Soru

Zorluk: OrtaMalware Types and Indicators of Compromise

During an off-peak security monitoring review, a security analyst identifies anomalous activity across several database server endpoints. Host telemetry indicates sustained 98% CPU and GPU utilization during non-business hours, accompanied by persistent outbound TCP traffic destined for an external IP address over port 3333 using the Stratum protocol. Endpoint inspection confirms an unauthorized binary executing via a persistent Windows Task Scheduler job. Based on these technical indicators of compromise (IoCs), which of the following malware types has compromised the systems?

  1. CryptominerCevap
  2. B
    Ransomware
  3. C
    Worm
  4. D
    Rootkit

Cevap

Cryptominer (or coin-miner) malware is identified by telemetry showing high system resource consumption (CPU/GPU) and network communication over mining pool protocols such as Stratum.
The correct answer is Cryptominer. Cryptomining malware (also known as cryptojacking software) secretly utilizes an infected endpoint's computational resources (CPU and GPU) to mine cryptocurrency. The key indicators in the scenario—extreme processor utilization during off-peak hours, persistence established via Task Scheduler, and outbound network traffic using the Stratum mining protocol—are definitive signatures of coin-mining operations.

Adım Adım Çözüm

1
Analyze the resource consumption telemetry in the incident log.
Near-100% CPU and GPU utilization during off-peak hours indicates unauthorized resource-heavy background computational tasks.
Cryptomining software requires intense mathematical operations to process cryptographic hashes for mining blocks.
2
Examine the network transport layer indicators and communication protocols.
Outbound TCP traffic over port 3333 utilizing the Stratum protocol links directly to cryptocurrency mining pool communication standards.
Stratum is the primary JSON-RPC based network protocol used by mining software to communicate with mining pool servers.
3
Synthesize the host persistence mechanics and telemetry artifacts to determine the malware type.
The combination of high processing load, Stratum mining pool network traffic, and scheduled task persistence confirms cryptominer malware deployment.
These telemetry markers explicitly define resource-hijacking cryptojacking malware.

Anahtar Kavram

Cryptomining Malware and Indicators of Compromise
Bu soruyu puanla