Skip to content

Latest commit

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

🛡️ Malware Incident Analysis Report

XMRig Cryptocurrency Miner — Forensic Investigation

Threat TypeSeverityStatusAV DetectionVirusTotalType


📋 Table of Contents


📁 Case Overview

FieldDetails
AnalystNiraj
Date of Discovery2025
Date of AnalysisMay 16, 2026
Threat TypeCryptocurrency Miner (Cryptojacker)
Malware FamilyXMRig
Cryptocurrency TargetedMonero (XMR)
SeverityHIGH
Status at DiscoveryACTIVE
LocationC:\Users\niraj\AppData\Roaming\windowshost\
Antivirus Detection (host AV)⚠️ UNDETECTED — evaded the installed antivirus on the victim machine
VirusTotal Reference5379df3d28d8…1bc49bc3

🔍 How It Was Discovered

The malware was not detected by the antivirus running on the host. It was discovered through manual investigation after observing suspicious system behavior:

Upon laptop startup, CPU/memory usage immediately spiked to ~80% before any user applications were opened. This abnormal resource consumption at boot time raised suspicion and triggered a manual investigation.

Investigation Tools Used

ToolPurpose in Investigation
Task ManagerInitial detection — observed unusual high CPU and listed svchost32.exe in the Details tab
Process ExplorerConfirmed svchost32.exe as a non-Microsoft process consuming excessive CPU and memory
AutorunsLocated the persistence entry — WindowsHostService scheduled task pointing to runhidden.vbs
Task SchedulerVerified the persistence trigger and the exact command line
Process MonitorCaptured live Stratum mining traffic from svchost32.exe to a remote pool
TCPViewConfirmed the established outbound TCP connection to the mining pool
RamMapQuantified the memory footprint of svchost32.exe
Notepad / Text EditorInspected runhidden.vbs, config.json, and SHA256SUMS

Investigation Timeline

Step 1 — Symptom Observed Laptop boots with ~80% CPU usage, no user apps open.

Step 2 — Task Manager Suspicious svchost32.exe visible in the Details tab.

Task Manager Details tab listing svchost32.exe

Behaviour: Shows the renamed miner running alongside legitimate svchost.exe instances.
Use case: First visual confirmation that an unknown process is masquerading as a system process.

Step 3 — Process Explorer Inspected the process to see private bytes, working set, and threads.

Process Explorer properties for svchost32.exe

Behaviour:svchost32.exe (PID 35592) holds ~2.45 GB working set with heavy CPU cycles.
Use case: Quantifies the resource theft caused by the miner.

Step 4 — Located the Malware Folder Drilled into AppData\Roaming\windowshost\.

windowshost folder contents

Behaviour: 7 files staged in user AppData — exe, vbs, config, lock, certs, hash list.
Use case: Enumerates every artifact dropped by the attacker.

Step 5 — Inspected runhidden.vbs The hidden launcher used at logon.

runhidden.vbs source code

Behaviour: Launches svchost32.exe with window style 0 (hidden) using WScript.Shell.Run.
Use case: Explains how the miner runs with no visible window or console.

Step 6 — Inspected config.json XMRig configuration with mining pool and wallet.

config.json showing pool and wallet settings

Behaviour: Pool URL pool.supportxmr.com:3333, attacker wallet, tls:false, nicehash:false.
Use case: Extracts the mining pool, wallet address, and protocol IOCs.

Step 7 — Inspected SHA256SUMS Confirms the binary origin.

SHA256SUMS file listing original XMRig hashes

Behaviour: Lists hashes for xmrig.exe, WinRing0x64.sys, config.json, and helper scripts.
Use case: Proves the dropped binary is an official XMRig 6.24.0 build, only renamed.

Step 8 — Process Monitor Built a filter for svchost32.exe / xmrig.exe to capture mining activity.

Process Monitor filter dialog

Behaviour: Includes svchost32.exe and xmrig.exe; excludes windowshost, Procmon, Procexp, Autoruns.
Use case: Documents the exact investigation methodology used to isolate miner events.

Step 9 — Captured Stratum Traffic Live TCP send/receive events to the pool.

Process Monitor showing TCP traffic to mining pool

Behaviour: Continuous TCP Send/Receive frames between svchost32.exe and ns31430818.ip-141-94-96.eu:3333.
Use case: Live evidence of active Stratum mining communication.

Step 10 — TCPView Confirmed the established outbound connection.

TCPView showing svchost32.exe connection

Behaviour:svchost32.exe PID 35592 — 192.168.1.64:52338 → 141.94.96.144:3333, state ESTABLISHED.
Use case: Pins down the live remote IP, port, and source PID for IOC and firewall blocking.

Step 11 — RamMap Confirmed memory consumption.

RamMap process view of svchost32.exe

Behaviour:svchost32.exe shows a multi-MB total/working set among normal services.
Use case: Corroborates the memory impact reported by Process Explorer.

Step 12 — Autoruns Discovered the persistence entry.

Autoruns showing WindowsHostService scheduled task

Behaviour: Search for "windowshost" reveals a scheduled task named WindowsHostService.
Use case: Identifies the autostart mechanism keeping the miner alive across reboots.

Step 13 — Task Scheduler Verified the persistence trigger and command.

Task Scheduler showing WindowsHostService action

Behaviour: Task WindowsHostService runs wscript.exe "C:\Users\niraj\AppData\Roaming\windowshost\runhidden.vbs" at logon.
Use case: Confirms exactly how, when, and with what command the miner is auto-launched.


🧩 Threat Summary

This is a trojanized XMRig cryptocurrency miner disguised as a legitimate Windows system process. The attacker renamed the XMRig mining executable to svchost32.exe to mimic the legitimate Windows service host process (svchost.exe). The malware completely evaded the host antivirus and was only found through manual forensic investigation.

The sample has been independently confirmed as a Monero miner on VirusTotal — most major engines flag it as XMRig, CoinMiner, or BitMiner (categories: miner / trojan / pua).

🔗 Reference: VirusTotal Report — 5379df3d...


🗂️ File-by-File Analysis

1. svchost32.exe — Main Malicious Executable

PropertyValue
True IdentityXMRig Miner (renamed from xmrig.exe)
Disguised AsWindows Service Host (svchost.exe)
PurposeMines Monero cryptocurrency using victim's CPU
Original Hash (from SHA256SUMS)f29d673b032f7ff763dec032aefd6c5759a1583b211625f7f770017bedf03689
Host AV DetectionNONE — undetected by installed antivirus
VirusTotalFlagged as XMRig / CoinMiner by majority of engines

Why it evades the host antivirus:

  • XMRig is technically "legitimate" mining software — many AV vendors classify it as PUA (Potentially Unwanted Application).
  • Placed in a user directory where AV real-time scanning may have exclusions.
  • The renamed filename avoids signature rules targeting xmrig.exe.
  • VBScript indirection adds another layer of evasion.

2. config.json — Mining Configuration

SettingValueMeaning
Mining Poolpool.supportxmr.com:3333Public Monero mining pool
Wallet Address42eXxkZXEKLD38gM4XpNxUitLdkt5f7yZFJXRswCjvqPX9BjRmSUCL5Nxw7AKAY5hbaWpfbxWyors87ZZfvvWXhd6uTvXcNAttacker's Monero wallet
Worker PasswordSPool authentication token
CPU MiningEnabled — ALL 16 threadsMaximum resource theft
GPU Mining (OpenCL)Disabled
GPU Mining (CUDA)Disabled
Background ModetrueRuns silently, no visible window
Pause on ActivefalseDoes NOT stop when user is active
Pause on BatteryfalseDoes NOT stop on battery power
Donate Level1%Minimal donation to XMRig developers
HTTP APIDisabledNo remote monitoring interface exposed
AlgorithmRandomX (auto)Monero's proof-of-work algorithm
Huge PagesEnabledOptimizes mining performance
TLSDisabledUnencrypted pool connection

Critical observations:

  • Uses all 16 CPU threads at maximum intensity — explains the 80% resource usage at startup.
  • pause-on-active: false means it never stops, even when the user is working.
  • pause-on-battery: false drains laptop battery aggressively.
  • background: true ensures no visible console window appears.

3. runhidden.vbs — Stealth Launcher (Persistence Mechanism)

SetobjShell=CreateObject("WScript.Shell")objShell.CurrentDirectory="C:\Users\niraj\AppData\Roaming\windowshost"objShell.Run"svchost32.exe",0,False
PropertyValue
PurposeLaunches the miner with a completely hidden window
TechniqueWScript.Shell.Run with window style 0 (SW_HIDE)
BlockingFalse — script exits immediately after launch
TriggerScheduled task WindowsHostService at logon

The VBScript itself contains no overtly malicious code — it simply runs an executable — which is why it is not flagged by signature-based AV.


4. running.lock — Process Lock File

PropertyValue
Contentrunning
PurposeIndicates the miner is currently active
MechanismPrevents multiple instances from running simultaneously

5. cert.pem & cert_key.pem — TLS Certificate & Private Key

PropertyValue
Subjectlocalhost
IssuedApril 21, 2025
ExpiresApril 19, 2035 (10-year validity)
Key TypeRSA 2048-bit
TypeSelf-signed

The HTTP API is disabled in config.json, but these certificates are bundled for the optional XMRig HTTPS API endpoint.


6. SHA256SUMS — Origin Verification File

This file lists hashes for the original XMRig distribution, confirming the malware's source:

Original FilePurpose
xmrig.exeThe miner binary (renamed to svchost32.exe)
WinRing0x64.sysKernel driver for MSR register access
config.jsonMining configuration
start.cmdOriginal start script
benchmark_10M.cmd / benchmark_1M.cmdBenchmark scripts
pool_mine_example.cmdPool mining example
rtm_ghostrider_example.cmdGhostRider algorithm example
solo_mine_example.cmdSolo mining example

🚨 Indicators of Compromise (IOCs)

File System IOCs

TypeIndicator
DirectoryC:\Users\niraj\AppData\Roaming\windowshost\
Executablesvchost32.exe (SHA256: f29d673b032f7ff763dec032aefd6c5759a1583b211625f7f770017bedf03689)
VBS Launcherrunhidden.vbs
Lock Filerunning.lock (contains running)
Configconfig.json (XMRig format with pool/wallet)
Certificatecert.pem (self-signed, CN=localhost)
Private Keycert_key.pem (RSA 2048-bit)

Network IOCs

TypeIndicator
Mining Pool Domain (config)pool.supportxmr.com
Resolved Pool Endpoint (observed)ns31430818.ip-141-94-96.eu / 141.94.96.144
Port3333 (Stratum protocol)
ProtocolTCP/Stratum (unencrypted)
Source Port (observed)52338
Connection TypePersistent outbound, ESTABLISHED

Attacker's Monero Wallet Address

42eXxkZXEKLD38gM4XpNxUitLdkt5f7yZFJXRswCjvqPX9BjRmSUCL5Nxw7AKAY5hbaWpfbxWyors87ZZfvvWXhd6uTvXcN

Persistence IOCs

LocationWhat to Look For
Task SchedulerTask named WindowsHostService running wscript.exe runhidden.vbs
HKCU\Software\Microsoft\Windows\CurrentVersion\RunEntries pointing to runhidden.vbs
HKLM\Software\Microsoft\Windows\CurrentVersion\RunEntries pointing to runhidden.vbs
shell:startup folderShortcut or VBS file

🗺️ MITRE ATT&CK Framework Mapping

Technique IDTacticNameUsage in This Attack
T1496ImpactResource HijackingCPU used for Monero mining
T1036.005Defense EvasionMasquerading: Match Legitimate Namesvchost32.exe mimics svchost.exe
T1059.005ExecutionCommand and Scripting Interpreter: Visual Basicrunhidden.vbs launches the miner
T1564.003Defense EvasionHide Artifacts: Hidden WindowWindow style 0 hides process
T1053.005PersistenceScheduled Task/Job: Scheduled TaskWindowsHostService task at logon
T1547.001PersistenceBoot or Logon Autostart Execution: Registry Run Keys(alternate persistence vector to check)
T1071Command and ControlApplication Layer ProtocolStratum mining protocol over TCP
T1027Defense EvasionObfuscated Files or InformationRenamed binary, indirect execution
T1074.001CollectionData Staged: Local Data StagingAll components staged in AppData\Roaming

🛡️ Why the Host Antivirus Failed to Detect This

Evasion TechniqueExplanation
Legitimate Tool AbuseXMRig is open-source mining software; many AV vendors classify it as PUA, not malware, and may not block it by default.
File RenamingRenaming xmrig.exe to svchost32.exe bypasses filename-based detection signatures.
Living-off-the-LandUses Windows-native VBScript (wscript.exe) for execution — a trusted Microsoft binary.
User-Space LocationAppData\Roaming is a legitimate application data folder; some AV products reduce scanning intensity here.
No Exploit CodeThe malware contains no shellcode, exploits, or traditionally "malicious" code patterns.
Indirect ExecutionVBS → EXE chain adds indirection that breaks simple behavioral detection.

Note: While the host AV missed it, VirusTotal cross-checks (sample report) show that the majority of engines do recognize this binary as XMRig / CoinMiner — the failure was specific to the host's installed product.


📊 Impact Assessment

Impact AreaSeverityDescription
CPU Usage🔴 CRITICALAll 16 CPU threads consumed at 100% capacity
System Performance🔴 HIGHSystem extremely slow, 80% resources consumed at boot
Battery Life🔴 HIGHLaptop battery drains rapidly due to constant full CPU load
Electricity Cost🟡 MEDIUMIncreased power consumption at victim's expense
Hardware Lifespan🟡 MEDIUMProlonged 100% CPU usage causes thermal stress
Network🟢 LOWConstant outbound connection to mining pool
Data Theft✅ NONE OBSERVEDNo data exfiltration capability detected in this configuration
Privacy🟢 LOWWallet address and pool connection expose attacker's identity

🔧 Remediation Steps

Phase 1 — Immediate Containment

  1. Kill the process — Open Task Manager → find svchost32.exe → End Task.
  2. Disconnect from network — Prevent further communication with the mining pool.
  3. Verify process is dead — Use Process Explorer to confirm no child processes remain.

Phase 2 — Remove Persistence

  1. Open Task Scheduler (taskschd.msc) → delete the WindowsHostService task.
  2. Open Autoruns (run as Administrator) → remove any entry referencing runhidden.vbs, svchost32.exe, or windowshost.
  3. Check the registry for any backup persistence:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
    
  4. Check Startup folders:shell:startup and shell:common startup.

Phase 3 — Remove Malware Files

  1. Delete the entire malware directory:
    rmdir /s /q "C:\Users\niraj\AppData\Roaming\windowshost"
  2. Search for related files — Check for copies in:
    • C:\Users\niraj\AppData\Local\Temp\
    • C:\ProgramData\
    • Other user profiles

Phase 4 — Block & Verify

  1. Block the mining pool / observed IP at the firewall:
    netsh advfirewall firewall add rule name="Block Mining Pool" dir=out action=block remoteip=141.94.96.144
    netsh advfirewall firewall add rule name="Block SupportXMR" dir=out action=block remoteip=pool.supportxmr.com
  2. Monitor CPU usage for 48 hours to confirm mining has stopped.
  3. Run full antivirus scan with updated definitions (consider Malwarebytes or HitmanPro as a secondary scanner).

Phase 5 — Post-Incident

  1. Change all passwords — Assume credentials may be compromised.
  2. Investigate infection vector — phishing, cracked software, drive-by download, or USB?
  3. Check for additional payloads — the dropper may have installed other malware.
  4. Audit AV exclusions — ensure AppData\Roaming is not excluded from scanning.

🗜️ Sample Preservation — windowshost.zip

The complete malware folder has been compressed into windowshost.zip and kept alongside this report for educational and incident-response purposes.

⚠️WARNING:windowshost.zip contains a live, working XMRig miner. Do not unzip or execute it on any production or personal system.

Safe Analysis Environments

EnvironmentNotes
VMware Workstation / PlayerUse a Windows VM with networking set to Host-only or NAT with the mining pool blocked. Take a clean snapshot before extraction so you can roll back.
VirtualBoxSame precautions — host-only networking, snapshot first, no shared folders mounted as writable to the host.
Windows SandboxLightweight isolated container shipped with Windows 10/11 Pro+. Files inside the sandbox are discarded on close, which is ideal for one-shot inspection.
REMnux + FLARE VMRecommended dual-VM setup for static + dynamic analysis with full network capture (Wireshark, INetSim).

Recommended Workflow Inside the VM

  1. Disable internet access (or route through INetSim/FakeNet) before unzipping.
  2. Calculate hashes of every file and compare with the SHA256SUMS shipped in the archive.
  3. Open config.json, runhidden.vbs, and SHA256SUMS in a text viewer — they are plain text.
  4. Run static analysis on svchost32.exe (PE-bear, CFF Explorer, DIE) without executing.
  5. Only execute under controlled conditions (Process Monitor + Wireshark running) if dynamic behavior is needed.
  6. Revert the snapshot when done.

Recommended Analysis Tools

ToolPurpose
VirusTotalCross-engine detection — sample report linked above
WiresharkCapture Stratum traffic to the mining pool
x64dbg / IDA FreeDebug and analyze the PE
PE-bear / CFF Explorer / DIEStatic PE inspection (headers, imports, sections)
Any.Run / Hybrid AnalysisOnline sandbox if you can't run a local VM
YARAWrite detection signatures from observed strings/imports

📚 Key Learning Points

  1. Antivirus alone is not enough — the host AV missed this entirely while VirusTotal engines did not.
  2. Behavioral analysis matters — the 80% CPU usage was the only visible symptom.
  3. Sysinternals tools are essential — Process Explorer, Autoruns, Process Monitor, TCPView, and RamMap revealed what AV could not.
  4. Know your baseline — recognizing normal system behavior is what made the anomaly stand out.
  5. Check process paths — the real svchost.exe only runs from C:\Windows\System32\, never from AppData.
  6. Living-off-the-land techniques are common — attackers chain trusted Windows tools (VBScript, wscript, scheduled tasks) to avoid detection.

Red Flags Checklist

├── High CPU at startup with no user applications open
├── Process named similar to a system process (svchost32 vs svchost)
├── Executable running from AppData\Roaming (not System32)
├── Persistent outbound connections to known mining pools / Stratum ports
├── VBScript or PowerShell entries in Task Scheduler / startup
└── Lock files indicating background process management

✅ Conclusion

This is a confirmed XMRig cryptocurrency miner operating covertly on the system. The attacker deployed a well-crafted evasion strategy that bypassed the host antivirus by:

  1. Renaming the miner to mimic a Windows system process.
  2. Using a VBScript launcher with a hidden window to execute it.
  3. Persisting via a scheduled task disguised as WindowsHostService.
  4. Staging files in a legitimate-looking AppData\Roaming directory.
  5. Leveraging the fact that XMRig is technically "legitimate" software.

The malware was only discovered through manual forensic investigation using Sysinternals tools after the analyst noticed abnormal 80% CPU usage at startup. The sample is independently confirmed as a Monero miner by the majority of engines on VirusTotal:

🔗 https://www.virustotal.com/gui/file/5379df3d28d83164b24cfa02833233514958652eca489b968ff6e36b1bc49bc3

This case demonstrates that antivirus alone is insufficient against well-disguised threats. Manual investigation skills and knowledge of system internals remain critical for identifying stealthy malware.


Report generated for educational and incident response purposes.


Made with ❤️ by hackthacker

About

Windows threat analysis toolkit focused on malware investigation, persistence detection, and suspicious process monitoring.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors