COINMINER_MALXMR.BB-ELF32

 Analysis by: Rheniel Rhay Ramos

 ALIASES:

RDN/ADB.Miner (McAfee); Andr/AdbMiner-A (Sophos); ELF:BitCoinMiner-CM [Trj] (Avast)

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Coinminer

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW


This Coinminer arrives as a component bundled with malware/grayware packages.

  TECHNICAL DETAILS

File Size:

165,528 bytes

File Type:

ELF

Memory Resident:

No

Initial Samples Received Date:

07 Feb 2018

Payload:

Drops files

Arrival Details

This Coinminer arrives as a component bundled with malware/grayware packages.

Installation

This Coinminer drops and executes the following files:

  • /data/local/tmp/droidbot -> detected as Coinminer_MALXMR.B-ELF32
  • /data/local/tmp/invoke.sh -> used to grant permissions in replacing system files
  • /data/local/tmp/ddexe
  • /data/local/tmp/debuggerd
  • /data/local/tmp/install-recovery.sh
  • /data/local/tmp/xmrig32 -> detected as Coinminer_MALXMR.BA-ELF32
  • /data/local/tmp/xmrig64 -> detected as Coinminer_MALXMR.BA-ELF64
  • /data/local/tmp/config.json -> detected as Coinminer_MALXMR.B-CFG

Other Details

This Coinminer does the following:

  • It uses nohup to continue execution even if the terminal is closed.
  • It decrypts the following file to be used as the contents of its drop files:
    • bot.dat -> detected as Coinminer_MALXMR.BC-CFG

  SOLUTION

Minimum Scan Engine:

9.850

FIRST VSAPI PATTERN FILE:

13.968.04

FIRST VSAPI PATTERN DATE:

15 Feb 2018

VSAPI OPR PATTERN File:

13.969.00

VSAPI OPR PATTERN Date:

16 Feb 2018

Step 1

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android and iOS smartphones and tablets from malicious and Trojanized applications. It blocks access to malicious websites, increase device performance, and protects your mobile data. You may download the Trend Micro Mobile Security apps from the following sites:

Step 2

Remove unwanted apps on your Android mobile device

[ Learn More ]

Did this description help? Tell us how we did.