[Guest Diary] Using Zeek, Snort, and Grafana to Detect Crypto Mining Malware, (Tue, Nov 26th)
ID: f2722382-589f-584e-96de-a502a059cfd2
STIX ID: report--f2722382-589f-584e-96de-a502a059cfd2
Feed Name: SANS ISC Diary
A DShield honeypot observed an active campaign deploying 'RedTail' crypto-mining malware via SSH password-guessing; the malware drops installers (setup.sh, redtail.*), uses XMRig/Stratum mining (DNS lookups for moneroed.net, Stratum on port 2137) and communicates with a C2 on port 43782 where client packets start with hex 0x0c180000003c. The author demonstrates detection using a Zeek cryptomining package and a Snort signature (content:"|0c 18 00 00 00 3c|"), notes multiple attacker IPs and changing binary hashes, and recommends network tapping, IDS/Zeek monitoring, and signature-driven hunting to reduce detection time.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
