logo

[Guest Diary] Using Zeek, Snort, and Grafana to Detect Crypto Mining Malware, (Tue, Nov 26th)

ID: f2722382-589f-584e-96de-a502a059cfd2

STIX ID: report--f2722382-589f-584e-96de-a502a059cfd2

Feed Name: SANS ISC Diary

Threat Score
50/100

Date Published: 2024-11-26

Date Updated: 2026-04-19

...
...

A DShield honeypot observed an active campaign deploying 'RedTail' crypto-mining malware via SSH password-guessing; the malware drops installers (setup.sh, redtail.*), uses XMRig/Stratum mining (DNS lookups for moneroed.net, Stratum on port 2137) and communicates with a C2 on port 43782 where client packets start with hex 0x0c180000003c. The author demonstrates detection using a Zeek cryptomining package and a Snort signature (content:"|0c 18 00 00 00 3c|"), notes multiple attacker IPs and changing binary hashes, and recommends network tapping, IDS/Zeek monitoring, and signature-driven hunting to reduce detection time.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.