• About us
  • Contact Us
  • Privacy & Policy
CryptoCoinNewsHub.com
No Result
View All Result
Sunday, July 12, 2020
  • Home
  • Live Updates
    • Cryptocurrency Prices
    • Live ICO
    • Live Exchange
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
  • Blockchain
  • Tech
  • Business
  • Trading
CryptoCoinNewsHub.com
  • Home
  • Live Updates
    • Cryptocurrency Prices
    • Live ICO
    • Live Exchange
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
  • Blockchain
  • Tech
  • Business
  • Trading
No Result
View All Result
CryptoCoinNewsHub.com
No Result
View All Result
Home Crypto News

New Crypto Malware Targets Unprotected WordPress Sites

August 13, 2019
in Crypto News
2 min read
0
New Crypto Malware Targets Unprotected WordPress Sites
152
SHARES
1.9k
VIEWS
Share on FacebookShare on Twitter

New Crypto Malware Targets Unprotected WordPress Sites, CryptoCoinNewsHub.com

A new malware called Clipsa was found by researchers, which is basically a malicious crypto miner that targets WordPress sites that are not secured.

According to the Avast researchers, the malware was noticed during a huge spread campaign which targeted thousands of PCs from all over the world. While Clipsa mostly targets to steal crypto, it also replaces the crypto addresses it finds on a clipboard (which is where the malware got its name).

The malware is still spreading as it is scouring the internet to find unsecured sites through infected computers.

Regarding the multiple activities of malicious malware, the researchers stated:

“Clipsa is a multipurpose password stealer, written in Visual Basic, focusing on stealing cryptocurrencies, brute-forcing and stealing administrator credentials from unsecured WordPress websites, replacing crypto-addresses present in a clipboard, and mining cryptocurrencies on infected machines. Several versions of Clipsa also deploy an XMRig coinminer to make even more money from infected computers.”

The malware’s modus operandi involved a malicious codec pack installer for media players. The victim then downloads the malware when he downloads the player. From an infected PC, Clipsa can also attack unsecured WordPress sites.

After the codec is downloaded, the file then installs itself and executes its tasks in a succession of phases. The initiation phase does not contain specific parameters, but the next ones contain parameters that hint their functionalities.

  1. Initiation – No parameters; malware just installs and hides on the system, and executes the next phases.
  2. CLIPS
  3. CLIPPS
  4. WALLS

The phases from 2 to 4 are programmed to steal ‘crypto-wallet related data’ from the computers. Then the wallet addresses found on the clipboard are replaced with those of the attackers from a predefined list.

RELATED  Roman Schnider to Replace Eelco Fiole as Tezos New Chief Financial Officer

This means that when the victim pastes his wallet address anywhere, he will actually paste the attackers’ address.

  1. PARSE
  2. BRUTE

These two parameters involve searching for vulnerable WordPress websites on the internet and stealing through brute force their admin credentials.

The malware creators are also interested in analyzing the activities of the malware, as it has a file for logging purposes:

“Clipsa creates and uses an additional file: C:UsersuserAppDataRoamingAudioDGlog.dat This file is used for logging purposes, which the malware author can use to debug Clipsa and obtain statistics.”

Clipsa was found active in various regions throughout the world, mostly in India, Philippines, and Brazil. In over a year, more than thousands of victims were affected by the malware.

Featured image: Coinjournal

Credit: Source link

  • Trending
  • Comments
  • Latest
Bitcoin Price Bottom Could Fall Far Beyond $7,700, Warns Trader

Bitcoin Price Bottom Could Fall Far Beyond $7,700, Warns Trader

October 1, 2019
Perth Mint, InfiGold Launch Gold-Backed Token on Public Blockchain

Perth Mint, InfiGold Launch Gold-Backed Token on Public Blockchain

October 10, 2019
Blockchain Startups Looking To Implement Ethereum Purchases in Amazon

Blockchain Startups Looking To Implement Ethereum Purchases in Amazon

June 15, 2019
Bitcoin Price Recovery Banishes Slump as Momentum Tests $12,000

Bitcoin Price Recovery Banishes Slump as Momentum Tests $12,000

July 5, 2019

Confiscated Bitcoins by Tax Agents Remain in a Criminal’s Wallet

February 7, 2020

XRP Beats Ethereum and Bitcoin as the Best Performing Crypto

February 1, 2020

Robin Hood- Problems in more than just Sherwood Forest

January 28, 2020

One Wallet Has 27% of Ether in Old MakerDAO Network

January 26, 2020
CryptoCoinNewsHub.com

CryptoCoinNewsHub.com is an online news portal which aims to provide latest trendy crypto news around the world with real time updates.
Email us hello@cryptocoinnewshub.com

Topics to Cover

  • Bitcoin
  • Blockchain
  • Business
  • Crypto News
  • Ethereum
  • Ripple
  • Tech
  • Trading

Whats New Here!

  • Confiscated Bitcoins by Tax Agents Remain in a Criminal’s Wallet
  • XRP Beats Ethereum and Bitcoin as the Best Performing Crypto
  • Robin Hood- Problems in more than just Sherwood Forest

Subscribe to get more

Simply subscribe to our newsletters and we will be in touch. Don't worry, we won't spam you

© 2019 CryptoCoinNewsHub.com - All rights reserved

No Result
View All Result
  • Home
  • Live Updates
    • Cryptocurrency Prices
    • Live ICO
    • Live Exchange
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
  • Blockchain
  • Tech
  • Business
  • Trading

© 2019 CryptoCoinNewsHub.com - All rights reserved

  • bitcoinBitcoin(BTC)$8,152.26-0.70%
  • ethereumEthereum(ETH)$175.30-1.63%
  • rippleXRP(XRP)$0.252799-0.58%
  • bitcoin-cashBitcoin Cash(BCH)$242.68-2.16%
  • tetherTether(USDT)$1.000.27%
  • litecoinLitecoin(LTC)$55.01-1.92%
  • eosEOS(EOS)$3.11-2.39%
  • binance-coinBinance Coin(BNB)$18.56-2.84%
  • cardanoCardano(ADA)$0.042556-2.10%
  • stellarStellar(XLM)$0.064655-3.04%
  • tronTRON(TRX)$0.016891-2.25%
  • moneroMonero(XMR)$58.64-0.32%
  • neoNEO(NEO)$11.682.51%
  • iotaIOTA(MIOTA)$0.245122-1.96%
  • dashDash(DASH)$65.431.15%
  • nemNEM(XEM)$0.039494-0.75%