Author Topic: Coinhive miner script detected on website...  (Read 1367 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Coinhive miner script detected on website...
« on: August 18, 2018, 10:59:46 PM »
See: https://webcookies.org/cookies/coinhive.com/14521137
on
Re: https://webcookies.org/cookies/donpet.es/19060608
Re: https://urlquery.net/report/92235595-895e-433d-8fe7-3d4b12922ec9
Flagged here: https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=www.vitabelia.com&ref_sel=none&ua_sel=ff&fs=1
Problems in this file: -wp-content/uploads/custom-css-js/269253.js?v=7530
Reputation Check
PASSED
Google Safe Browse: OK
Spamhaus Check: OK
Compromised Hosts: OK
Dshield Blocklist: OK
Shadowserver C&C: OK
Web Server:
nginx
X-Powered-By:
PleskLin
IP Address:
92.222.8.139
Hosting Provider:
OVH SAS 
Shared Hosting:
11 sites found on 92.222.8.139

Suspicious max runtime exceeded by -www.vitabelia.com/wp-content/plugins/UVC_Addons/assets/js/SmoothScroll.js?ver=3.8.0

error
Quote
[script] stats.wp.com/e-201833.js
     info: [decodingLevel=0] found JavaScript
     error: line:65: SyntaxError: invalid label:
          error: line:65: ;{"@context":"-http:\/\/schema.org","@type":"WebSite","@id":"#website","url":"-http:\/\/www.vitabelia.com\/","name":"Vitabelia","potentialAction":{"@type":"SearchAction","target":"-http:\/\/www.vitabelia.com\/?s={string}","query-input":"required
          error: line:65: ..^
     error: line:3: SyntaxError: missing = in XML attribute:
          error: line:3: <!DOCTYPE html>
          error: line:3: ..............^
     file: 999635c521e2c8373e73ade479eb97096b78e042: 57825 bytes
and
Quote
(script) -www.vitabelia.com/wp-content/themes/captiva-child/js/masonry-archive.js?ver=1.0.0
     status: (referer=-www.vitabelia.com/)saved 7959 bytes 53764627610724b699e23d239a82c9fe2a46c54a
     info: [decodingLevel=0] found JavaScript
     error: undefined variable jQuery
     error: undefined function jQuery
     suspicious: maxruntime exceeded 10 seconds (incomplete) 0 bytes
     file: 53764627610724b699e23d239a82c9fe2a46c54a: 7959 bytes
     file: 8810f5d3fe5bbc85c8f1d3cb1c5f27be1ae9c447: 8281 bytes
     file: 5aff49f42f4ebe8bc00c9943865fab6df8656507: 8490 bytes
     file: 46740fd8df5813aa3fec8b0d3917280bd89cfe4a: 8682 bytes
     file: fd287f54582430a4e6f09f97a45b0dbb8726b877: 8396 bytes
     file: 9ccf35d739a854d60d7e030d69cb4c4ea528b694: 8520 bytes 
&
Quote
[iframe] -www.vitabelia.com/wp-content/plugins/contact-form-7/includes/js/
     info: [decodingLevel=0] found JavaScript
     error: undefined function e
     file: 374aa1f8db17575b0e35eabc46ad82062e09106c: 15248 bytes


polonus [volunteer website security analyst and website error-hunter)
« Last Edit: August 18, 2018, 11:02:31 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Coinhive miner script detected on website...
« Reply #1 on: August 18, 2018, 11:16:34 PM »
Also quite some deadlinks there:
##/s.gravatar.com/
##/fonts.googleapis.com/
##/s.w.org/
##/netdna.bootstrapcdn.com/
##/s0.wp.com/
##/comments/
##/fonts.googleapis.com
##/s.gravatar.com
##/s.w.org
##/netdna.bootstrapcdn.com
##/s0.wp.c
##/wp-includes/wlwmanifest.xml/
##/v0.wordpress.com/
##/i0.wp.com/
##/i2.wp.com/
##/i1.wp.com/
##/v0.wordpress.com
##/reblog
##/i2.wp.com
##/i1.wp.com
##/sitemap_index.xml
##/i0.wp.com
##/padres/netdna.bootstrapcdn.com
##/padres/s.gravatar.com
##/padres/fonts.googleapis.com
##/padres/s0.wp.com
##/padres/s.w.org
##/profesionales/fonts.googleapis.com
##/profesionales/s.gravatar.com
##/profesionales/s0.wp.com
##/profesionales/netdna.bootstrapcdn.com
##/reblog/s0.wp.com
##/reblog/fonts.googleapis.com
##/category/
##/profesionales/s.w.org
##/reblog/s.gravatar.com

pol
« Last Edit: August 18, 2018, 11:19:07 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!