Bitcoin Mining Malware
ID: 03aff456-2947-5cf9-9cec-031c1f724a90
STIX ID: report--03aff456-2947-5cf9-9cec-031c1f724a90
Feed Name: Zscaler Security Research Blog
This report analyzes Bitcoin-mining malware (Trojan.Badminer and related samples) that deploys Ufasoft-based miners to infected Windows hosts, reports miner activity to attacker-controlled domains and Hetzner-hosted IPs, and includes IOCs such as MD5 hashes (e.g., 8941ECF2586690701F0E748CCC954BB7), domains (x.miners.in), IPs (78.47.124.250 and others), and distinctive user-agent strings; the author notes detection rates on VirusTotal and a growing trend of such malicious miners being used by botnets to monetize compromised machines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
