Rewterz
Rewterz threat Alert – Malspam NanoCore RAT Malware – IoCs
March 11, 2019
Rewterz
Rewterz Threat Alert – Pots Ransomware Campaign – IoCs
March 12, 2019

Rewterz threat Alert – SpeakUp Malware Infecting Linux Devices

Severity

Medium

Analysis Summary

The primary purpose of the SpeakUp malware appears to be to spread Bitcoin miners to as many Linux devices operating on the public Internet as possible, for financial gain via Bitcoin mining.

Impact

  • Malware infection.
  • Exposure of sensitive information.
  • Execution of shell commands. 

Indicators of Compromise

IP(s) / Hostname(s) 143.95.250[.]212
5.196.70[.]86
5.2.73[.]127
67.209.177[.]163
URLs linuxservers.000webhostapp[.]com
linuxsrv134.xp3[.]biz
speakupomaha[.]com
Malware Hash (MD5/SHA1/SH256) 2c08897bcd51cb5cd6a86a72186b2c6c4a1a7a632bdc40998e724a237c8a45af

Affected Vendors

Linux

Remediation

  • Maintain up-to-date antivirus signatures and engines.
  • Keep operating system patches up-to-date.
  • Exercise caution when opening e-mail attachments even if the attachment is expected and the sender appears to be known.