Riskware/BitCoinMiner

description-logoAnalysis


  • This detection is for a known bitcoin miner that could cause unwanted network traffic on the affected hosts.

  • This application is often delivered through a package installer which has been observed to consistently drop the following files:
    • libcurl-4.dll : This is a recognized clean file.
    • pthreadGC2.dll : This is a recognized clean file.
    • [RandomFileName].exe : This is detected as Riskware/BitCoinMiner.
    • zlib1.dll : This is a recognized clean file.

  • There are some variations on the installation and could include other potentially unwanted files that may harm the affected user, such as autostart scripts, uninstallers, etc.

  • The main executable, which is the bitcoin miner program itself, usually stays resident in memory without any prompts or graphical user interface, thus rendering it to be classified as a potential risk.

recommended-action-logoRecommended Action

    FortiGate Systems
  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.
    FortiClient Systems
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2023-02-27 91.00975
2023-01-24 90.09944
2022-10-04 90.06580
2022-09-06 90.05740
2022-05-25 90.02622
2021-12-14 89.07763
2021-08-31 88.00782
2021-08-29 88.00734
2021-07-12 87.00582
2021-07-05 87.00413