{"id":42170,"date":"2018-01-19T05:00:00","date_gmt":"2018-01-19T05:00:00","guid":{"rendered":"https:\/\/www.cira.ca\/blog\/weekly-web-security-warning-bitcoin-miners-mirai-and-malware-call-home\/"},"modified":"2023-03-10T10:57:13","modified_gmt":"2023-03-10T15:57:13","slug":"weekly-web-security-warning-bitcoin-miners-mirai-and-malware-call-home","status":"publish","type":"cira_news","link":"https:\/\/stg-saas.cira.ca\/en\/resources\/news\/cybersecurity\/weekly-web-security-warning-bitcoin-miners-mirai-and-malware-call-home\/","title":{"rendered":"Weekly web security warning: Bitcoin miners, Mirai and Malware Call Home"},"content":{"rendered":"<p>For our weekly web security warning, we thought it would be interesting to explore what each of the categories means for the user. We have a library of over 400 types of malware so let&#8217;s see what hit the top 10.<\/p>\n<p><!--more--><\/p>\n<p>For the past two weeks, we have seen a significant increase in Bitcoin Miner&nbsp;malware among our top D-Zone DNS Firewall blocks.&nbsp;This week, cryptocurrency-related malware is still a significant contributor to the top 10 list but the total number of queries has dropped way off. This indicates that this round of activity is on the wane (for now).<\/p>\n<p>For our weekly web security warning, we thought it would be interesting to explore what each of the categories means for the user. We have a library of over 400 types of malware so let&#8217;s see what hit the top 10.<\/p>\n<p>&nbsp;<\/p>\n<div class=\"media media-element-container media-default\">\n<img loading=\"lazy\" decoding=\"async\" class=\" size-full wp-image-2566\" src=\"https:\/\/stg-saas.cira.ca\/uploads\/2018\/01\/topblocks0122-2.png\" alt=\"\" title=\"\" width=\"771\" height=\"422\" srcset=\"https:\/\/stg-saas.cira.ca\/uploads\/2018\/01\/topblocks0122-2.png 771w, https:\/\/stg-saas.cira.ca\/uploads\/2018\/01\/topblocks0122-2-300x164.png 300w, https:\/\/stg-saas.cira.ca\/uploads\/2018\/01\/topblocks0122-2-768x420.png 768w\" sizes=\"auto, (max-width: 771px) 100vw, 771px\" \/>\n<\/div>\n<p><strong>Bitcoin Miner<\/strong><\/p>\n<p>Any malware whose primary function is using victim computers&#8217; CPUs and electricity to mine Bitcoins. Don&#8217;t let your machine be someone else&#8217;s profits \u2013 if you let this happen you might as well mine your own cryptocurrencies because at least that won&#8217;t leave a lot of CPU cycles left for the baddies.<\/p>\n<p><strong>Mirai<\/strong><\/p>\n<p>An IoT botnet that is used primarily to launch DDoS attacks. Also includes variants (e.g. Persirai).&nbsp;Remember when the <a href=\"https:\/\/dyn.com\/blog\/dyn-analysis-summary-of-friday-october-21-attack\/\">internet broke down in 2016<\/a>? Yup, that was Mirai, and it remains a persistent threat<\/p>\n<p><strong>Malware Call Home<\/strong><\/p>\n<p>Domains used for malware post-infection communications. This one is a pervasive problem for our customers as malware attempts to contact host servers. Those primarily impacted are in the education sector as, <strong><em>we assume<\/em><\/strong>, students link their infected machines to the network.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For our weekly web security warning, we thought it would be interesting to explore what each of the categories means for the user. We have a library of over 400 types of malware so let&#8217;s see what hit the top 10.<\/p>\n","protected":false},"featured_media":2569,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"ngg_post_thumbnail":0,"slim_seo":{"title":"Weekly web security warning: Bitcoin miners, Mirai and Malware Call Home - CIRA","description":"For our weekly web security warning, we thought it would be interesting to explore what each of the categories means for the user. We have a library of over 400"},"footnotes":""},"topic":[28],"class_list":["post-42170","cira_news","type-cira_news","status-publish","has-post-thumbnail","hentry","cira_news_type-cira-news-type-blog","cira_topic-cira-topic-cybersecurity","cira_author-rob-williamson"],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/cira\/v1\/news\/42170","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/cira\/v1\/news"}],"about":[{"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/wp\/v2\/types\/cira_news"}],"version-history":[{"count":0,"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/cira\/v1\/news\/42170\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/wp\/v2\/media\/2569"}],"wp:attachment":[{"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/wp\/v2\/media?parent=42170"}],"wp:term":[{"taxonomy":"cira_topic","embeddable":true,"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/cira\/v1\/topic?post=42170"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}