Concrete signature match: Trojan - Appears legitimate but performs malicious actions for 64-bit Windows platform, family Coinminer
This threat is a trojan identified as a cryptocurrency miner for 64-bit Windows systems. It secretly utilizes the infected machine's CPU and GPU resources to mine cryptocurrency for the attacker, leading to significant performance degradation and increased power consumption.
No specific strings found for this threat
rule Trojan_Win64_Coinminer_RB_2147896802_0
{
meta:
author = "threatcheck.sh"
detection_name = "Trojan:Win64/Coinminer.RB!MTB"
threat_id = "2147896802"
type = "Trojan"
platform = "Win64: Windows 64-bit platform"
family = "Coinminer"
severity = "Critical"
info = "MTB: Microsoft Threat Behavior"
signature_type = "SIGNATURE_TYPE_PEHSTR_EXT"
threshold = "1"
strings_accuracy = "High"
strings:
$x_1_1 = {41 89 c2 41 83 e2 1f 45 32 0c 12 44 88 0c 07 48 ff c0 48 39 c6 74 ac} //weight: 1, accuracy: High
condition:
(filesize < 20MB) and
(all of ($x*))
}9d140474f1c6b998cffc94ec840ca6b9b91f82b390fb64c10e18bfb559958f541ebcfddad6ca2b49edfeacdfb3e9f074333729b965d637aa44ecb8df3626efe9d335a352595cd376587cc3e071b6fdaa58b1e8f5e193f090d679e36cda054b66c28c65b7f30c1ed7af879a7aa2b6aa8b1f8e54775ed847d0655a8d7bb2f939c7f930afd78b0f26099dc7bf8170ebb7c0514e4100f72720ae711bf7251b15377cIsolate the affected system from the network. Use an updated antivirus tool, such as Windows Defender, to perform a full system scan and remove the threat. Investigate and eliminate any persistence mechanisms (e.g., scheduled tasks, services) and identify the initial infection vector to prevent re-occurrence.