Bitcoin Miner Utilizing IRC Worm
ID: 7094c86c-6ed8-55d5-9387-ee05c3b4c472
STIX ID: report--7094c86c-6ed8-55d5-9387-ee05c3b4c472
Feed Name: Zscaler Security Research Blog
Threat Score
The report analyzes a network-propagating IRC-enabled worm that drops binaries and autorun.inf to infect SMB shares, establishes persistence (service and IFEO debugger), beacons to IRC/C2 and DNS-based phone-home servers, and runs a bitcoin mining payload (xptMiner). Several variant samples and DNS indicators are provided along with VirusTotal/sandbox references and evidence of low AV detection rates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
