Severity
Medium
Analysis Summary
The primary purpose of the SpeakUp malware appears to be to spread Bitcoin miners to as many Linux devices operating on the public Internet as possible, for financial gain via Bitcoin mining.
Impact
- Malware infection.
- Exposure of sensitive information.
- Execution of shell commands.
Indicators of Compromise
| IP(s) / Hostname(s) | 143.95.250[.]212 5.196.70[.]86 5.2.73[.]127 67.209.177[.]163 |
| URLs | linuxservers.000webhostapp[.]com linuxsrv134.xp3[.]biz speakupomaha[.]com |
| Malware Hash (MD5/SHA1/SH256) | 2c08897bcd51cb5cd6a86a72186b2c6c4a1a7a632bdc40998e724a237c8a45af |
Affected Vendors
Linux
Remediation
- Maintain up-to-date antivirus signatures and engines.
- Keep operating system patches up-to-date.
- Exercise caution when opening e-mail attachments even if the attachment is expected and the sender appears to be known.