Lemon_Duck cryptominer targets cloud apps & Linux

 


Lemon_Duck cryptominer targets cloud apps & Linux


The Lemon Duck cryptominer is one of the more advanced types of cryptojacker payloads. Its creators continuously update the code with new threat vectors and obfuscation techniques to evade detection, and the miner itself is “fileless,” meaning it remains memory resident and leaves no trace of itself on the victim’s filesystem.

 Indicator Of Compromise(IOC)

Domain:

d.ackng.com    
lplp.ackng.com    
t.amynx.com    
t.jdjdcjq.top    
t.zer9g.com    
t.zz3r0.com
lplp.ackng.com:444    
p.b69kq.com:443    
p.k3qh4.com:443

IP:

167.71.87.85

Port:

65529

URLs:

hxxp://167.71.87.85/20.dat?$params
hxxp://d.ackng.com/if_mail.bin?$params
hxxp://d.ackng.com/kr.bin?$params
hxxp://d.ackng.com/ln/xr.zip
hxxp://d.ackng.com/m6.bin?$params
hxxp://d.ackng.com/m6g.bin?$params
hxxp://d.ackng.com/nvd.zip
hxxp://d.ackng.com/ode.bin?$params
hxxp://t.amynx.com/7p.php?0.8*ipc*%username%*%computername%*+[Environment]::OSVersion.version.Major
hxxp://t.amynx.com/a.jsp?[attack_vector]_20200820&%username%+%computername%+UUID+random_no
hxxp://t.amynx.com/eb.jsp?0.8*%username%*%computername%
hxxp://t.amynx.com/ebo.jsp?0.8*%username%*%computername%
hxxp://t.amynx.com/ipc.jsp?0.8
hxxp://t.amynx.com/ipco.jsp?0.8
hxxp://t.amynx.com/ln/a.asp?src_date_*whoami*hostname*guid
hxxp://t.amynx.com/ln/core.png?0.8*ssh*whoami*hostname
hxxp://t.amynx.com/ln/core.png?0.8*ssho*whoami*hostname
hxxp://t.amynx.com/ln/core.png?rds
hxxp://t.amynx.com/ln/core.png?rdso
hxxp://t.amynx.com/ln/core.png?yarn
hxxp://t.amynx.com/ln/core.png?yarno
hxxp://t.amynx.com/ms.jsp?0.8*%computername%
hxxp://t.amynx.com/mso.jsp?0.8*%computername%
hxxp://t.amynx.com/rdp.jsp
hxxp://t.amynx.com/rdpo.jsp
hxxp://t.amynx.com/smgh.jsp?0.8*%computername%
hxxp://t.amynx.com/smgho.jsp?0.8*%computername%
hxxp://t.amynx.com/usb.jsp?0.8*%computername%
hxxp://t.jdjdcjq.top/ln/a.asp?src_date_*whoami*hostname*guid

Comments

Popular posts from this blog

Revil Ransomware Targeted Kaseya

BANDOOK(RAT)

Buer Loader provides malware-as-a-service