Threat actors targeted are exploiting the ProxyLogon vulnerabilities in Microsoft Exchange servers to deploy Monero cryptocurrency miners. The attack used a. PowerShell command to retrieve a file named win_r.zip from another compromised servers Outlook Web Access logon path. The.zip file was not a compressed archive, but a batch script that then invoked the built-into-Windows certutil.exe program to download the. win_s.zip and win_d.zip files. The miners pools.txt file is temporarily written to disk, its analysis allowed the researchers to determine the wallet address and its password, and the name DRUGS.”]
Source: https://securityaffairs.co/wordpress/116955/cyber-crime/proxylogon-flaws-cryptocurrencyminer.html

