WinstarNssmMiner
Malware

45f6ca06-eec3-4ffc-9a71-7659da5cd9f7

 

WinstarNssmMiner is brutal code as it will crash victim PCs the moment antivirus products detect and attempt to remove it.

The cryptominer launches the svchost.exe process — used to manage system services — and injects malicious code into the file. One injected process begins mining cryptocurrency while the other runs in the background to avoid detection and scan for antivirus protection.

Source: ZDNet

How do you protect yourself?

Proper security measures must be in place to defend against WinstarNssmMiner malware and similar threats. Having proper up-to-date endpoint and firewall security provides a cross-generational blend of threat defense techniques to protect systems from cryptocurrency-mining malware.

 

CVE
2018-0222

Threat Meter

 

A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by using an administrative account that has default, static user credentials.

The vulnerability is due to the presence of undocumented, static user credentials for the default administrative account for the affected software. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands with root privileges.

Source: Cisco

How do you protect yourself?

Ensure your software is up-to-date and that you have proper firewall and endpoint systems setup within your network.

 

Bip Dharma
Ransomware

Threat Meter

 

This new version of Dharma Ransomware will append the .Bip extension to encrypted files. It is not known exactly how this variant is being distributed, but in the past Dharma is typically spread by hacking into Remote Desktop Services and manually installing the ransomware.

When the Bip ransomware variant is installed, it will scan a computer for data files and encrypt them. When encrypting a file it will append an extension in the format of .id-[id].[email].bip.

Source: BleepingComputer

How do you protect yourself?

Proper security measures must be in place to defend against Bip Dharma Ransomware and similar threats. Having proper up-to-date endpoint security provides a cross-generational blend of threat defense techniques to protect systems from cryptocurrency-mining malware.