FILEMembers
FILE

Hash-identified XMRig launch shares an IP with separate C2 configuration

A recorded process launch identifies an XMRig miner configured for port 6060, while a different file’s recovered configuration lists the same IP as C2 on port 6000. The address overlap is a useful infrastructure lead, but the supplied events do not show a connection to the configured C2 endpoint or link the files in one execution chain.

Oct 8, 2026, 07:32 (UTC+9)Last seenOct 8, 2026Severity100ByCTX TeamIOC59MITRE19RegionsCNGBHKHUIT

A Windows process named sysmgnrsv.exe was created with a command line directing an XMRig miner to 178.16.54.109:6060. In a different file’s memory-extracted configuration, the same IP appeared on TCP port 6000, classified as command-and-control infrastructure. Does that overlap connect mining and malware control into one execution chain?

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence