RSS
Логотип
Баннер в шапке 1
Баннер в шапке 2
2020/09/16 19:16:43

MrbMiner (virus miner)

Content

2020: Infection of thousands of Microsoft SQL Servers

In the middle of September, 2020 it became known of spread of a virus under the name MrbMiner which attacks the Microsoft SQL Server system (MSSQL) and is used for production of cryptocurrencies. Specialists in information security of Tencent Security told about this threat.

According to them, the botnet extends only by scanning of Internet space to the MSSQL servers, and then executes brute force attack (password guessing by search of options), repeatedly trying to use an account of the administrator with weak passwords.

After a purpose compromise attacking load the assm.exe file serving for contact with the managing server, installation of the mechanism of persistence capable to sustain reset and also for adding of a backdoor in the form of an account with the login Default and the password @fg125kjnhn987. At the last stage on a system the application for cryptocurrency mining is loaded.

The MrbMiner virus miner infected thousands of Microsoft SQL Servers
File:Aquote1.png
As a result of monitoring of harmful activity it was succeeded to set a new harmful trojan miner of MrbMiner. Attacking interfered on servers thanks to the weak passwords SQL Server, and then set the malware of assm.exe written on C#, says Tencent Security.
File:Aquote2.png

Researchers noticed interesting feature — though the virus infects only servers running Windows with the Microsoft SQL databases, on the server of management of a botnet there are versions for Linux and for systems on ARM processors.

After the research of purses on which the got coins are listed analysts reported that on a purse for Windows version of a virus about 7 XMR ($630), and on a purse for Linux version — 3.38 XMR ($300) are stored. However, usually malefactors use a set of purses therefore total amounts of the mined cryptocurrency can be much more.[1]

See Also





Notes