Question

In: Computer Science

– Malware – Your cybersecurity team is finally getting a break after dealing with an outbreak...

– Malware – Your cybersecurity team is finally getting a break after dealing with an outbreak of the new malware W32/CoinMiner hit the corporate network, impacting productivity over the holiday weekend. It was determined this was caused by one of the sales folks who clicked on a “get rich quick” link. The attackers were able to use your company’s computing resources to generate a cryptocurrency mining pool, negatively impacting server performance. As your team is headed home for some much needed rest, your manager pulls you aside.

" I’d really appreciate it if you could do a little research into this whole CoinMiner mess and write up the Security Incident Report for us. Be sure to add in any relevant technical details you can about the file paths or registry keys it may touch as well. Need that report by Tuesday! Have good night!” Complete a 1-2 page assessment of the W32/CoinMiner malware. Be sure to include the specific technical details on the file paths, registry keys, etc. The intent here is that you demonstrate your ability to effectively research and analyze new malware and report up to higher what you have learned.

Solutions

Expert Solution

W32/CoinMiner is a Trojan software. It affects the system resources without letting any user know and mining digital currency. It can cause graphics card and CPU issues. It makes use of the system to generate more numbers of bitcoins and make the system run slower. It can also sometimes enter the system by being bundled inside another set of software.

It drops malicious software in the system and makes the system generate different types of files. There are some library files as well that prevent the proper functioning of the system.

The registry key gets affected in this case just like any other software installation. The processing power of the system is also affected.

It can edit the registry of operating systems incorrectly and make modifications that are irreversible.

It also affects the user accounts because the modifications are reflected in them as well. It is done through registry change. The registry tools and folder options are also disabled. The safe mode is also deleted.

The concept has inspired many others to use coin mining and make money easily. The mining deals with transaction processing in the system with digital currency. Digital ledge records all the newly arrived transactions. This creates a blockchain. When it is not done with permission of the system owner, it is considered illegal.

W32/CoinMiner also does the same without letting the user know or taking permission. The file that is infected doesn't show any signs until number of files get affected. The file that gets affected looks like user-executable version and original file doesn't run. Even when deleted, it is reinfected with the same file.

To avoid being detected, the domains are directed to different addresses and then back to the user's system.


Related Solutions

2. After your frustration with tissue culture, you finally get your cells passaged and decide to...
2. After your frustration with tissue culture, you finally get your cells passaged and decide to set up your cDNA synthesis reaction, PCR, and agarose gel. You have extracted RNA from your cells, and now you need to proceed with the cDNA synthesis. a. The first step is to determine the concentration of your RNA. You dilute your RNA 1:250, vortex it, move it to the cuvette, and run it on the spectrophotometer.   The spec tells you that your concentration...
After spending a year and ​$50,000​, you finally have the design of your new product ready....
After spending a year and ​$50,000​, you finally have the design of your new product ready. In order to start​ production, you will need ​$30,000 in raw materials and you will also need to use some existing equipment that​ you've fully​ depreciated, but which has a market value of ​$100,000. Your colleague notes that the new product could represent 10​% of the​ company's overall sales and that 10​% of overhead is ​$60,000. Your tax rate is 40​%. As you start...
After all of your glorious battles against the common enemy, you finally decide to retire from...
After all of your glorious battles against the common enemy, you finally decide to retire from hack & slash and live peacefully for the rest of your life. You decide to deposit some (1000 gold) of your hard-earned gold to a bank that earns you the most interest for a 20-year period. You have three options to choose from: Bank of Orgrimmar, Bank of Stormwind and Bank of Ironforge. Each of the banks have different payment plans to choose from...
Given the fixed and variable costs your team has identified and agreed upon, compute the break-even...
Given the fixed and variable costs your team has identified and agreed upon, compute the break-even point for this business in either units or dollar sales. Fixed Costs For a Retail Store Selling DVDs Rent - 3,000 a month Insurance - 100 a month Employee Salaries (Unless we have Hourly Employees Let's say 3 Employees working 40 Hours at 13 an hour) - 6,240 / month Loan Payment (For furniture, starting up) 1000 a month Variable Costs Utilities per month...
After getting trounced by your little brother in a children’s game, you suspect the die he...
After getting trounced by your little brother in a children’s game, you suspect the die he gave you to roll may be unfair. To check, you roll it 60 times, recording the number of times each face appears. Do these results cast doubt on the die’s fairness? a) If the die is fair, how many times would you expect each face to show? b) To see if these results are unusual, will you test goodness-of-fit, homogeneity, or independence? c) State...
After a catastrophic failure of your injection mold die, the production team has rebuilt the equipment...
After a catastrophic failure of your injection mold die, the production team has rebuilt the equipment and production is running smoothly again. However, management wants to be sure the quality after the repairs is the same as before. Taking it on faith that σ = 0.030 grams before the failure, you conduct a quick experiment on a batch produced after the failure, and you measure s = 0.036 grams from a random sample of 25 O-rings. a) Based on this...
Back for more O-rings! After a catastrophic failure of your injection mold die, the production team...
Back for more O-rings! After a catastrophic failure of your injection mold die, the production team has rebuilt the equipment and production is running smoothly again. However, management wants to be sure the quality after the repairs is the same as before. Taking it on faith that σ = 0.030 grams before the failure, you conduct a quick experiment on a batch produced after the failure, and you measure s = 0.036 grams from a random sample of 25 O-rings....
Summarize in your own words the article below (300 words) Trivago Ramps Up Finance Team After...
Summarize in your own words the article below (300 words) Trivago Ramps Up Finance Team After Material Weakness By Nina Trentmann Feb 8, 2018 Rolf Schroemgens, co-founder and chief executive officer of Trivago, center, cheers with employees during the company's initial public offering (IPO) in New York, U.S., Dec. 16, 2016. Rolf Schroemgens, co-founder and chief executive officer of Trivago, center, cheers with employees during the company's initial public offering (IPO) in New York, U.S., Dec. 16, 2016. PHOTO: BLOOMBERG...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT