COINMINER_MALXMR.BA-ELF32
March 01, 2018
ALIASES:
Andr/AdbMiner-A (Sophos)
PLATFORM:
Android
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:

Threat Type: Coinminer
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Coinminer arrives as a component bundled with malware/grayware packages.
TECHNICAL DETAILS
Tipo de compactação: 588,348 bytes
Tipo de arquivo: ELF
Residente na memória: No
Data de recebimento das amostras iniciais: 07 Feb 2018
Arrival Details
This Coinminer arrives as a component bundled with malware/grayware packages.
Other Details
This Coinminer does the following:
- It uses the following as its config file:
- config.json -> detected as Coinminer_MALXMR.B-CFG
- It uses the following URLs as mining pools:
- {BLOCKED}.{BLOCKED}.hashvault.pro:5555
- {BLOCKED}.{BLOCKED}r.com:7777
- It uses the following as username for the mining server or simply the wallet address:
- 44XT4KvmobTQfeWa6PCQF5RDosr2MLWm43AsaE3o5iNRXXTfDbYk2VPHTVedTQHZyfXNzMn8YYF2466d3FSDT7gJS8gdHAr
SOLUTION
Mecanismo de varredura mínima: 9.850
Primeiro arquivo padrão VSAPI: 13.968.04
Data do lançamento do primeiro padrão VSAPI: 15 Feb 2018
VSAPI OPR Pattern Version: 13.969.00
VSAPI OPR Pattern veröffentlicht am: 16 Feb 2018
Step 1
Trend Micro Mobile Security Solution
Trend Micro Mobile Security Personal Edition protects Android and iOS smartphones and tablets from malicious and Trojanized applications. It blocks access to malicious websites, increase device performance, and protects your mobile data. You may download the Trend Micro Mobile Security apps from the following sites:
Step 2
Remove unwanted apps on your Android mobile device
[ Learn More ]
Did this description help? Tell us how we did.