Apache Struts Exploit Cryptocurrency Miner
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The exploit code was published three days after the vulnerability was disclosed.
If successful the exploit code performs requests to URLs, downloads a copy of the CNRig cryptocurrency miner and a shell script.The executed script deploys Linux ELF binaries for Intel, ARM and MIPS processors to enable the miner to run on a wide range of hardware.
Once the CNRig module is installed it will initiate mining tokens over TCP port 20580.
Remediation steps
| Type | Step |
|---|---|
|
CVE Vulnerabilities
Last edited: 17 February 2020 12:37 pm