Advertisement
Bank_Security

GhostMiner: Cryptomining Malware Goes Fileless

Mar 26th, 2018
1,295
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.34 KB | None | 0 0
  1. IOCs
  2.  
  3. C2 IP Address:
  4. 123[.]59[.]68[.]172
  5.  
  6. Hashes (SHA-256)
  7. Neutrino.ps1:
  8. 4b9ce06c6dc82947e888e919c3b8108886f70e5d80a3b601cc6eb3752a1069a1
  9. 9a326afeeb2ba80de356992ec72beeab28e4c11966b28a16356b43a397d132e8
  10. WMI.ps1:
  11. 40a507a88ba03b9da3de235c9c0afdfcf7a0473c8704cbb26e16b1b782becd4d
  12. WMI64.ps1:
  13. 8a2bdea733ef3482e8d8f335e6a4e75c690e599a218a392ebac6fcb7c8709b52
  14.  
  15. Associated Monero address:
  16. 43ZSpXdMerQGerimDrUviDN6qP3vkwnkZY1vvzTV22AbLW1oCCBDstNjXqrT3anyZ22j7DEE74GkbVcQFyH2nNiC3fchGfc
  17.  
  18. β€œKiller” script:
  19. Service names
  20. xWinWpdSrv
  21. SVSHost
  22. Microsoft Telemetry
  23. lsass
  24. Microsoft
  25. system
  26. Oracleupdate
  27. CLR
  28. sysmgt
  29. gm
  30. WmdnPnSN
  31. Sougoudl
  32. Nationaaal
  33. Natimmonal
  34. Nationaloll
  35.  
  36. Task names
  37. Mysa
  38. Mysa1
  39. Mysa2
  40. Mysa3
  41. ok
  42. Oracle Java
  43. Oracle Java Update
  44. Microsoft Telemetry
  45. Spooler SubSystem Service
  46. Oracle Products Reporter
  47. Update service for products
  48. gm
  49. ngm
  50.  
  51. Process names
  52. msinfo
  53. xmrig*
  54. minerd
  55. MinerGate
  56. Carbon
  57. yamm1
  58. upgeade
  59. auto-upgeade
  60. svshost
  61. SystemIIS
  62. SystemIISSec
  63. WindowsUpdater*
  64. WindowsDefender*
  65. update
  66. carss
  67. service
  68. csrsc
  69. cara
  70. javaupd
  71. gxdrv
  72. lsmosee
  73.  
  74. Miner related server side TCP ports
  75. 1111
  76. 2222
  77. 3333
  78. 4444
  79. 5555
  80. 6666
  81. 7777
  82. 8888
  83. 9999
  84. 14433
  85. 14444
  86. 45560
  87. 65333
  88. 55335
  89.  
  90. Miner related command line arguments
  91. *cryptonight*
  92. *stratum+*
  93. *--donate-level*
  94. *--max-cpu-usage*
  95. *-p x*
  96. *pool.electroneum.hashvault
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement