""ET POLICY Crypto Coin Miner Login""

SID: 2022886

Revision: 3

Class Type: trojan-activity

Metadata: affected_product Any, attack_target Client_Endpoint, created_at 2016_06_09, deployment Perimeter, malware_family CoinMiner, performance_impact Low, signature_severity Informational, tag Bitcoin_Miner, updated_at 2017_06_16

Reference:

  • md5

  • ebe1aeb5dd692b222f8cf964e7785a55

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: to_server,established

Contents:

  • Value: "|7b 22|method|22 3a|" Depth: 10

  • Value: "|22|login|22 2c|"

  • Value: "|22|params|22 3a|"

  • Value: "|7b 22|login"

  • Value: "agent|22 3a|"

Within: 8

PCRE:

Special Options:

  • fast_pattern

  • nocase

  • nocase

source