Potential Coin Miner Execution


Description

This rule detects the execution of a coin miner through potential mining commandline arguments. Adversaries may leverage the resources of compromised systems to mine cryptocurrency, to generate revenue. This activity may impact system performance and availability.

Query · eql

process where event.type == "start" and event.action == "exec" and (
  process.name like (
    "telnet.netkit", "ping", "telnet", "xmrig", "dash", "bash", "sh", "zsh", "ash", "fish", "ksh", "tcsh",
    "csh", "nohup", "pgrep", "python*", "perl*", "ruby*", "php*", "lua*", "sed", "pkill", "docker", "dig",
    "nslookup", "inetutils-telnet", "nc", "ncat", "netcat", "netcat.openbsd", "netcat.traditional",
    "nc.openbsd", "nc.traditional", "curl", "wget", "sudo", "grep", ".*"
  ) or
  process.executable like (
    "/tmp/*", "/var/tmp/*", "/dev/shm/*", "/boot/*", "./*", "/sys/*", "/lost+found/*", "/media/*", "/proc/*",
    "/var/backups/*", "/var/log/*", "/var/mail/*", "/var/spool/*"
  )
) and
(
  (
    (
      (
        process.args in ("-a", "--algo") and process.args in (
          "gr", "rx/graft", "cn/upx2", "argon2/chukwav2", "cn/ccx", "kawpow", "rx/keva", "cn-pico/tlo", "rx/sfx", "rx/arq",
          "rx/0", "argon2/chukwa", "argon2/ninja", "rx/wow", "cn/fast", "cn/rwz", "cn/zls", "cn/double", "cn/r", "cn-pico",
          "cn/half", "cn/2", "cn/xao", "cn/rto", "cn-heavy/tube", "cn-heavy/xhv", "cn-heavy/0", "cn/1", "cn-lite/1",
          "cn-lite/0", "cn/0"
        )
      ) or
      process.args in ("--nicehash", "--hash", "--seed") or
      (
        process.args == "--coin" and process.args in ("monero", "arqma", "dero")
      )
    ) and process.args in ("-o", "--url")
  ) or
  process.command_line like ("*stratum+tcp://*", "*stratum2+tcp://*")
) and not (
  process.parent.executable like "/var/cache/sensu/sensu-agent/*" or
  process.name in ("grep", "xargs")
)
Raw source Potential Coin Miner Execution · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = """
This rule detects the execution of a coin miner through potential mining commandline arguments. Adversaries may leverage
the resources of compromised systems to mine cryptocurrency, to generate revenue. This activity may impact system
performance and availability.
"""
id = "0259c937-877f-4140-a67b-dc51298f3f86"
license = "Elastic License v2"
name = "Potential Coin Miner Execution"
os_list = ["linux"]
reference = ["https://xmrig.com/docs/algorithms"]
version = "1.0.7"

query = '''
process where event.type == "start" and event.action == "exec" and (
  process.name like (
    "telnet.netkit", "ping", "telnet", "xmrig", "dash", "bash", "sh", "zsh", "ash", "fish", "ksh", "tcsh",
    "csh", "nohup", "pgrep", "python*", "perl*", "ruby*", "php*", "lua*", "sed", "pkill", "docker", "dig",
    "nslookup", "inetutils-telnet", "nc", "ncat", "netcat", "netcat.openbsd", "netcat.traditional",
    "nc.openbsd", "nc.traditional", "curl", "wget", "sudo", "grep", ".*"
  ) or
  process.executable like (
    "/tmp/*", "/var/tmp/*", "/dev/shm/*", "/boot/*", "./*", "/sys/*", "/lost+found/*", "/media/*", "/proc/*",
    "/var/backups/*", "/var/log/*", "/var/mail/*", "/var/spool/*"
  )
) and
(
  (
    (
      (
        process.args in ("-a", "--algo") and process.args in (
          "gr", "rx/graft", "cn/upx2", "argon2/chukwav2", "cn/ccx", "kawpow", "rx/keva", "cn-pico/tlo", "rx/sfx", "rx/arq",
          "rx/0", "argon2/chukwa", "argon2/ninja", "rx/wow", "cn/fast", "cn/rwz", "cn/zls", "cn/double", "cn/r", "cn-pico",
          "cn/half", "cn/2", "cn/xao", "cn/rto", "cn-heavy/tube", "cn-heavy/xhv", "cn-heavy/0", "cn/1", "cn-lite/1",
          "cn-lite/0", "cn/0"
        )
      ) or
      process.args in ("--nicehash", "--hash", "--seed") or
      (
        process.args == "--coin" and process.args in ("monero", "arqma", "dero")
      )
    ) and process.args in ("-o", "--url")
  ) or
  process.command_line like ("*stratum+tcp://*", "*stratum2+tcp://*")
) and not (
  process.parent.executable like "/var/cache/sensu/sensu-agent/*" or
  process.name in ("grep", "xargs")
)
'''

min_endpoint_version = "7.15.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[actions]]
action = "kill_process"
field = "process.parent.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1059"
name = "Command and Scripting Interpreter"
reference = "https://attack.mitre.org/techniques/T1059/"
[[threat.technique.subtechnique]]
id = "T1059.004"
name = "Unix Shell"
reference = "https://attack.mitre.org/techniques/T1059/004/"



[threat.tactic]
id = "TA0002"
name = "Execution"
reference = "https://attack.mitre.org/tactics/TA0002/"
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1496"
name = "Resource Hijacking"
reference = "https://attack.mitre.org/techniques/T1496/"


[threat.tactic]
id = "TA0040"
name = "Impact"
reference = "https://attack.mitre.org/tactics/TA0040/"

[internal]
min_endpoint_version = "7.15.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.