W32/CoinMiner.AKE!tr

description-logoAnalysis



W32/CoinMiner.AKE!tr is a generic detection for a Miner trojan. Since this is a generic detection, this malware may have varying behaviour.
Below are some of its observed characteristics/behaviours:

  • This malware may drop any of the following file(s):
    • C:\log\32.exe : This file is detected as VBS/BitMin.AA!tr
    • C:\ProgramData\Windows\[Random]_log.txt : This file is a log file that shows it is trying to connect to xmr.pool.miner{Removed}.com
    • C:\ProgramData\Windows\csrs.exe : This file will be detected as W32/CoinMiner.AKE!tr.
    • C:\ProgramData\Windows\start.bat : This file is a batch file that may run the file csrs.exe and connect to xmr.pool.miner{Removed}.com
    • C:\ProgramData\Windows\svchost.vbs : This file is a script file that may run the file csrs.exe and connect to xmr.pool.miner{Removed}.com
    • %UserProfile%\Start Menu\Programs\Startup\explorer.lnk : This file is a shortcut to run the file svchost.vbs on startup.

  • This malware may connect to the following site(s):
    • xmr.pool.miner{Removed}.com

  • Some instances of this file are in RAR SFX form.



recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2019-07-30 70.35800 Sig Updated
2019-04-30 68.17800 Sig Updated
2019-04-29 68.14600 Sig Updated
2019-04-12 67.75300 Sig Updated
2019-04-02 67.50600 Sig Updated
2019-03-27 67.36200 Sig Updated
2019-03-20 67.19300 Sig Updated
2019-03-20 67.19200 Sig Updated
2019-03-07 66.88800 Sig Updated
2019-03-07 66.88700 Sig Updated