저작권 위반 그림 사용 확인 메일'로 위장한 가상화폐 채굴 악성코드 주의

2018-01-18 ESTSecurity Beware of virtual currency mining malware disguised as a ‘copyright infringement image use confirmation email'

http://blog.alyac.co.kr/1498

Thumbnail for 저작권 위반 그림 사용 확인 메일'로 위장한 가상화폐 채굴 악성코드 주의

ESTsecurity describes Venus Locker operators distributing email lures framed as copyright-law complaints to push malware with Monero mining functionality. The attached EGG archive contained shortcut files and an executable; running a shortcut launched the .NET malware laptop.exe instead of simply showing the alleged image evidence. The malware created and injected a copy of itself, persisted through a Run key under the user profile, and injected into system processes such as wuapp.exe, svchost.exe, notepad.exe, or explorer.exe depending on the operating system architecture. The mining command connected to xmr.pool.minergate.com on port 45560 using a Proton Mail address as the miner account. The report matters as an example of socially engineered email attachments combining familiar legal-pressure lures with commodity cryptocurrency-mining payloads.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2018-01-15 2018-01-18
DOMAIN xmr.pool.minergate.com 2018-01-15 2018-01-18

Related Reports

« Back