PyCryptoMiner Linux Worm
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
PyCryptoMiner propagates by automatically scanning for vulnerable JBoss servers and brute-forcing their SSH logins. Once access is gained, a simple base-64 encoded Python script is loaded which connects to a command and control (C2) server. These addresses are published on Pastebin.com to prevent easy blacklisting of addresses.
Another base-64 encoded script is loaded from the C2 server to act as a controller. This script registers as a "cron" job to maintain persistence before collecting information on the host, operating system, number of central processing units (CPU) and CPU usage. It will also scan for other malware infections on the system before sending this information back to the C2 server. A list of tasks is then sent to the infected machine to begin the mining process.
It appears that Python has been used to construct PyCryptoMiner to allow it to more easily evade security measures. The scripts can be easily obfusticated and are executed by a legitimate binary such as Perl, Bash or PowerShell.
IOCs
SHA256 File Hashes
- d47d2aa3c640e1563ba294a140ab3ccd22f987d5c5794c223ca8557b68c25e0d
Command and Control Servers
- hxxp://pastebin[.]com/raw/yDnzKz72
- hxxp://pastebin[.]com/raw/rWjyEGDq
- hxxp://k.zsw8[.]cc:8080 (104.223.37[.]150)
- hxxp://i.zsw8[.]cc:8080 (103.96.75[.]115)
- hxxp://208.92.90[.]51
- hxxp://208.92.90[.]51:443
- hxxp://104.223.37[.]150:8090
Infected Machine
- /tmp/VWTFEdbwdaEjduiWar3adW
- /bin/httpsd
- /bin/wipefs
- /bin/wipefse
- /bin/minerd
- /bin/webnode
- /bin/safenode
- /tmp/tmplog
Remediation steps
Last edited: 17 February 2020 12:52 pm