Potential Coin Miner Execution via Shell


Description

This rule detects the execution of a coin miner via a shell command through potential mining commandline arguments. Adversaries may leverage the resources of compromised systems to mine cryptocurrency, to generate revenue. This activity may impact system performance and availability.

Query · eql

process where event.type == "start" and event.action == "exec" and process.parent.executable != null and
process.name in ("bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish") and process.args == "-c" and (
  (
    process.command_line like ("*-a*", "*--algo*", "*--coin*") and process.command_line like (
      "*monero*", "*arqma*", "* dero *", "*rx/graft*", "*cn/upx2*", "*cn/1*", "*cn-lite/1*", "*cn-lite/0*", "*cn/0*",
      "*argon2/chukwav2*", "*cn/ccx*", "*kawpow*", "*rx/keva*", "*cn-pico/tlo*", "*rx/sfx*", "*rx/arq*", "*rx/0*",
      "*argon2/chukwa*", "*argon2/ninja*", "*rx/wow*", "*cn/fast*", "*cn/rwz*", "*cn/zls*", "*cn/double*", "*cn/r*",
      "*cn-pico*", "*cn/half*", "*cn/2*", "*cn/xao*", "*cn/rto*", "*cn-heavy/tube*", "*cn-heavy/xhv*", "*cn-heavy/0*"
    )
  ) or process.command_line like ("*stratum+tcp://*", "*stratum2+tcp://*", "*--nicehash*") 
) and not (
  process.parent.name like (
    "find", "python3", "httpd", "sshd", "php*", "sudo", "ruby", "nvim", "vim", "make", "schroot", "vimdiff", "sbuild", "ninja"
  ) or
  process.parent.executable in (
    "/opt/cron/registry-sync/ru/syncRegistryByReport.pl",  "/usr/bin/gvimdiff", "/usr/bin/ninja-reference",
    "/usr/bin/sw-engine", "/usr/local/bin/teleport", "/usr/share/dotnet/dotnet", "/usr/libexec/openssh/sshd-session"
  ) or
  process.parent.executable like ("/tmp/baum/easybuild/*", "/home/*/.vscode-server/extensions/*/resources/native-binary/claude") or
  process.command_line like ("*openssl*", "*--display-charset*", "sh -c aws s3 cp*") or
  process.parent.args in ("/usr/bin/crun", "/usr/local/bin/claude") or
  (
    process.parent.executable like "/home/*/.local/share/claude/versions/*" and
    process.command_line like "/bin/bash -c source /home/*/.claude/shell-snapshots/snapshot-*"
  )
)
Raw source Potential Coin Miner Execution via Shell · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = """
This rule detects the execution of a coin miner via a shell command through potential mining commandline arguments.
Adversaries may leverage the resources of compromised systems to mine cryptocurrency, to generate revenue. This activity
may impact system performance and availability.
"""
id = "e5149069-189b-4b1a-ad24-9fed16f5a15b"
license = "Elastic License v2"
name = "Potential Coin Miner Execution via Shell"
os_list = ["linux"]
reference = ["https://xmrig.com/docs/algorithms"]
version = "1.0.12"

query = '''
process where event.type == "start" and event.action == "exec" and process.parent.executable != null and
process.name in ("bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish") and process.args == "-c" and (
  (
    process.command_line like ("*-a*", "*--algo*", "*--coin*") and process.command_line like (
      "*monero*", "*arqma*", "* dero *", "*rx/graft*", "*cn/upx2*", "*cn/1*", "*cn-lite/1*", "*cn-lite/0*", "*cn/0*",
      "*argon2/chukwav2*", "*cn/ccx*", "*kawpow*", "*rx/keva*", "*cn-pico/tlo*", "*rx/sfx*", "*rx/arq*", "*rx/0*",
      "*argon2/chukwa*", "*argon2/ninja*", "*rx/wow*", "*cn/fast*", "*cn/rwz*", "*cn/zls*", "*cn/double*", "*cn/r*",
      "*cn-pico*", "*cn/half*", "*cn/2*", "*cn/xao*", "*cn/rto*", "*cn-heavy/tube*", "*cn-heavy/xhv*", "*cn-heavy/0*"
    )
  ) or process.command_line like ("*stratum+tcp://*", "*stratum2+tcp://*", "*--nicehash*") 
) and not (
  process.parent.name like (
    "find", "python3", "httpd", "sshd", "php*", "sudo", "ruby", "nvim", "vim", "make", "schroot", "vimdiff", "sbuild", "ninja"
  ) or
  process.parent.executable in (
    "/opt/cron/registry-sync/ru/syncRegistryByReport.pl",  "/usr/bin/gvimdiff", "/usr/bin/ninja-reference",
    "/usr/bin/sw-engine", "/usr/local/bin/teleport", "/usr/share/dotnet/dotnet", "/usr/libexec/openssh/sshd-session"
  ) or
  process.parent.executable like ("/tmp/baum/easybuild/*", "/home/*/.vscode-server/extensions/*/resources/native-binary/claude") or
  process.command_line like ("*openssl*", "*--display-charset*", "sh -c aws s3 cp*") or
  process.parent.args in ("/usr/bin/crun", "/usr/local/bin/claude") or
  (
    process.parent.executable like "/home/*/.local/share/claude/versions/*" and
    process.command_line like "/bin/bash -c source /home/*/.claude/shell-snapshots/snapshot-*"
  )
)
'''

min_endpoint_version = "7.15.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[actions]]
action = "kill_process"
field = "process.parent.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1059"
name = "Command and Scripting Interpreter"
reference = "https://attack.mitre.org/techniques/T1059/"
[[threat.technique.subtechnique]]
id = "T1059.004"
name = "Unix Shell"
reference = "https://attack.mitre.org/techniques/T1059/004/"



[threat.tactic]
id = "TA0002"
name = "Execution"
reference = "https://attack.mitre.org/tactics/TA0002/"
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1496"
name = "Resource Hijacking"
reference = "https://attack.mitre.org/techniques/T1496/"


[threat.tactic]
id = "TA0040"
name = "Impact"
reference = "https://attack.mitre.org/tactics/TA0040/"

[internal]
min_endpoint_version = "7.15.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.