
Hash-identified XMRig launch shares an IP with separate C2 configuration
A recorded process launch identifies an XMRig miner configured for port 6060, while a different file’s recovered configuration lists the same IP as C2 on port 6000. The address overlap is a useful infrastructure lead, but the supplied events do not show a connection to the configured C2 endpoint or link the files in one execution chain.
A Windows process named sysmgnrsv.exe was created with a command line directing an XMRig miner to 178.16.54.109:6060. In a different file’s memory-extracted configuration, the same IP appeared on TCP port 6000, classified as command-and-control infrastructure. Does that overlap connect mining and malware control into one execution chain?
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read