PULSE NAME
Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows
WHITE Iron Group AlienVault 2018-09-17 Modified: 2018-09-17
42
IOCs
MEDIUM VOLUME
A new malware family is targeting Linux and Microsoft Windows servers. We can tie this malware, which we have named Xbash, to the Iron Group, a threat actor group known for previous ransomware attacks. Xbash has ransomware and coinmining capabilities. It also has self-propagating capabilities (meaning it has worm-like characteristics similar to WannaCry or Petya/NotPetya). It also has capabilities not currently implemented that, when implemented, could enable it to spread very quickly within an organizations’ network (again, much like WannaCry or Petya/NotPetya). Xbash spreads by attacking weak passwords and unpatched vulnerabilities. Xbash is data-destructive; destroying Linux-based databases as part of its ransomware capabilities. We can also find no functionality within Xbash that would enable restoration after the ransom is paid. This means that, similar to NotPetya, Xbash is data destructive malware posing as ransomware.
Indicators of Compromise (15 / 42 total)
All FileHash-SHA256 CVE URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 09968c4573580398b3269577ced28090eae4a7c326c1a0ec546761c623625885 2018-09-17
FileHash-SHA256 0b9c54692d25f68ede1de47d4206ec3cd2e5836e368794eccb3daa632334c641 2018-09-17
FileHash-SHA256 31155bf8c85c6c6193842b8d09bda88990d710db9f70efe85c421f1484f0ee78 2018-09-17
FileHash-SHA256 5b790f02bdb26b6b6b270a5669311b4f231d17872aafb237b7e87b6bbb57426d 2018-09-17
FileHash-SHA256 725efd0f5310763bc5375e7b72dbb2e883ad90ec32d6177c578a1c04c1b62054 2018-09-17
FileHash-SHA256 7a18c7bdf0c504832c8552766dcfe0ba33dd5493daa3d9dbe9c985c1ce36e5aa 2018-09-17
FileHash-SHA256 a27acc07844bb751ac33f5df569fd949d8b61dba26eb5447482d90243fc739af 2018-09-17
FileHash-SHA256 d7fbd2a4db44d86b4cf5fa4202203dacfefd6ffca6a0615dca5bc2a200ad56b6 2018-09-17
FileHash-SHA256 dbc380cbfb1536dfb24ef460ce18bccdae549b4585ba713b5228c23924385e54 2018-09-17
FileHash-SHA256 dcd37e5b266cc0cd3fab73caa63b218f5b92e9bd5b25cf1cacf1afdb0d8e76ff 2018-09-17
FileHash-SHA256 de63ce4a42f06a5903b9daa62b67fcfbdeca05beb574f966370a6ae7fd21190d 2018-09-17
FileHash-SHA256 e59be6eec9629d376a8a4a70fe9f8f3eec7b0919019f819d44b9bdd1c429277c 2018-09-17
FileHash-SHA256 ece3cfdb75aaabc570bf38af6f4653f73101c1641ce78a4bb146e62d9ac0cd50 2018-09-17
FileHash-SHA256 f808a42b10cf55603389945a549ce45edc6a04562196d14f7489af04688f12bc 2018-09-17
FileHash-SHA256 f888dda9ca1876eba12ffb55a7a993bd1f5a622a30045a675da4955ede3e4cb8 2018-09-17