Analysis by: Rheniel Rhay Ramos

ALIASES:

RDN/ADB.Miner (McAfee); Backdoor:Linux/Mirai!rfn (Microsoft); Andr/AdbMiner-A (Sophos)

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Coinminer

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This Coinminer arrives as a component bundled with malware/grayware packages.

  TECHNICAL DETAILS

Tamaño del archivo 169,624 bytes
Tipo de archivo ELF
Residente en memoria No
Fecha de recepción de las muestras iniciales 07 Feb 2018

Arrival Details

This Coinminer arrives as a component bundled with malware/grayware packages.

Other Details

This Coinminer does the following:

  • It searches for all devices with enabled 5555 adb ports.
  • It will use specific commands to propagate the following files to the specific folders:
    • /data/local/tmp/sss -> detected asCoinminer_MALXMR.BB-ELF32
    • /data/local/tmp/nohup
    • /data/local/tmp/bot.dat -> detected as Coinminer_MALXMR.BC-CFG

  SOLUTION

Motor de exploración mínimo 9.850
Primer archivo de patrones de VSAPI 13.964.08
Primera fecha de publicación de patrones de VSAPI 13 Feb 2018
Versión de patrones OPR de VSAPI 13.965.00
Fecha de publicación de patrones OPR de VSAPI 14 Feb 2018

Step 1

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android and iOS smartphones and tablets from malicious and Trojanized applications. It blocks access to malicious websites, increase device performance, and protects your mobile data. You may download the Trend Micro Mobile Security apps from the following sites:

Step 2

Remove unwanted apps on your Android mobile device

[ Learn More ]

Did this description help? Tell us how we did.