2018-01-11 - RIG EK SENDS SMOKELOADER (SHARIK/DOFOIL) AND MONERO COIN MINER

NOTICE:

ASSOCIATED FILES:

 

WEB TRAFFIC BLOCK LIST

Indicators are not a block list.  If you feel the need to block web traffic, I suggest the following domain and URL:

 

EMAILS


Shown above:  Traffic from the infection filtered in Wireshark.

 

RIG EK:

URLS TO NON-MALICIOUS DOMAINS GENERATED BY SMOKELOADER (SHARIK/DOFOIL):

URLS TO MALICIOUS DOMAINS GENERATED BY SMOKELOADER (SHARIK/DOFOIL):

MONERO (XMR) COIN MINER ACTIVITY:

 


Shown above:  Some alerts on the infection traffic from the Snort subscriber ruleset when reading the pcap with Snort 2.9.11.

 


Shown above:  Some alerts from Sguil in Security Onion using Suricata and the EmergingThreats Pro (ETPRO) ruleset.

 

FILE HASHES

RIG EK FLASH EXPLOIT SEEN ON 2018-01-11:

RIG EK PAYLOAD - SMOKELOADER (ALSO CALLED "SHARIK" OR "DOFOIL"):

FOLLOW-UP MALWARE - MONERO (XMR) COIN MINER:

 

Click here to return to the main page.