da_667 · @da_667
3097 followers · 235 posts · Server infosec.exchange

Found this in our threat feed:
trendmicro.com/content/dam/tre

Trend Micro found a campaign with chaos rat dropping XMRIG miners it looks like? The blog post is gone, but the file hashes and IOCs are still there. It looks like we have some coverage via:

2024897 ET USER_AGENTS Go HTTP Client User-Agent

2037145 ET MALWARE Win32/Khaosz.A!MTB Checkin

Of course the Go HTTP Client User-Agent rule is very generic coverage for software using the Go language HTTP library default user-agent. More often than not, that warrants looking at (hunting) but the results may not necessarily be malicious.

#malware #threatintel #iocs #iocsharing #snort #suricata #cryptojacking #chaosrat

Last updated 3 years ago