{"id":3219,"date":"2021-07-05T23:06:21","date_gmt":"2021-07-06T04:06:21","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3219"},"modified":"2021-07-05T23:06:22","modified_gmt":"2021-07-06T04:06:22","slug":"shellbot-malware-used-to-mine-cryptocurrencies","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/","title":{"rendered":"Shellbot Malware used to mine cryptocurrencies"},"content":{"rendered":"\n<p>As we can well agree, Shellbot made its appearance in 2005, at that time Shellbot was able to brutally force the credentials of SSH remote access services on Linux servers protected by weak passwords. But, over time it has been receiving improvements and updates. The malware then undermines privacy-centric cryptocurrency monero (XMR).<\/p>\n\n\n\n<p>With the exponential rise in the value of cryptocurrencies, cybercrime efforts based on these digital currencies have also increased. Aside from the devastating rise in ransomware attacks, illegal mining of cryptocurrencies on devices you don&#8217;t own, also known as cryptojacking, has become a commercial-grade threat used in the hands of lone criminals and organized groups alike.<\/p>\n\n\n\n<p>In some cases, the cryptojacking operations that keep mining farms processing coins reached the magnitude of a $ 50 million business for their bot masters. ShellBot malware lives within this ecosystem. While it is a fairly simple piece of Perl-based code, it allows attackers to set up Internet Relay Chat (IRC) controlled botnets that control the mining of coins on computers, Linux servers, Android devices, and Internet devices from things.<\/p>\n\n\n\n<p>While it started out as a basic IRC bot, over time ShellBot has been using effective exploits to compromise servers and devices. It started with a ShellShock campaign (CVE-2014-6271), which is how it got its name, but over the years it has used Drupalgeddon (CVE-2018-7600) and other exploits that can compromise large swaths of devices.<\/p>\n\n\n\n<p>ShellBot infections often use brute force attacks to guess passwords for specific servers and devices, which shows why having a strong password is so important. In the botnets that IBM X-Force examined, the most frequently used types of credentials helped identify targets such as misconfigured databases, FTP servers, monitoring servers, and other Linux machines.<\/p>\n\n\n\n<p>ShellBot is placed as a payload on systems and devices where a password was forced. Immediately after a successful login, the infected machine or device receives a list of commands to execute; These include sending system information, downloading and running a PERL script, deleting records, deleting command history, and removing payload.<\/p>\n\n\n\n<p>Check also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/pandastealer-the-new-threat-to-cryptocurrencies\/\">PandaStealer, the new threat to cryptocurrencies<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/the-dangers-of-cryptojacking-and-how-it-affects\/\">The Dangers of Cryptojacking and how it affects users<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As we can well agree, Shellbot made its appearance in 2005, at that time Shellbot was able to brutally force the credentials of SSH remote access services on Linux servers protected by weak passwords. But, over time it has been receiving improvements and updates. The malware then undermines privacy-centric cryptocurrency monero (XMR). With the exponential [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3220,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14,10],"tags":[97,280,36],"class_list":["post-3219","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-botnets","category-cybersecurity","tag-botnet","tag-cryptojacking","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Shellbot Malware used to mine cryptocurrencies - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"ShellBot has already been active for a long time since its first appearance and over time it has received improvements which we will see today\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Shellbot Malware used to mine cryptocurrencies - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"ShellBot has already been active for a long time since its first appearance and over time it has received improvements which we will see today\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-06T04:06:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-07-06T04:06:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/botnet.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Shellbot Malware used to mine cryptocurrencies\",\"datePublished\":\"2021-07-06T04:06:21+00:00\",\"dateModified\":\"2021-07-06T04:06:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/\"},\"wordCount\":361,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/botnet.jpg\",\"keywords\":[\"Botnet\",\"Cryptojacking\",\"Cybersecurity\"],\"articleSection\":[\"Botnets\",\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/\",\"name\":\"Shellbot Malware used to mine cryptocurrencies - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/botnet.jpg\",\"datePublished\":\"2021-07-06T04:06:21+00:00\",\"dateModified\":\"2021-07-06T04:06:22+00:00\",\"description\":\"ShellBot has already been active for a long time since its first appearance and over time it has received improvements which we will see today\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/botnet.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/botnet.jpg\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/shellbot-malware-used-to-mine-cryptocurrencies\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Shellbot Malware used to mine cryptocurrencies\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Shellbot Malware used to mine cryptocurrencies - Truxgo Server Blog","description":"ShellBot has already been active for a long time since its first appearance and over time it has received improvements which we will see today","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/","og_locale":"es_MX","og_type":"article","og_title":"Shellbot Malware used to mine cryptocurrencies - Truxgo Server Blog","og_description":"ShellBot has already been active for a long time since its first appearance and over time it has received improvements which we will see today","og_url":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-07-06T04:06:21+00:00","article_modified_time":"2021-07-06T04:06:22+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/botnet.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Shellbot Malware used to mine cryptocurrencies","datePublished":"2021-07-06T04:06:21+00:00","dateModified":"2021-07-06T04:06:22+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/"},"wordCount":361,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/botnet.jpg","keywords":["Botnet","Cryptojacking","Cybersecurity"],"articleSection":["Botnets","Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/","url":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/","name":"Shellbot Malware used to mine cryptocurrencies - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/botnet.jpg","datePublished":"2021-07-06T04:06:21+00:00","dateModified":"2021-07-06T04:06:22+00:00","description":"ShellBot has already been active for a long time since its first appearance and over time it has received improvements which we will see today","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/botnet.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/botnet.jpg","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/shellbot-malware-used-to-mine-cryptocurrencies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Shellbot Malware used to mine cryptocurrencies"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3219","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3219"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3219\/revisions"}],"predecessor-version":[{"id":3229,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3219\/revisions\/3229"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3220"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3219"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3219"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}