Skypemageddon by Bitcoining
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | hotfile.com | ystem many other pieces of malware. Downloads come from the Hotfile.com service. At the same time the malware connects to its C2 se |
| ipv4 | 213.165.68.138 | o its C2 server located in Germany. The IP address of C2 is 213.165.68.138:9000 So what does malware do? To be honest many things but |
Full article406 words · extracted from securelist.com · click to collapse
Is it a Skype day? Or maybe a Bitcoin one? Or maybe just both?
I say this because right after I published my previous post about malware ongoing campaign on Skype, a mate from Venezuela sent me a screenshot of her Skype client with a similar campaign in terms or propagation but different in origins and purposes. Here is the original screenshot:

(Translation from Spanish: “this is my favorite picture of you“)
This campaign is born right today and is ongoing too:

An average clicking is also pretty high with more than 2k clicks per hour. Most of potential victims live in Italy then Russia, Poland, Costa Rica, Spain, Germany, Ukraine and others.
The initial dropper is downloaded from a server located in India. The detection rate on VirusTotal is low. Once the machine is infected it drops to the system many other pieces of malware. Downloads come from the Hotfile.com service. At the same time the malware connects to its C2 server located in Germany.

The IP address of C2 is 213.165.68.138:9000
So what does malware do? To be honest many things but one of the most interesting is it turns the infected machine to a slave of the bitcoin generator. The usage of CPU grows up significantly. Here is an example:

The mentioned process runs with the command “bitcoin-miner.exe -a 60 -l no -o http://suppp.cantvenlinea.biz:1942/ -u [email protected] -p XXXXXXXX” (sensitive data was replaced by XXXXXX) It abuses the CPU of infected machine to mine Bitcoins for the criminal.
As I said the campaign is quite active. If you see your machine is working hard, using all available CPU resources, you may be infected.
The initial dropper is detected by Kaspersky as Trojan.Win32.Jorik.IRCbot.xkt.
Follow me on twitter: @dimitribest
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/skypemageddon-by-bitcoining/57591/