Rudeminer, Blacksquid and Lucifer Walk into a Bar

 

 Rudeminer, Blacksquid and Lucifer Walk into a Bar

 

Lucifer is a Windows crypto miner and DDOS hybrid malware and started as a miner with self-spreading capabilities that targeted the Windows system. Now it evolved into a multi-platform and multi-architecture malware targeting Linux, and IoT devices as well. It targets over 25 organizations in the US, Ireland, the Netherlands Turkey, and India. Attacks have come from a variety of domains including manufacturing, legal, insurance, and the banking industry.
The current main attack vector for IoT devices is through the exploitation of the vulnerability known as CVE-2018-10561, which targets unpatched Dasan GPON router devices. The malware has several capabilities: multiple types of DDOS attacks, full command-and-control operations able to download and execute files, remote command execution, Monero mining using the Xmrig miner, and self-spreading in Windows systems through various exploitation techniques.

Indicators of Compromise

Domains
guyeyuyu[.]com
qianduoduo[.]pw
qf2020[.]top
tyz2020[.]top

IP

122[.]112[.]179[.]189

File Hash

Linux samples:

53c2a0f3c3775111cbf8c09cd685e44a434bdd2d4dc0b9af18266083fb4b41e8 82934ed1f42986bdad8e78049e27fcb0b8e43a5b0b9332aa913b901c7344cbc6 ebcaed78aab7b691735bb33d5c33dd6dd447a0a538ff84d0d115c2b35831d43d d9f1878b029202195e0aeefb8406ea13d1ed57f8042636858dfd71f204ca0b05 7caf6f673d224effa207c3b3f9a0ce65eabe60230fbc70e52091f0e2f3c1f09c bcdadf4930abab3773df1c184fd2b6fa34b5cb8543177d76daf2b9f7c1f36c4f ECA3E0DE0A9FA7CAC75617C57839E7D62C53E4690483C08A849E624A2C79D8D9 49A8F1F9A771283771E5733EF05C3D525806318EEC7C82A049EE2B05B4259204

ARM sample:

3ea56bcf897cb8909869e1bfc35f47e1c8a454dd891c5396942c1255aa09b0ce

Monero wallets:

ז44ygo7VfwEYdEbe1ruyZNLfrV19snk3REQpfb5LU9Yxf98z7Ws9EZPPbUgvozZyfYXCb3vsRJRT8wTGe3FipsLb93NaDULN 45sep79Asuwcjz8dLTu7XtJBTX7yYf7uo6qT9ymFBQXv8gjZsDPyd46Hoh6DM8pAXkLnsw9U7veZWU1DqMjKRoryAn3zEq1 43VqbHtuooiNC8rMEeoiB6LzUTyBfPaup3DxAUxRxmqo2fGRDGkyzx68ehdh43Zbn5LHwdFAcztskQW2bAoxMtm9NwJDi7R 4AfAd5hsdMWbuNyGbFJVZjcMLeKHvrXnT155DWh8qGkYRPbVGKBT9q1Z5gcFXqmwUuh2Kh6t2sTnHXPysYrGf2m9KqBwz9e 48S6vZmW26kCchf44dmbkQY87iVBZ9hkuVaRjyFniWVcS8gSUKjcgPUWFUp7z9WwVx7FkMP2iGUEFLpGQdTjip5U6NEBpA6

Comments

Popular posts from this blog

Revil Ransomware Targeted Kaseya

BANDOOK(RAT)

Buer Loader provides malware-as-a-service