GhostMiner Weaponizes WMI, Kills Other Mining Payloads
Common Information
Type Value
UUID e68b851f-2bab-43de-9eec-ebf556aa0946
Fingerprint 9d25a839647286c7
Analysis status DONE
Considered CTI value 2
Text language
Published Sept. 19, 2019, midnight
Added to db Sept. 26, 2022, 9:30 a.m.
Last updated Nov. 17, 2024, 6:54 p.m.
Headline GhostMiner Weaponizes WMI, Kills Other Mining Payloads
Title GhostMiner Weaponizes WMI, Kills Other Mining Payloads
Detected Hints/Tags/Attributes 39/1/15
Attributes
Details Type #Events CTI Value
Details Domain 3
commandlineeventconsumer.name
Details File 1208
powershell.exe
Details File 4
cc.php
Details File 2
c:\windows\temp\lsass.exe
Details File 21
takeown.exe
Details File 1
c:\windows\temp  icacls.exe
Details File 37
icacls.exe
Details sha256 1
13a4751b83e53abdf0fb6d5876d6cc9dfbd33e343038dae6951de755d93c8284
Details sha256 1
558914713cf3174c8b489aef12a1a7871ad886bc9483fd7b0790383702bfd75d
Details sha256 1
7cec25bdb7c3cb2778168e9b02e0fdd608a6c94cb69feba7b4ee647aef0588b1
Details sha256 1
8ffa7f991637e28fa5b4ae7f5522fe5fee622307bed87d1d478c48fa0696dc5a
Details sha256 1
a0e0e5d0ff95e3193ed0999234588e3327ea8d759316a0d1175c5084daf5b083
Details sha256 1
aa16c957a85ecedaac9f629082913dfdaefe95b8b8191d7cb3e8c02da2963452
Details IPv4 1
118.24.63.208
Details IPv4 1
103.105.59.68