SHA1:
- 39fc51bb248869e0e28db47adabef35b08cb1d34
A Trojan designed to mine cryptocurrency, an improved version of a miner Trojan.BtcMine.2024. It is installed on servers that run on Microsoft Windows Server using a vulnerability in Cleverence Mobile SMARTS Server.
Contains three resources:
- Service.Payload.networks.dat — a zip archive with a file russia.txt. This file contains subnets that correspond to Russia according to geolocation.
- Service.Payload.svchost.dat — a miner to mine the XMRig cryptocurrency.
- Service.Payload.x64.dat — a driver of an application Process Hacker.
All resources are encrypted using the XOR algorithm.
News about the Trojan |