SHA1:
- 14640a78751e74a7b1df3da2a4af295cf4535f82
A Trojan designed to mine cryptocurrency, an early version of a miner Trojan.BtcMine.1978. It is installed on servers that run on Microsoft Windows Server using a vulnerability in Cleverence Mobile SMARTS Server.
In its resources, the Trojan stores a malicious program Trojan.DownLoader26.11478. It uses this program to download Process Hacker, its driver and a miner module.
It attempts to delete the following system services:
WinDefend
MsMpSvc
SepMasterService
DrWebEngine
avp
AVP18.0.0
AVP17.0.0
AVP15.0.2
ekrn
a2AntiMalware
ZAMSvc
AntiVirService
The downloaded miner is saved in a folder %system32% with a name "svchоst.exe” and is launched from there.
News about the Trojan |