📜 ⬆️ ⬇️

How on animeshniki cryptocurrency mined

In general, not only on them. Today, while watching anemone of some content, the loading of a suspicious js script was detected.

Removed under spoiler
image

It loaded one more wasm script:

Removed under spoiler
image

The required script was inserted into the iframe:

Removed under spoiler
image

Which looked like this:
')
Removed under spoiler
image

CPU utilization reached 100%:

Removed under spoiler
image

iframe traffic was kindly provided by these comrades:

Removed under spoiler
image

And the script is these:

Removed under spoiler
image

However, I liked their slogan. The script was monero miner in the web version.

Script itself: pastebin.com/raw/9ejjyFsN
Basic load: filebin.ca/3bTq9sInAOxJ

Here are the things here. This case occurred with one of the most popular sites of the RuNet according to alexa statistics . In the foreseeable future, for sure, the blockchain and miners will be even in our televisions.

The main consequence of this situation is a complete refusal to interact with left-wing advertisers, which allow you to insert arbitrary code into advertising.
UPD: the administration of the aforementioned site has already eliminated the problem and is now actively fighting off the crowd of haters. I would like to note once again that in this case, not so much the project, how much the advertiser. Guys, thank you for all these years.

Source: https://habr.com/ru/post/338580/


All Articles