c8f79bdf8c9 |
|
Details | md5 | 1 | 08da41489b4b68565dc77bb9acb1ecb4 |
|
Details | md5 | 1 | 06fe9ab0b17f659486e3c3ace43f0e3a |
|
Details | md5 | 1 | f38a1b6b132afa55ab48b4b7a8986181 |
|
Details | md5 | 1 | 63e0cd6475214c697c5fc115d40327b4 |
|
Details | sha256 | 1 | 14e18cc1bd2f1af7344b31692caeda949a62f71475f43ae4d9ea287e9847b495 |
|
Details | IPv4 | 1 | 185.243.112.239 |