Skip to content

Files from the repository are being used in remote code execution crypto mining attacks #4

@FalsePattern

Description

@FalsePattern

I have become aware of a repeat attack attempt on my web server which attempts to run cryptomining installer scripts directly from github servers.
The following screenshot of an apache log shows one of said attacks:
image.png
The attacker is setting the referrer and the user agent to a log4j script, attempting to abuse the well-known Log4J exploit to run a base64 obfuscated chunk of code, which, when decoded, resolves to a script hosted at https://raw.githubusercontent.com/C3Pool/xmrig_setup/master/setup_c3pool_miner.sh
image.png

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions