COINMINER_MALXMR.BB-ELF32
RDN/ADB.Miner (McAfee); Andr/AdbMiner-A (Sophos); ELF:BitCoinMiner-CM [Trj] (Avast)
Android
Threat Type: Coinminer
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Coinminer arrives as a component bundled with malware/grayware packages.
TECHNICAL DETAILS
165,528 bytes
ELF
No
07 Feb 2018
Drops files
Arrival Details
This Coinminer arrives as a component bundled with malware/grayware packages.
Installation
This Coinminer drops and executes the following files:
- /data/local/tmp/droidbot -> detected as Coinminer_MALXMR.B-ELF32
- /data/local/tmp/invoke.sh -> used to grant permissions in replacing system files
- /data/local/tmp/ddexe
- /data/local/tmp/debuggerd
- /data/local/tmp/install-recovery.sh
- /data/local/tmp/xmrig32 -> detected as Coinminer_MALXMR.BA-ELF32
- /data/local/tmp/xmrig64 -> detected as Coinminer_MALXMR.BA-ELF64
- /data/local/tmp/config.json -> detected as Coinminer_MALXMR.B-CFG
Other Details
This Coinminer does the following:
- It uses nohup to continue execution even if the terminal is closed.
- It decrypts the following file to be used as the contents of its drop files:
- bot.dat -> detected as Coinminer_MALXMR.BC-CFG
SOLUTION
9.850
13.968.04
15 Feb 2018
13.969.00
16 Feb 2018
Step 1
Trend Micro Mobile Security Solution
Trend Micro Mobile Security Personal Edition protects Android and iOS smartphones and tablets from malicious and Trojanized applications. It blocks access to malicious websites, increase device performance, and protects your mobile data. You may download the Trend Micro Mobile Security apps from the following sites:
Step 2
Remove unwanted apps on your Android mobile device
Did this description help? Tell us how we did.