Skip to main content

PyCryptoMiner Linux Worm

A new Python-based worm has been observed, known as PyCryptoMiner, that spreads over the Secure Shell (SSH) protocol and targets Linux devices in order to enrol them in a Monero cryptocurrency mining botnet.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A new Python-based worm has been observed, known as PyCryptoMiner, that spreads over the Secure Shell (SSH) protocol and targets Linux devices in order to enrol them in a Monero cryptocurrency mining botnet.

Affected platforms

The following platforms are known to be affected:

Threat details

PyCryptoMiner propagates by automatically scanning for vulnerable JBoss servers and brute-forcing their SSH logins. Once access is gained, a simple base-64 encoded Python script is loaded which connects to a command and control (C2) server. These addresses are published on Pastebin.com to prevent easy blacklisting of addresses.

Another base-64 encoded script is loaded from the C2 server to act as a controller. This script registers as a "cron" job to maintain persistence before collecting information on the host, operating system, number of central processing units (CPU) and CPU usage. It will also scan for other malware infections on the system before sending this information back to the C2 server. A list of tasks is then sent to the infected machine to begin the mining process.

It appears that Python has been used to construct PyCryptoMiner to allow it to more easily evade security measures. The scripts can be easily obfusticated and are executed by a legitimate binary such as Perl, Bash or PowerShell.

IOCs

SHA256 File Hashes

  • d47d2aa3c640e1563ba294a140ab3ccd22f987d5c5794c223ca8557b68c25e0d

Command and Control Servers

  • hxxp://pastebin[.]com/raw/yDnzKz72
  • hxxp://pastebin[.]com/raw/rWjyEGDq
  • hxxp://k.zsw8[.]cc:8080 (104.223.37[.]150)
  • hxxp://i.zsw8[.]cc:8080 (103.96.75[.]115)
  • hxxp://208.92.90[.]51
  • hxxp://208.92.90[.]51:443
  • hxxp://104.223.37[.]150:8090

Infected Machine

  • /tmp/VWTFEdbwdaEjduiWar3adW
  • /bin/httpsd
  • /bin/wipefs
  • /bin/wipefse
  • /bin/minerd
  • /bin/webnode
  • /bin/safenode
  • /tmp/tmplog

Remediation steps

Type Step
  • Where possible, avoid using SSH logins on internet-facing servers.
  • Ensure that strong password and account policies are enforced for all accounts that have access to management interfaces over SSH.
  • Use multi factor authentication (MFA) and valid certificates.

Last edited: 17 February 2020 12:52 pm