Lemon_Duck cryptominer targets cloud apps & Linux
Lemon_Duck cryptominer targets cloud apps & Linux
The Lemon Duck cryptominer is one of the more advanced types of cryptojacker payloads. Its creators continuously update the code with new threat vectors and obfuscation techniques to evade detection, and the miner itself is “fileless,” meaning it remains memory resident and leaves no trace of itself on the victim’s filesystem.
Indicator Of Compromise(IOC)
Domain:
d.ackng.com
lplp.ackng.com
t.amynx.com
t.jdjdcjq.top
t.zer9g.com
t.zz3r0.com
lplp.ackng.com:444
p.b69kq.com:443
p.k3qh4.com:443
IP:
167.71.87.85
Port:
65529
URLs:
hxxp://167.71.87.85/20.dat?$params
hxxp://d.ackng.com/if_mail.bin?$params
hxxp://d.ackng.com/kr.bin?$params
hxxp://d.ackng.com/ln/xr.zip
hxxp://d.ackng.com/m6.bin?$params
hxxp://d.ackng.com/m6g.bin?$params
hxxp://d.ackng.com/nvd.zip
hxxp://d.ackng.com/ode.bin?$params
hxxp://t.amynx.com/7p.php?0.8*ipc*%username%*%computername%*+[Environment]::OSVersion.version.Major
hxxp://t.amynx.com/a.jsp?[attack_vector]_20200820&%username%+%computername%+UUID+random_no
hxxp://t.amynx.com/eb.jsp?0.8*%username%*%computername%
hxxp://t.amynx.com/ebo.jsp?0.8*%username%*%computername%
hxxp://t.amynx.com/ipc.jsp?0.8
hxxp://t.amynx.com/ipco.jsp?0.8
hxxp://t.amynx.com/ln/a.asp?src_date_*whoami*hostname*guid
hxxp://t.amynx.com/ln/core.png?0.8*ssh*whoami*hostname
hxxp://t.amynx.com/ln/core.png?0.8*ssho*whoami*hostname
hxxp://t.amynx.com/ln/core.png?rds
hxxp://t.amynx.com/ln/core.png?rdso
hxxp://t.amynx.com/ln/core.png?yarn
hxxp://t.amynx.com/ln/core.png?yarno
hxxp://t.amynx.com/ms.jsp?0.8*%computername%
hxxp://t.amynx.com/mso.jsp?0.8*%computername%
hxxp://t.amynx.com/rdp.jsp
hxxp://t.amynx.com/rdpo.jsp
hxxp://t.amynx.com/smgh.jsp?0.8*%computername%
hxxp://t.amynx.com/smgho.jsp?0.8*%computername%
hxxp://t.amynx.com/usb.jsp?0.8*%computername%
hxxp://t.jdjdcjq.top/ln/a.asp?src_date_*whoami*hostname*guid
Comments
Post a Comment