• About
  • Contact
  • DMCA
  • Terms and Conditions
  • Privacy Policy
Altcoin Central
News for the Crypto Community
  • Bitcoin
  • Ripple
  • Crypto
  • Blockchain
  • Mining
  • About
  • Contact

Linux_headpic.jpg

Mining

New SHC-compiled Linux malware installs cryptominers, DDoS bots

admin January 4, 2023

Tweet

, 2023-01-04 16:29:46,

Contents hide
1 Stealthy loading
2 Dropping numerous payloads

A new Linux malware downloader created using SHC (Shell Script Compiler) has been spotted in the wild, infecting systems with Monero cryptocurrency miners and DDoS IRC bots.

According to ASEC researchers, who discovered the attack, the SHC loader was uploaded to VirusTotal by Korean users, with attacks generally focused on Linux systems in the same country.

The analysts say the attacks likely rely on brute-forcing weak administrator account credentials over SSH on Linux servers.

Stealthy loading

SHC is a “generic shell script compiler” for Linux, able to convert Bash shell scripts into ELF (Linux and Unix executables) files.

Malicious Bash shell scripts used by threat actors typically contain system commands, which can be detected by security software installed on a Linux device.

As scripts in SHC ELF executables are encoded using the RC4 algorithm, the malicious commands are not as easily seen by the security software, potentially allowing the malware to evade detection.

Part of a decoded Bash shell script
Part of a decoded Bash shell script
Source: ASEC

Dropping numerous payloads

When the SHC malware downloader is executed, it will fetch multiple other malware payloads and install them on the device.

One of the payloads is an XMRig miner that is downloaded as a TAR archive from a remote URL and extracted to “/usr/local/games/” and executed.

The archive also contains the “run” script and the miner’s configuration file, which points to the configured mining pool.

Contents of the TAR archive
Contents of the TAR…

,
To read the original article from news.google.com, Click here

PIA Logo Private Internet Access gives you unparalleled access to thousands of next-gen servers in over 83 countries and each US state. Your VPN experience will always be fast, smooth, and reliable.

Related Posts

leather-3080553_960_720.jpg

Mining /

New Staking Requirements for Utopia Mining Nodes – Press release Bitcoin News

bitcoin-3171918_960_720.jpg

Mining /

A Critical Test for Bitcoin 40% Rally

bitcoin-3662726_960_720.jpg

Mining /

Bitcoin mining advocate is going state-to-state to educate US lawmakers

‹ Blockchain 101: All the Basics Explained › Cryptoassets: Beyond the Hype

Categories

  • Bitcoin (2,246)
  • Blockchain (1,196)
  • Crypto (1,735)
  • Mining (1,462)
  • Ripple (747)




Back to Top

Legal Stuff

  • DMCA
  • Privacy Policy
  • Terms and Conditions
Hostinger logo

Categories

  • Bitcoin
  • Blockchain
  • Crypto
  • Mining
  • Ripple
  • Altcoin Central – Latest news on Cryptocurrencies all in one place.
  • About
  • Contact
Copyright 2023 4 Hat LLC

DMCA - Terms and Conditions - Privacy Policy