Attackers built a cryptojacking botnet by exploiting CVE-2017-7269, a WebDAV buffer overflow in unpatched Microsoft IIS 6.0 servers running on Windows Server 2003. The campaign, active since at least May 2017, used internet-wide scanning from Amazon Web Services-hosted IP addresses to find vulnerable systems and then delivered shellcode that downloaded and executed a minimally modified version of the open-source xmrig miner.
The compromised servers were used to mine Monero, with the operation reportedly growing to several hundred machines and generating more than 420 XMR, worth over $63,000 at the time. ESET said it detected the miner as Win32/CoinMiner.AMW and the exploit traffic as webDAV/ExplodingCan, and urged administrators to apply Microsoft patch KB3197835 and other critical updates to protect exposed legacy servers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
In late August 2017, the combined victim hash rate peaked near 160 kH/s. By the end of August, infected machines were generating about XMR5.5 per day.
Microsoft did not release a patch for CVE-2017-7269 until June 2017, when it issued KB3197835 for affected Windows Server 2003 systems. The patch addressed the exploited IIS 6.0 WebDAV vulnerability.
A malicious Monero miner based on xmrig was first seen in the wild on 2017-05-26. The malware was used to turn compromised IIS servers into cryptomining nodes.
From at least May 2017 and over roughly three months, attackers exploited unpatched IIS 6.0 servers to build a botnet of several hundred machines for Monero mining. The campaign used internet-wide scanning, including AWS-hosted infrastructure, and earned more than XMR420.
The first observed real-world exploitation of CVE-2017-7269 occurred on 2017-03-26, two days after publication according to the source. Attackers used crafted WebDAV requests to trigger the flaw.
The IIS 6.0 WebDAV buffer overflow tracked as CVE-2017-7269 was discovered in March 2017 by Zhiniang Peng and Chen Wu. The flaw affected Windows Server 2003 R2 systems running IIS 6.0.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.