Page 1 of 2 12 LastLast
Results 1 to 16 of 20

Thread: Hexus crypto miner

  1. #1
    Senior Member
    Join Date
    Aug 2009
    Location
    UK
    Posts
    431
    Thanks
    20
    Thanked
    33 times in 27 posts
    • Jace007's system
      • CPU:
      • Intel i7 7700k
      • Memory:
      • 16GB
      • Storage:
      • 500GB SSD
      • Graphics card(s):
      • nVidia 1080
      • PSU:
      • EVGA 750w
      • Operating System:
      • WinLOW

    Hexus crypto miner

    Hi, recently my AV (Eset) software is picking up crypto mine malware on your hexus website and the left & right hand side Adverts are being blocked. Something like j.f coin or J.coin
    I thought i'll let you know.

    Log;
    (Please dont click on the URL)
    Time;Scanner;Object type;Object;Threat;Action;User;Information;Hash;First seen here
    11/12/2017 11:45:54;JavaScript scanner;file;http://www.thefashiondistrict.net/a-...JS/CoinMiner.F potentially unwanted application;blocked;

  2. Received thanks from:

    Kanoe (13-12-2017),Millennium (11-12-2017)

  3. #2
    Administrator MLyons's Avatar
    Join Date
    Feb 2017
    Posts
    470
    Thanks
    303
    Thanked
    155 times in 91 posts
    • MLyons's system
      • Motherboard:
      • ASUS PRIME X470-PRO
      • CPU:
      • 2700x
      • Memory:
      • 16GB DDR4 Corsair RGB
      • Storage:
      • 500GB MX500 500GB HDD 2TB SSD
      • Graphics card(s):
      • EVGA SC2 1080Ti
      • PSU:
      • Corsair tx650
      • Case:
      • Corsair Air 540
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 2 Asus 1080p

    Re: Hexus crypto miner

    Quote Originally Posted by Jace007 View Post
    Hi, recently my AV (Eset) software is picking up crypto mine malware on your hexus website and the left & right hand side Adverts are being blocked. Something like j.f coin or J.coin
    I thought i'll let you know.

    Log;
    (Please dont click on the URL)
    Time;Scanner;Object type;Object;Threat;Action;User;Information;Hash;First seen here
    11/12/2017 11:45:54;JavaScript scanner;file;http://www.thefashiondistrict.net/a-...JS/CoinMiner.F potentially unwanted application;blocked;
    Which ones exactly? Do you mean the site skins "behind" the site? Mind sending me a screenshot highlighting which ones?
    Half dev, Half doge. Some say DevDoge

    Feel free to message me if you find any bugs or have any suggestions.
    If you need me urgently, PM me
    If something is/was broke it was probably me. ¯\_(ツ)_/¯

  4. #3
    root Member DanceswithUnix's Avatar
    Join Date
    Jan 2006
    Location
    In the middle of a core dump
    Posts
    12,333
    Thanks
    714
    Thanked
    1,406 times in 1,188 posts
    • DanceswithUnix's system
      • Motherboard:
      • Asus X470-PRO
      • CPU:
      • 3700X
      • Memory:
      • 32GB 3200MHz ECC
      • Storage:
      • 1TB Linux, 1TB Games (Win 10)
      • Graphics card(s):
      • Asus Strix RX Vega 56
      • PSU:
      • 650W Corsair TX
      • Case:
      • Antec 300
      • Operating System:
      • Fedora 33 + Win 10 Pro 64 (yuk)
      • Monitor(s):
      • Benq XL2730Z 1440p + Iiyama 27" 1440p
      • Internet:
      • Zen 80Mb/20Mb VDSL

    Re: Hexus crypto miner

    and there was me thinking the site had started a crypto currency. Not sure what you would buy with HexusCoin mind

  5. #4
    Administrator MLyons's Avatar
    Join Date
    Feb 2017
    Posts
    470
    Thanks
    303
    Thanked
    155 times in 91 posts
    • MLyons's system
      • Motherboard:
      • ASUS PRIME X470-PRO
      • CPU:
      • 2700x
      • Memory:
      • 16GB DDR4 Corsair RGB
      • Storage:
      • 500GB MX500 500GB HDD 2TB SSD
      • Graphics card(s):
      • EVGA SC2 1080Ti
      • PSU:
      • Corsair tx650
      • Case:
      • Corsair Air 540
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 2 Asus 1080p

    Re: Hexus crypto miner

    Quote Originally Posted by DanceswithUnix View Post
    and there was me thinking the site had started a crypto currency. Not sure what you would buy with HexusCoin mind
    Hmmm. Wonder how easy this would be to setup.
    Half dev, Half doge. Some say DevDoge

    Feel free to message me if you find any bugs or have any suggestions.
    If you need me urgently, PM me
    If something is/was broke it was probably me. ¯\_(ツ)_/¯

  6. #5
    Senior Member
    Join Date
    Aug 2009
    Location
    UK
    Posts
    431
    Thanks
    20
    Thanked
    33 times in 27 posts
    • Jace007's system
      • CPU:
      • Intel i7 7700k
      • Memory:
      • 16GB
      • Storage:
      • 500GB SSD
      • Graphics card(s):
      • nVidia 1080
      • PSU:
      • EVGA 750w
      • Operating System:
      • WinLOW

    Re: Hexus crypto miner

    Mylons Yes the site skins with the Adverts. Is shows it as Threat JS/CoinMiner.F - My AV has blocked it 3 times, Even after clearing my chrome browser data.

  7. #6
    Administrator MLyons's Avatar
    Join Date
    Feb 2017
    Posts
    470
    Thanks
    303
    Thanked
    155 times in 91 posts
    • MLyons's system
      • Motherboard:
      • ASUS PRIME X470-PRO
      • CPU:
      • 2700x
      • Memory:
      • 16GB DDR4 Corsair RGB
      • Storage:
      • 500GB MX500 500GB HDD 2TB SSD
      • Graphics card(s):
      • EVGA SC2 1080Ti
      • PSU:
      • Corsair tx650
      • Case:
      • Corsair Air 540
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 2 Asus 1080p

    Re: Hexus crypto miner

    Quote Originally Posted by Jace007 View Post
    Mylons Yes the site skins with the Adverts. Is shows it as Threat JS/CoinMiner.F - My AV has blocked it 3 times, Even after clearing my chrome browser data.
    Odd, the page containing the mining JS file is now throwing what seems to be a legit 404. Is this happening every load of the page. Please can you link me the exact HEXUS page this happened on.
    Half dev, Half doge. Some say DevDoge

    Feel free to message me if you find any bugs or have any suggestions.
    If you need me urgently, PM me
    If something is/was broke it was probably me. ¯\_(ツ)_/¯

  8. #7
    HEXUS.timelord. Zak33's Avatar
    Join Date
    Jul 2003
    Location
    I'm a Jessie
    Posts
    35,157
    Thanks
    3,105
    Thanked
    3,138 times in 1,916 posts
    • Zak33's system
      • Storage:
      • Kingston HyperX SSD, Hitachi 1Tb
      • Graphics card(s):
      • Nvidia 1050
      • PSU:
      • Coolermaster 800w
      • Case:
      • Silverstone Fortress FT01
      • Operating System:
      • Win10
      • Internet:
      • Zen FTC uber speedy

    Re: Hexus crypto miner

    Hi Jace

    I've just instaled ESET 30 day trial to see how this shows up.

    So far nothing, so please can you tell me : Does it do it every visit?

    Quote Originally Posted by Advice Trinity by Knoxville
    "The second you aren't paying attention to the tool you're using, it will take your fingers from you. It does not know sympathy." |
    "If you don't gaffer it, it will gaffer you" | "Belt and braces"

  9. #8
    HEXUS.timelord. Zak33's Avatar
    Join Date
    Jul 2003
    Location
    I'm a Jessie
    Posts
    35,157
    Thanks
    3,105
    Thanked
    3,138 times in 1,916 posts
    • Zak33's system
      • Storage:
      • Kingston HyperX SSD, Hitachi 1Tb
      • Graphics card(s):
      • Nvidia 1050
      • PSU:
      • Coolermaster 800w
      • Case:
      • Silverstone Fortress FT01
      • Operating System:
      • Win10
      • Internet:
      • Zen FTC uber speedy

    Re: Hexus crypto miner

    I've been to check it's working, and it detected Coinhive instantly, but I'm pleased to say so far no HEXUS pages have gone ping on the radar.

    I will keep checking, but please keep me posted too

    Quote Originally Posted by Advice Trinity by Knoxville
    "The second you aren't paying attention to the tool you're using, it will take your fingers from you. It does not know sympathy." |
    "If you don't gaffer it, it will gaffer you" | "Belt and braces"

  10. #9
    Senior Member
    Join Date
    Aug 2009
    Location
    UK
    Posts
    431
    Thanks
    20
    Thanked
    33 times in 27 posts
    • Jace007's system
      • CPU:
      • Intel i7 7700k
      • Memory:
      • 16GB
      • Storage:
      • 500GB SSD
      • Graphics card(s):
      • nVidia 1080
      • PSU:
      • EVGA 750w
      • Operating System:
      • WinLOW

    Re: Hexus crypto miner

    hey Zak, I've gone to another PC now, after going into the main page and then at Random going into different pages its pop up again
    Its strange i've never seen this before on Hexus - thou it mentions a File on my Computers, Its only when i'm on the hexus site. No other sites gets this & I have run a full Av & malware scan of both Pcs. maybe a False positive i'm not sure

    http://tinypic.com/r/1234coo/9

  11. #10
    HEXUS.timelord. Zak33's Avatar
    Join Date
    Jul 2003
    Location
    I'm a Jessie
    Posts
    35,157
    Thanks
    3,105
    Thanked
    3,138 times in 1,916 posts
    • Zak33's system
      • Storage:
      • Kingston HyperX SSD, Hitachi 1Tb
      • Graphics card(s):
      • Nvidia 1050
      • PSU:
      • Coolermaster 800w
      • Case:
      • Silverstone Fortress FT01
      • Operating System:
      • Win10
      • Internet:
      • Zen FTC uber speedy

    Re: Hexus crypto miner

    tis strange

    that IS the same pop up I get when going to a known coinminer site but we're not doing that, and won't

    You've got an ad blocker running, as we have a Site Skin running and I cant see it on your screenshot. Does it still do it if you turn Ad Blocker off?

    Quote Originally Posted by Advice Trinity by Knoxville
    "The second you aren't paying attention to the tool you're using, it will take your fingers from you. It does not know sympathy." |
    "If you don't gaffer it, it will gaffer you" | "Belt and braces"

  12. #11
    Senior Member
    Join Date
    Aug 2009
    Location
    UK
    Posts
    431
    Thanks
    20
    Thanked
    33 times in 27 posts
    • Jace007's system
      • CPU:
      • Intel i7 7700k
      • Memory:
      • 16GB
      • Storage:
      • 500GB SSD
      • Graphics card(s):
      • nVidia 1080
      • PSU:
      • EVGA 750w
      • Operating System:
      • WinLOW

    Re: Hexus crypto miner

    I dont have any Ad blocker extension. Whatever its stopping is straight from eset nod32

    How much money have you collected eh eh ?

  13. #12
    root Member DanceswithUnix's Avatar
    Join Date
    Jan 2006
    Location
    In the middle of a core dump
    Posts
    12,333
    Thanks
    714
    Thanked
    1,406 times in 1,188 posts
    • DanceswithUnix's system
      • Motherboard:
      • Asus X470-PRO
      • CPU:
      • 3700X
      • Memory:
      • 32GB 3200MHz ECC
      • Storage:
      • 1TB Linux, 1TB Games (Win 10)
      • Graphics card(s):
      • Asus Strix RX Vega 56
      • PSU:
      • 650W Corsair TX
      • Case:
      • Antec 300
      • Operating System:
      • Fedora 33 + Win 10 Pro 64 (yuk)
      • Monitor(s):
      • Benq XL2730Z 1440p + Iiyama 27" 1440p
      • Internet:
      • Zen 80Mb/20Mb VDSL

    Re: Hexus crypto miner

    I noticed when viewing https://hexus.net/tech/news/storage/...mr-technology/
    that the task manager I just happened to have open jumped to 50% on all 8 cores. That is the latest Firefox on Windows.

  14. #13
    Bagnaj97
    Guest

    Re: Hexus crypto miner

    From the Chome profiling tool in the dev console, on the link DanceswithUnix posted:



    Definitely mining going on, cryptonight is the algorithm used for Monero mining. With adblock enabled, no mining.



    It's coming from https://api.300ca0d0.space/ or at least https://api.300ca0d0.space/lib/ is in the JS.
    Last edited by Bagnaj97; 12-12-2017 at 10:23 AM.

  15. #14
    Not a good person scaryjim's Avatar
    Join Date
    Jan 2009
    Location
    Gateshead
    Posts
    15,196
    Thanks
    1,230
    Thanked
    2,291 times in 1,874 posts
    • scaryjim's system
      • Motherboard:
      • Dell Inspiron
      • CPU:
      • Core i5 8250U
      • Memory:
      • 2x 4GB DDR4 2666
      • Storage:
      • 128GB M.2 SSD + 1TB HDD
      • Graphics card(s):
      • Radeon R5 230
      • PSU:
      • Battery/Dell brick
      • Case:
      • Dell Inspiron 5570
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 15" 1080p laptop panel

    Re: Hexus crypto miner

    I'm very suspicious of a script being loaded from zenoviaexchange.com, which is hugely obfuscated.

    I honestly wouldn't mind too much if Hexus was using a background miner instead of adverts (particularly if it was throttled like this one, which is only tapping ~ 40% CPU usage on my laptop), but I rather suspect this is an advert that's running it surreptitiously in the background and Hexus isn't getting the benefit...

  16. Received thanks from:

    MLyons (12-12-2017)

  17. #15
    HEXUS.timelord. Zak33's Avatar
    Join Date
    Jul 2003
    Location
    I'm a Jessie
    Posts
    35,157
    Thanks
    3,105
    Thanked
    3,138 times in 1,916 posts
    • Zak33's system
      • Storage:
      • Kingston HyperX SSD, Hitachi 1Tb
      • Graphics card(s):
      • Nvidia 1050
      • PSU:
      • Coolermaster 800w
      • Case:
      • Silverstone Fortress FT01
      • Operating System:
      • Win10
      • Internet:
      • Zen FTC uber speedy

    Re: Hexus crypto miner

    we utterly are not deliberately running a miner.

    We're trying to replicate it, and will keep at it.

    Quote Originally Posted by Advice Trinity by Knoxville
    "The second you aren't paying attention to the tool you're using, it will take your fingers from you. It does not know sympathy." |
    "If you don't gaffer it, it will gaffer you" | "Belt and braces"

  18. #16
    Bagnaj97
    Guest

    Re: Hexus crypto miner


  19. Received thanks from:

    scaryjim (12-12-2017)

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •