Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. CoinTicker

CoinTicker

CoinTicker is a malicious application that poses as a cryptocurrency price ticker and installs components of the open source backdoors EvilOSX and EggShell.[1]

ID: S0369
Type: MALWARE
Platforms: macOS
Contributors: Richie Cyrus, SpecterOps
Version: 1.1
Created: 23 April 2019
Last Modified: 25 April 2025
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1059.003Command and Scripting Interpreter:Windows Command Shell

CoinTicker executes a bash script to establish a reverse shell.[1]

.004Command and Scripting Interpreter:Unix Shell

CoinTicker executes a bash script to establish a reverse shell.[1]

.006Command and Scripting Interpreter:Python

CoinTicker executes a Python script to download its second stage.[1]

EnterpriseT1543.001Create or Modify System Process:Launch Agent

CoinTicker creates user launch agents named .espl.plist and com.apple.[random string].plist to establish persistence.[1]

EnterpriseT1140Deobfuscate/Decode Files or Information

CoinTicker decodes the initially-downloaded hidden encoded file using OpenSSL.[1]

EnterpriseT1564.001Hide Artifacts:Hidden Files and Directories

CoinTicker downloads the following hidden files to evade detection and maintain persistence: /private/tmp/.info.enc, /private/tmp/.info.py, /private/tmp/.server.sh, ~/Library/LaunchAgents/.espl.plist, ~/Library/Containers/.[random string]/[random string].[1]

EnterpriseT1105Ingress Tool Transfer

CoinTicker executes a Python script to download its second stage.[1]

EnterpriseT1027Obfuscated Files or Information

CoinTicker initially downloads a hidden encoded file.[1]

EnterpriseT1553.001Subvert Trust Controls:Gatekeeper Bypass

CoinTicker downloads the EggShell mach-o binary using curl, which does not set the quarantine flag.[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp