Mimo CoinMiner and Mimus Ransomware Installed via Vulnerability Attacks - ASEC
Common Information
Type Value
UUID 43a3d642-4b94-4d8f-a96b-95add792f122
Fingerprint 84ada45981579e87
Analysis status DONE
Considered CTI value 2
Text language
Published Jan. 11, 2024, 3 p.m.
Added to db Oct. 1, 2024, 3:42 p.m.
Last updated Nov. 17, 2024, 6:53 p.m.
Headline Mimo CoinMiner and Mimus Ransomware Installed via Vulnerability Attacks
Title Mimo CoinMiner and Mimus Ransomware Installed via Vulnerability Attacks - ASEC
Detected Hints/Tags/Attributes 68/2/28
Attributes
Details Type #Events CTI Value
Details CVE 397
cve-2021-44228
Details CVE 23
cve-2022-29464
Details CVE 122
cve-2022-26134
Details CVE 140
cve-2023-27350
Details CVE 84
cve-2023-46604
Details Domain 1
dom.zip
Details Domain 1
dom-6.zip
Details Domain 1
windows.n1tro.cyou
Details Domain 74
proton.me
Details Domain 3
satoshidisk.com
Details Email 1
arbeyceo@proton.me
Details File 1
poc-win.xml
Details File 1
lnl.bat
Details File 17
kill.bat
Details File 1
ln.bat
Details File 4
mad.bat
Details File 1
dom.zip
Details File 1
dom-6.zip
Details File 1
dom.exe
Details File 1
dsm.exe
Details File 4
read_to_decrypt.html
Details File 4
files_encrypted.html
Details File 351
recycle.bin
Details File 31
generic.c4
Details IPv4 2
102.130.112.157
Details Url 1
http://102.130.112.157/poc-win.xml
Details Url 1
http://windows.n1tro.cyou:4544
Details Url 1
https://satoshidisk.com/pay/ciirg6