--- name: cryptominer-analysis description: > Analyze cryptocurrency mining malware including XMRig variants, coin miners, and cryptojacking campaigns. Covers mining algorithm identification (CryptoNight/RandomX for Monero, Ethash for Ethereum), Stratum protocol detection, resource usage evasion techniques, process injection for hidden mining, web-based cryptojacking (JavaScript miners), wallet and pool extraction for attribution, and distinguishing legitimate mining from malware. --- # Cryptominer Analysis Analyze cryptocurrency mining malware to identify the mining algorithm, extract wallet addresses and pool configurations, understand evasion techniques, and determine the scope of the infection. ## Prerequisites - **Python 3.10+**: `pefile`, `yara-python`, `json`, `re` - **Tools**: Wireshark/tshark, Process Monitor, Resource Monitor - **Optional**: js-beautify (for web miners), strings, Ghidra - **Environment**: Isolated VM with network monitoring ## Step-by-Step Instructions ### Step 1: Identify the Mining Software Determine which mining software or variant is being used. **Run miner identification:** ```bash python3 scripts/cryptominer_analyzer.py --sample suspicious.exe --mode identify --output miner_id.json ``` **Common mining software:** | Miner | Cryptocurrency | Indicators | |-------|---------------|------------| | XMRig | Monero (XMR) | `xmrig`, `RandomX`, `CryptoNight`, `rx/0` | | T-Rex | ETH/various | `t-rex`, `ethash`, `kawpow` | | PhoenixMiner | ETH | `PhoenixMiner`, `ethash` | | NBMiner | ETH/various | `nbminer`, `ethash` | | Custom | Various | Embedded pool configs, Stratum strings | **Quick identification:** ```bash # Check for common miner strings strings suspicious.exe | grep -iE "(xmrig|cryptonight|randomx|stratum|mining|hashrate|pool)" # Check for mining algorithm constants strings suspicious.exe | grep -iE "(rx/0|cn/r|cn-heavy|ethash|kawpow|equihash)" # Check for Stratum protocol strings suspicious.exe | grep -iE "(stratum\+tcp|stratum\+ssl|mining\.subscribe|mining\.authorize)" ``` ### Step 2: Extract Pool and Wallet Configuration Pull out the mining pool URLs and wallet addresses for attribution. **Extract configuration:** ```bash python3 scripts/cryptominer_analyzer.py --sample suspicious.exe --mode config --output miner_config.json ``` **Manual extraction:** ```bash # Extract Monero wallet addresses (95 characters, starts with 4) strings suspicious.exe | grep -oE "4[0-9AB][1-9A-HJ-NP-Za-km-z]{93}" # Extract Bitcoin addresses strings suspicious.exe | grep -oE "(bc1[a-zA-HJ-NP-Z0-9]{25,39}|[13][a-km-zA-HJ-NP-Z1-9]{25,34})" # Extract pool URLs strings suspicious.exe | grep -iE "stratum\+[a-z]+://[^ ]+" strings suspicious.exe | grep -iE "(pool\.|mining\.|hashvault|nanopool|supportxmr|minexmr)" ``` **Common Monero mining pools:** | Pool | Domain | |------|--------| | SupportXMR | `pool.supportxmr.com` | | MineXMR | `pool.minexmr.com` (closed) | | Nanopool | `xmr.nanopool.org` | | HashVault | `pool.hashvault.pro` | | MoneroOcean | `gulf.moneroocean.stream` | | Unmineable | `rx.unmineable.com` | **Config file locations:** ```bash # XMRig config is often a JSON file find / -name "config.json" -exec grep -l "pool\|wallet\|stratum" {} \; 2>/dev/null # Check for embedded configs in the binary strings suspicious.exe | python3 -c " import sys, json for line in sys.stdin: try: j = json.loads(line.strip()) if 'pool' in str(j).lower() or 'wallet' in str(j).lower(): print(json.dumps(j, indent=2)) except: pass " ``` ### Step 3: Analyze Resource Usage Evasion Understand how the miner hides its CPU/GPU usage. **Evasion analysis:** ```bash python3 scripts/cryptominer_analyzer.py --sample suspicious.exe --mode evasion --output evasion_analysis.json ``` **Common evasion techniques:** | Technique | Description | Indicators | |-----------|-------------|------------| | CPU throttling | Limits to 50-70% CPU | `max-cpu-usage`, `threads` config | | Idle-only mining | Mines only when user is inactive | `GetLastInputInfo`, idle timer | | Process hiding | Hides from Task Manager | Process hollowing, name spoofing | | Periodic pausing | Stops during business hours | Time-of-day checks | | GPU-only mining | Avoids CPU spikes | CUDA/OpenCL only, no CPU threads | | Name mimicking | Process named like system service | `svchost.exe`, `csrss.exe`, `dwm.exe` | **Check for idle detection:** ```bash strings suspicious.exe | grep -iE "(GetLastInputInfo|LASTINPUTINFO|idle|screensaver)" ``` **Check for CPU throttling:** ```bash strings suspicious.exe | grep -iE "(max-cpu|threads|cpu-priority|SetProcessAffinityMask)" ``` ### Step 4: Analyze Process Injection for Hidden Mining Some miners inject into legitimate processes to avoid detection. **Injection analysis:** ```bash python3 scripts/cryptominer_analyzer.py --sample suspicious.exe --mode injection --output injection.json ``` **Common injection targets for mining:** - `svchost.exe` (most common — blends with legitimate instances) - `explorer.exe` - `notepad.exe` (surprising choice, seen in some campaigns) - `dllhost.exe` **Detection approach:** ```bash # Look for injection APIs strings suspicious.exe | grep -iE "(VirtualAllocEx|WriteProcessMemory|CreateRemoteThread|NtCreateThreadEx)" # In a running system, check for unexpected CPU-heavy processes # Legitimate svchost.exe should not use 50%+ CPU ``` ### Step 5: Analyze Stratum Protocol Communication Reverse engineer the mining pool communication. **Capture Stratum traffic:** ```bash python3 scripts/cryptominer_analyzer.py --pcap capture.pcap --mode stratum --output stratum.json ``` **Stratum protocol analysis:** ```bash # Capture mining traffic tshark -r capture.pcap -Y "tcp.payload" -T fields -e tcp.payload | \ xxd -r -p | strings | grep -E "mining\.|method|result" ``` **Stratum protocol messages:** ```json // mining.subscribe - Initial handshake {"id": 1, "method": "mining.subscribe", "params": ["xmrig/6.18.0"]} // mining.authorize - Login with wallet address {"id": 2, "method": "mining.authorize", "params": ["WALLET_ADDRESS.WORKER_NAME", "x"]} // mining.submit - Share submission (proof of work) {"id": 4, "method": "mining.submit", "params": ["WALLET", "JOB_ID", "NONCE", "HASH"]} ``` **Key information to extract:** - Wallet address (from `mining.authorize`) - Worker name (campaign/bot identifier) - Mining software and version (from `mining.subscribe` user agent) - Pool URL (from connection destination) - Algorithm (from job parameters) ### Step 6: Analyze Web-Based Cryptojacking Detect JavaScript-based miners injected into websites. **Analyze web miner:** ```bash python3 scripts/cryptominer_analyzer.py --input suspicious.html --mode web-miner --output webminer.json ``` **Detection in HTML/JavaScript:** ```bash # Look for known mining scripts grep -rnE "(coinhive|coin-hive|cryptonight|CryptoNoter|deepMiner|monerominer)" website_files/ # Look for WebAssembly mining modules grep -rn "WebAssembly\|wasm\|importObject" website_files/*.js # Look for Web Worker usage (background mining) grep -rn "new Worker\|SharedWorker\|postMessage.*hash" website_files/*.js ``` **Known web mining libraries:** | Library | Status | Indicators | |---------|--------|------------| | Coinhive | Dead (2019) | `coinhive.min.js`, `CoinHive.Anonymous` | | CryptoLoot | Dead | `cryptoloot.pro`, `CryptoLoot.Anonymous` | | deepMiner | Active | `deepMiner.js`, `deepMiner.Anonymous` | | WebMinePool | Active | `webminepool.com`, `WMP.Anonymous` | ### Step 7: Distinguish Legitimate from Malicious Mining Assess whether the mining activity is authorized or malware. **Legitimacy indicators:** | Indicator | Legitimate | Malicious | |-----------|-----------|-----------| | User consent | Explicitly installed | No consent, hidden | | Resource usage | Configurable, reasonable | Maxed out, throttled to hide | | Installation | Normal installer, visible | Dropper, injection, no UI | | Process name | Actual miner name | Mimicking system process | | Persistence | Optional, visible | Hidden autostart | | Wallet | User's own wallet | Attacker's wallet | ### Step 8: Extract IOCs and Build Detections Compile indicators for network and endpoint detection. **Generate IOCs:** ```bash python3 scripts/cryptominer_analyzer.py --sample suspicious.exe --mode iocs --output miner_iocs.json ``` **Network detection (Snort/Suricata):** ``` # Detect Stratum protocol alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"Cryptocurrency Mining - Stratum Protocol"; content:"mining.subscribe"; sid:1000001;) alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"Cryptocurrency Mining - Share Submission"; content:"mining.submit"; sid:1000002;) ``` **YARA detection:** ```yara rule XMRig_Miner { strings: $s1 = "stratum+tcp://" ascii $s2 = "mining.subscribe" ascii $s3 = "randomx" ascii nocase $s4 = "cryptonight" ascii nocase $pool1 = "supportxmr.com" ascii $pool2 = "nanopool.org" ascii $pool3 = "hashvault.pro" ascii condition: ($s1 and $s2) or ($s3 or $s4) and any of ($pool*) } ``` ## Output Format ```json { "miner_type": "XMRig", "version": "6.18.0", "cryptocurrency": "Monero (XMR)", "algorithm": "RandomX", "config": { "wallet_address": "4ABc...xyz", "pool_url": "stratum+tcp://pool.supportxmr.com:3333", "worker_name": "worker1", "max_cpu_usage": 70, "threads": 4, "donate_level": 0 }, "evasion": { "cpu_throttling": true, "idle_only": false, "process_injection": true, "target_process": "svchost.exe", "name_spoofing": true }, "persistence": { "method": "scheduled_task", "task_name": "WindowsUpdate" }, "network": { "pool_domains": ["pool.supportxmr.com"], "pool_ips": ["198.51.100.80"], "pool_ports": [3333, 443], "tls": false }, "iocs": { "wallet_addresses": ["4ABc...xyz"], "pool_urls": ["stratum+tcp://pool.supportxmr.com:3333"], "file_hashes": {}, "process_names": ["svchost.exe"], "scheduled_tasks": ["WindowsUpdate"] }, "mitre_attack": ["T1496", "T1055", "T1053.005", "T1036.005"] } ``` ## Tips - Monero is the most common cryptocurrency for malware mining due to its privacy features - XMRig is open-source and the most widely abused miner — many variants exist - Wallet addresses are the best attribution IOC — check mining pool APIs for payout history - Stratum protocol on port 3333 is a strong indicator; some miners use 443 to blend with HTTPS - CPU usage dropping when Task Manager is opened is a classic evasion tell - Some campaigns use proxy pools to hide the actual wallet address - Web-based cryptojacking has declined since Coinhive's shutdown but persists in niche forms - Mining malware often arrives via other malware (loaders, RATs) as a monetization module - Check for XMRig's built-in HTTP API (default port 8080) for monitoring data