/?pid=yahoo-malware-turned-pcs-into-bitcoin-miners-12321

Updated:02:59 AM EDT Sep 23


this is ggmania.com subsite Yahoo Malware Turned PCs Into Bitcoin Miners - TechAmok

Yahoo Malware Turned PCs Into Bitcoin Miners - [security]
03:42 PM EST - Jan,09 2014 - post a comment

Researchers at security firm Light Cyber revealed this week that one of the malware programs aimed to use the resources of infected PCs to perform the calculations necessary to run a Bitcoin network. Revealed earlier this month by fellow security firm Fox IT, the campaign spread its package by using Yahoo's ad server to deploy malicious ads. The malware took advantage of vulnerabilities in Java to install itself on computers that visited the ads.yahoo.com site. So far, Yahoo hasn't revealed any details on the infected computers or publicly advised affected users on what they should do. But security firm Surfright shed a bit more light on the situation.
Not every ad on the Yahoo advertisement network contained the malicious iframe, but if you have an outdated version of Java Runtime (you can check here) and you used Yahoo Mail the last 6 days, your computer is likely infected.

Communication with the following Internet domains is an indication of a positive infection of the communicating computer:

kmymmeiaoooigke.org bgdjstkwkbhagnp.org ceigqweqwaywiqgu.org smsfuzz.com

Communication with the following Internet domains/IP addresses is an indication of a possible infection:

blistartoncom.org
doesexisted.in
formsgained.in
funnyboobsonline.org
goodsdatums.in
locationmaking.in
mejudge.in
operatedalone.in
original-filmsonline.com
preferringbad.in
savedesiring.in
slaptoniktons.net
slaptonitkons.net
stopsadvise.in
yagerass.org
192.133.137.100
192.133.137.247
192.133.137.56
192.133.137.59
192.133.137.63
193.169.245.74
193.169.245.76

The existence of the following files is an indication of a positive infection:

%windows%\Installer\{4A74FBA7-71A0-BEA1-F538-72E3D519AA4F}\syshost.exe
%localappdata%\cygwin1.dll (See note 1)
%localappdata%\wuauclt.exe (See note 1)
%localappdata%\temp\????????.lnk (8 hex characters)
%localappdata%\temp\????????.exe (8 hex characters)
%localappdata%\temp\vedefuzunwi.exe
%programdata%\bbtmp0\jtkyygiu.exe
c:\temp\zcompute.exe

(1) filename is used by legitimate software but not in the listed path

Short overview of recent news articles

iPhone 17 Pro Max vs. Galaxy S25 Ultra Drop Test! (Sep,23 2025 )

Race Highlights: A Swing In The Drivers' Title Fight? | 2025 (Sep,21 2025 )

BYD Yangwang U9 Hits 496.22 KM/H - EV Supercar Speed Record (Sep,21 2025 )

I'm FIRST to Unbox The World's Biggest TV (Sep,21 2025 )

Samsung Begins Rollout of Android 16 to Rest of Lineup (Sep,21 2025 )

iOS 26 Now Available, with Visual Intelligence (Sep,21 2025 )

Apple's iPhone 17 Series is Nearly Hack-Proof (Sep,21 2025 )

Qualifying Highlights - 2025 Azerbaijan Grand Prix (Sep,21 2025 )

iPhone 17 Pro vs Samsung S25 Ultra Camera Comparison! (Sep,20 2025 )

iPhone Air Durability test -- I AM SHOCKED (Sep,20 2025 )

Microsoft warns Office 2016/2019 users to switch to the cloud as (Sep,15 2025 )

Get Windows 11 25H2 Right Now (Sep,15 2025 )

iPhone 17 Pro VS iPhone 16 Pro VS iPhone 15 Pro VS iPhone 14 Pro (Sep,14 2025 )

What's the AMD Alternative to an RTX 5070? (Sep,11 2025 )

Apple got my wife, they might get me next... (Sep,10 2025 )

Which Phone Has The Fastest Wi-Fi 7? (Sep,09 2025 )

Apple Event - September 9 (Sep,09 2025 )

Ferrari F430 *MANUAL* with TUBI EXHAUST SCREAMING on the AUTOBAHN! (Sep,08 2025 )

AMD Adrenalin 25.9.1 Driver (Sep,08 2025 )

Google Brings AI Text Tools to its Keyboard (Sep,08 2025 )

The Fastest Lap In F1 History: Max Verstappen's Pole Lap | 2025 (Sep,06 2025 )

You can't download and install Windows 11 25H2 yet as Microsoft (Sep,06 2025 )

A House of Dynamite - Official Teaser (2025) Rebecca Ferguson, Greta (Sep,04 2025 )

RTX 5060 Ti 16GB + Ryzen 5 5600 : Test in 17 Games (Sep,04 2025 )

BUGONIA Trailer 2 (2025) Emma Stone, Jesse Plemons (Sep,02 2025 )

Huawei unveils world-leading AI supercharged hard drive to power (Sep,02 2025 )

AM4 Lives: AMD Ryzen 5 5500X3D CPU Review & Benchmarks (Sep,01 2025 )

I was wrong, iPhone IS better than Android...- 30 Day iPhone (Aug,29 2025 )

303KM/H BMW X5 M50i GPOWER SOUNDS LIKE THUNDER (Aug,29 2025 )

NVIDIA GeForce 581.15 WHQL drivers (Aug,29 2025 )

Apple Intelligence vs Galaxy AI / Google Pixel AI / Xiaomi HyperAI - (Aug,28 2025 )

The Woman in Cabin 10 - Official Trailer (Aug,28 2025 )

YANGWANG U9 Breaks Global EV Top Speed Record (Aug,28 2025 )

AMD B850 Motherboard Roundup: Sub $200 Models (Aug,26 2025 )

Gamers Nexus: Our Channel Could Be Deleted (Aug,25 2025 )

2025 Audi A5 E-Hybrid 299HP "250KMH is back!!" // REVIEW on (Aug,24 2025 )

I Can't Stop You From Buying This... But I'll Try - GeForce RTX (Aug,23 2025 )

NVIDIA GeForce 581.08 WHQL Driver (Aug,23 2025 )

Murcielago with flames chasing an F1 car on highway (2025) (Aug,21 2025 )

Windows 11 24H2 Security Update Causes SSD/HDD Failures and (Aug,18 2025 )

Samsung Galaxy Z Fold 7 - Tips, Tricks & Hidden Features! (Aug,17 2025 )

500Hz OLEDs are Awesome - Gigabyte AORUS FO27Q5P Review (Aug,17 2025 )

They Said my Gaming & Badminton Club Would Never OPEN! (Aug,17 2025 )

NVIDIA GeForce Game Ready 580.97 WHQL Driver (Aug,13 2025 )

When your Bro needs a new computer... (Aug,13 2025 )

WhatsApp's latest update is a huge "convenience" for group chats (Aug,12 2025 )

COLLAPSE: Intel is Falling Apart (Aug,12 2025 )

Useless or Genius: NVMe SSD Coolers (Aug,11 2025 )

2025 NEW! Audi A6 3.0 TFSI - BETTER than BMW 5? / (Aug,11 2025 )

Ryzen 7 5800X3D vs. 9800X3D, Battlefield 6 Open Beta Benchmark (Aug,10 2025 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs