Rewterz Threat Alert – Nodera Ransomware
January 24, 2020Rewterz Threat Alert – TrickBot Steals Windows Active Directory Credentials
January 24, 2020Rewterz Threat Alert – Nodera Ransomware
January 24, 2020Rewterz Threat Alert – TrickBot Steals Windows Active Directory Credentials
January 24, 2020Severity
High
Analysis Summary
A family of Monero Miners that spreads through cloud storage providers such as OneDrive, Google Drive and Dropbox. It also has the ability to mutate or change itself to try to avoid detection.
This malware’s main objective is to mine Monero. It includes in its body a version of XMRig miner. The system infected with this malware will be noticeably slow, as the cryptominer will consume most of the CPU. to extract the XMRig configuration files from the binaries we analyzed and identified at least four mining pools that this miner joins. This indicates that there could be more than one threat actor operating this network of miners.
One unique characteristic of this GoMiner is that it can spread itself via public cloud storage by dropping several copies of itself in “Public” folders.
It looks for the availability of the following files before dropping itself in those directories:
- %USERPROFILE%\Dropbox\Public
- %USERPROFILE%\OneDrive\Public
- %USERPROFILE%\Google Drive
When the above folders exist, it will drop a copy of itself with the following filenames:
- USBDriver.exe
- Installer.exe
- Install.exe
- Setup.exe
Impact
Mine Monero
Indicators of Compromise
SHA-256
- ecdcc6273bd8ccbf2740a3e43caba81647d9abec14386d7df3a3e9f725b2493a
- 9c76815aa2612c6777ce9addbcc38601d2d44e0b0de8787cdb922b0218a765f4
- 3fc3a8c9ed96021927bcd2ec69a487d51b66d7e5d03d252cf6a0bae9074e0327
- cb8f3a0b35b985204d4f371b2f41510d503eeb1da1f51a5aee533f5ecc1b078b
- db3ce6b9ad58923db5e2a3137c40a59ab186f223483f696869d56a641b233062
- 51dccbe2d84e52a4b5e0cb13379d0c79fa3a03f01ea0119e7b19c174d5b0ead4
- 6a42e610c1adf2d347488ec2fd42127dd1e3ca667519f7ac0a0728118f9fc607
- f46b3e8885d75baff9ec81192feeef61f1f05826d900fb05518797aae9db7b79
- 25496ec3b287c215e7a802ee4b7aad20e9eac550a4e044fe68a937baff04a077
- 69e48b7fac8d4e318dc79adb67bb2b56c27b020fa92c86ac1b01b2c0fb50a62e
- 706f7bd0508a91905196fcfafedba742e9ec920e9e8dc4ba1e4d90cc279f6350
- 1f36c63d182c6348e233ff8601185b585aee77eaadaab10bc226ac9df47e5ee4
- 77f59a8bc999e3c368894332e37ae88b986ed67d3a16a1557373ba076527db44
- fb7fd2710279a64056cbf7b55fef5dbbaf598f0b5958c71f045749685edaa1c4
- ab3790c79cc449d865e2568f2a4f854883fe0792d37c17f0a5c082581bd5fd7b
- fd2b55482f3db95e0a0b4d8d563ce45d08a43b5692ac4eee5c61b6084678eb38
- 18a2213384ec97c2b51cda378688f34b143b83a0f005977b748cca18dae2f5cd
- 18623498d214284064336b5c49b6205de2b0724952d2cf45d819b4d034a3260b
- 68a6f1e34ab571772f8aa4699b2904b9eb05de5bd2224edee138e17f87898cd4
- 685223dda5556cda659cb4f5e89cde24b81c910a78b1bdeed008380dc1d62417
- 1a455a3291e996ef9f7e964695eb48646d223e588ccb1f355c06fc21b1052456
- 9c4d85811fd1347a155dca7b5ad4be2a08b3adf932849d4e8b1320bd339a772e
- ad01b428e35bf4b70b86d050dae8e4036791018608d70564ebfa5fec04027051
- 712939c0a69c74ba85ebab9a48c3fd2934b9cb5a3ff0a506f3a1944386a15755
- ad5c6dbc06422bc19682080fc2eb40e24ad7913836f7947ffc3d791ddf488d07
- 2e3c8c7eb64bb881fcb82f14a20a788221a17bc048ad58ca7702363986b9dfc7
- 5d4de43d56f18c0a69c126eff8a792c47192a4197a6ec5e1fa0333436fe4687b
- 504a44632664652d9fe9a27519194d2296f85905fc68341b30eb9f97b8c9cf01
- 271cb5b032376c6531f4f57fe17b4f9255ac2577b59320ad49f59e1f60cb4689
- a50e043fb25d68bb38deb38b8d31728c1ba2df3d68ac5cd0eed633f341485048
- 98e1b71ff1980c7e1484dedde2cc6f6e6eea842729405d925dd6855795a54197
- 66c77ed578dbdb6c5076a66098e330b1682a69ee361bc9746f33a12f53e3e29b
- 96e2bb8d289f25c3f0c61d08ea96bfc897ee95793121e5c5eafb41c4cc0aebf2
- ec3ffdfd40d9bef3c7ffe3dfd4838f42cddbd1981135d87e193dc18419f964a0
- aa2c806c3ff473185e2df94e265bb0886c030daefa6f378866282fba37942820
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails sent by unknown senders.
- Never click on the links/attachments sent by unknown senders.