Jump to content

Ad network uses advanced malware technique to conceal CPU-draining mining ads

2FA
Just now, Donut417 said:

It only works in Firefox. States that directly on the download page. 

RIP

 

I realized after posting.

 

There's this: https://chrome.google.com/webstore/detail/scriptsafe/oiigbmnaadbkfbmpbfijlflahbdbdgdf?hl=en-US

[Out-of-date] Want to learn how to make your own custom Windows 10 image?

 

Desktop: AMD R9 3900X | ASUS ROG Strix X570-F | Radeon RX 5700 XT | EVGA GTX 1080 SC | 32GB Trident Z Neo 3600MHz | 1TB 970 EVO | 256GB 840 EVO | 960GB Corsair Force LE | EVGA G2 850W | Phanteks P400S

Laptop: Intel M-5Y10c | Intel HD Graphics | 8GB RAM | 250GB Micron SSD | Asus UX305FA

Server 01: Intel Xeon D 1541 | ASRock Rack D1541D4I-2L2T | 32GB Hynix ECC DDR4 | 4x8TB Western Digital HDDs | 32TB Raw 16TB Usable

Server 02: Intel i7 7700K | Gigabye Z170N Gaming5 | 16GB Trident Z 3200MHz

Link to comment
Share on other sites

Link to post
Share on other sites

16 minutes ago, Energycore said:

image.png.bae89d641863b43ed626855002564429.png

I guess it could be worse.

12 tabs open, if you need more than 12 then you should reconsider your personal order :P

I can easily get over 100 tabs, but Mozilla thought it was a great idea to copy Chrome and add tab processes instead of making a more efficient browser lol.

Anyway looks like i have to add noscript on top of ublock & ghostery.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Energycore said:

No chrome in there :(

So.... Firefox for Android supports extensions. Like Ad Block....... How well does it work on a phone in terms of battery drain and performance? 

I just want to sit back and watch the world burn. 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Donut417 said:

So.... Firefox for Android supports extensions. Like Ad Block....... How well does it work on a phone in terms of battery drain and performance? 

From what I've used of it, it's not really any different than other standard capability browsers. Loads fast, though you have to be precise when touching buttons/links for it to register them whereas Chrome has a pretty large margin of error area when "clicking" stuff.

[Out-of-date] Want to learn how to make your own custom Windows 10 image?

 

Desktop: AMD R9 3900X | ASUS ROG Strix X570-F | Radeon RX 5700 XT | EVGA GTX 1080 SC | 32GB Trident Z Neo 3600MHz | 1TB 970 EVO | 256GB 840 EVO | 960GB Corsair Force LE | EVGA G2 850W | Phanteks P400S

Laptop: Intel M-5Y10c | Intel HD Graphics | 8GB RAM | 250GB Micron SSD | Asus UX305FA

Server 01: Intel Xeon D 1541 | ASRock Rack D1541D4I-2L2T | 32GB Hynix ECC DDR4 | 4x8TB Western Digital HDDs | 32TB Raw 16TB Usable

Server 02: Intel i7 7700K | Gigabye Z170N Gaming5 | 16GB Trident Z 3200MHz

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Donut417 said:

So.... Firefox for Android supports extensions. Like Ad Block....... How well does it work on a phone in terms of battery drain and performance? 

I actually use chrome on my phone since I basically don't ever use my phone for the internet xD

 

So I couldn't tell you.

1 minute ago, DeadEyePsycho said:

From what I've used of it, it's not really any different than other standard capability browsers. Loads fast, though you have to be precise when touching buttons/links for it to register them whereas Chrome has a pretty large margin of error area when "clicking" stuff.

Right, the way Chrome handles you hitting an area where a bunch of buttons are located I feel makes a lot of sense.

We have a NEW and GLORIOUSER-ER-ER PSU Tier List Now. (dammit @LukeSavenije stop coming up with new ones)

You can check out the old one that gave joy to so many across the land here

 

Computer having a hard time powering on? Troubleshoot it with this guide. (Currently looking for suggestions to update it into the context of <current year> and make it its own thread)

Computer Specs:

Spoiler

Mathresolvermajig: Intel Xeon E3 1240 (Sandy Bridge i7 equivalent)

Chillinmachine: Noctua NH-C14S
Framepainting-inator: EVGA GTX 1080 Ti SC2 Hybrid

Attachcorethingy: Gigabyte H61M-S2V-B3

Infoholdstick: Corsair 2x4GB DDR3 1333

Computerarmor: Silverstone RL06 "Lookalike"

Rememberdoogle: 1TB HDD + 120GB TR150 + 240 SSD Plus + 1TB MX500

AdditionalPylons: Phanteks AMP! 550W (based on Seasonic GX-550)

Letterpad: Rosewill Apollo 9100 (Cherry MX Red)

Buttonrodent: Razer Viper Mini + Huion H430P drawing Tablet

Auralnterface: Sennheiser HD 6xx

Liquidrectangles: LG 27UK850-W 4K HDR

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Energycore said:

Right, the way Chrome handles you hitting an area where a bunch of buttons are located I feel makes a lot of sense.

I like both ways to be honest. It's easy to hit the wrong link in Chrome, and it's easy to miss the link altogether in FF. Both problems are equally annoying to me.

[Out-of-date] Want to learn how to make your own custom Windows 10 image?

 

Desktop: AMD R9 3900X | ASUS ROG Strix X570-F | Radeon RX 5700 XT | EVGA GTX 1080 SC | 32GB Trident Z Neo 3600MHz | 1TB 970 EVO | 256GB 840 EVO | 960GB Corsair Force LE | EVGA G2 850W | Phanteks P400S

Laptop: Intel M-5Y10c | Intel HD Graphics | 8GB RAM | 250GB Micron SSD | Asus UX305FA

Server 01: Intel Xeon D 1541 | ASRock Rack D1541D4I-2L2T | 32GB Hynix ECC DDR4 | 4x8TB Western Digital HDDs | 32TB Raw 16TB Usable

Server 02: Intel i7 7700K | Gigabye Z170N Gaming5 | 16GB Trident Z 3200MHz

Link to comment
Share on other sites

Link to post
Share on other sites

42 minutes ago, Energycore said:

Oh that reminds me I don't have Ghostery enabled.

I got rid of it myself awhile back, did it stop being shit now?  What's the point in having it if they're just going to sell your data?

 

But anyways, NoScript is a must.  Surfing without NoScript is like rolling around naked in sewage and expecting not to get dirty.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, MoonSpot said:

I got rid of it myself awhile back, did it stop being shit now?  What's the point in having it if they're just going to sell your data?

I actually can't remember why I stopped using Ghostery, it's been a while. It may very well have been due to them selling user data, which completely defeats the purpose of the service they offer.

 

But my memory is worse than a bird's. Get it? No? Ok I'll see myself out.

We have a NEW and GLORIOUSER-ER-ER PSU Tier List Now. (dammit @LukeSavenije stop coming up with new ones)

You can check out the old one that gave joy to so many across the land here

 

Computer having a hard time powering on? Troubleshoot it with this guide. (Currently looking for suggestions to update it into the context of <current year> and make it its own thread)

Computer Specs:

Spoiler

Mathresolvermajig: Intel Xeon E3 1240 (Sandy Bridge i7 equivalent)

Chillinmachine: Noctua NH-C14S
Framepainting-inator: EVGA GTX 1080 Ti SC2 Hybrid

Attachcorethingy: Gigabyte H61M-S2V-B3

Infoholdstick: Corsair 2x4GB DDR3 1333

Computerarmor: Silverstone RL06 "Lookalike"

Rememberdoogle: 1TB HDD + 120GB TR150 + 240 SSD Plus + 1TB MX500

AdditionalPylons: Phanteks AMP! 550W (based on Seasonic GX-550)

Letterpad: Rosewill Apollo 9100 (Cherry MX Red)

Buttonrodent: Razer Viper Mini + Huion H430P drawing Tablet

Auralnterface: Sennheiser HD 6xx

Liquidrectangles: LG 27UK850-W 4K HDR

 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, MoonSpot said:

I got rid of it myself awhile back, did it stop being shit now?  What's the point in having it if they're just going to sell your data?

They were bought by a privacy focused German company called Cliqz last year. That also has the added of effect of the privacy rules of Germany also applying. Any telemetry they still have is optional.

[Out-of-date] Want to learn how to make your own custom Windows 10 image?

 

Desktop: AMD R9 3900X | ASUS ROG Strix X570-F | Radeon RX 5700 XT | EVGA GTX 1080 SC | 32GB Trident Z Neo 3600MHz | 1TB 970 EVO | 256GB 840 EVO | 960GB Corsair Force LE | EVGA G2 850W | Phanteks P400S

Laptop: Intel M-5Y10c | Intel HD Graphics | 8GB RAM | 250GB Micron SSD | Asus UX305FA

Server 01: Intel Xeon D 1541 | ASRock Rack D1541D4I-2L2T | 32GB Hynix ECC DDR4 | 4x8TB Western Digital HDDs | 32TB Raw 16TB Usable

Server 02: Intel i7 7700K | Gigabye Z170N Gaming5 | 16GB Trident Z 3200MHz

Link to comment
Share on other sites

Link to post
Share on other sites

Can't we just block access to all domains names that are nonsensical and suffer the inconvenience of having to white list as needed.  

 

Also I keep coming back to my idea of having a stripped down browser that can do nothing more than view pictures.  can't run scripts, can't execute anything. Has no permissions etc. 

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, mr moose said:

Can't we just block access to all domains names that are nonsensical and suffer the inconvenience of having to white list as needed.  

 

Also I keep coming back to my idea of having a stripped down browser that can do nothing more than view pictures.  can't run scripts, can't execute anything. Has no permissions etc. 

I think the best we can do is for someone trustworthy to create a curated noscript list of allowed domains, then you uploading that to your extension. I know AdBlock did that when I first installed it (I'm now on ublock instead)

We have a NEW and GLORIOUSER-ER-ER PSU Tier List Now. (dammit @LukeSavenije stop coming up with new ones)

You can check out the old one that gave joy to so many across the land here

 

Computer having a hard time powering on? Troubleshoot it with this guide. (Currently looking for suggestions to update it into the context of <current year> and make it its own thread)

Computer Specs:

Spoiler

Mathresolvermajig: Intel Xeon E3 1240 (Sandy Bridge i7 equivalent)

Chillinmachine: Noctua NH-C14S
Framepainting-inator: EVGA GTX 1080 Ti SC2 Hybrid

Attachcorethingy: Gigabyte H61M-S2V-B3

Infoholdstick: Corsair 2x4GB DDR3 1333

Computerarmor: Silverstone RL06 "Lookalike"

Rememberdoogle: 1TB HDD + 120GB TR150 + 240 SSD Plus + 1TB MX500

AdditionalPylons: Phanteks AMP! 550W (based on Seasonic GX-550)

Letterpad: Rosewill Apollo 9100 (Cherry MX Red)

Buttonrodent: Razer Viper Mini + Huion H430P drawing Tablet

Auralnterface: Sennheiser HD 6xx

Liquidrectangles: LG 27UK850-W 4K HDR

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, mr moose said:

Can't we just block access to all domains names that are nonsensical and suffer the inconvenience of having to white list as needed.

You can do that with uBlock.

 

2 minutes ago, mr moose said:

Also I keep coming back to my idea of having a stripped down browser that can do nothing more than view pictures.  can't run scripts, can't execute anything. Has no permissions etc.

That sounds awful from a practical standpoint, and wholly unnecessary for regular users. I understand your reasoning but more and more of internet is relying on JS for functionality.

[Out-of-date] Want to learn how to make your own custom Windows 10 image?

 

Desktop: AMD R9 3900X | ASUS ROG Strix X570-F | Radeon RX 5700 XT | EVGA GTX 1080 SC | 32GB Trident Z Neo 3600MHz | 1TB 970 EVO | 256GB 840 EVO | 960GB Corsair Force LE | EVGA G2 850W | Phanteks P400S

Laptop: Intel M-5Y10c | Intel HD Graphics | 8GB RAM | 250GB Micron SSD | Asus UX305FA

Server 01: Intel Xeon D 1541 | ASRock Rack D1541D4I-2L2T | 32GB Hynix ECC DDR4 | 4x8TB Western Digital HDDs | 32TB Raw 16TB Usable

Server 02: Intel i7 7700K | Gigabye Z170N Gaming5 | 16GB Trident Z 3200MHz

Link to comment
Share on other sites

Link to post
Share on other sites

56 minutes ago, DeadEyePsycho said:

I like both ways to be honest. It's easy to hit the wrong link in Chrome, and it's easy to miss the link altogether in FF. Both problems are equally annoying to me.

I prefer Firefox myself, though it's lacking performance (especially in scrolling) brings me back to Chrome.

My eyes see the past…

My camera lens sees the present…

Link to comment
Share on other sites

Link to post
Share on other sites

17 minutes ago, mr moose said:

Can't we just block access to all domains names that are nonsensical and suffer the inconvenience of having to white list as needed.  

 

Also I keep coming back to my idea of having a stripped down browser that can do nothing more than view pictures.  can't run scripts, can't execute anything. Has no permissions etc. 

Your anti-virus program can do that automatically as they constantly update their blacklisted sites which includes stealthy cryptomining scripts.

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, hey_yo_ said:

Your anti-virus program can do that automatically as they constantly update their blacklisted sites which includes stealthy cryptomining scripts.

I thought the problem was they could generate more domains than the AV could list.

 

 

17 minutes ago, DeadEyePsycho said:

You can do that with uBlock.

 

That sounds awful from a practical standpoint, and wholly unnecessary for regular users. I understand your reasoning but more and more of internet is relying on JS for functionality.

 

It would just be for sites that are non interactive, like news sites, company information and PDF downloads and things like looking at timetables for trains.

 

You'd still need another browser for all the interactive stuff like forums, banking, anything with complex search functions, etc.

 

I personally like the idea of an ad not being able to be anything other than be a picture that hyperlinks to a website.

 

 

 

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, mr moose said:

I thought the problem was they could generate more domains than the AV could list.

Some AV programs detect behavior and don't rely on signatures so in the likelihood that someone comes up with a new mining script, the AV program detects the untrusted behavior characteristic of a cryptomining script and blocks it from executing and a lot of them constantly report unusual behavior to the AV cloud servers for analysis.

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Firefox Quantum is much better for crappy computers without too much RAM.

 

With 4GB RAM and some random laptop Pentium from the core-2-duo days, firefox runs pretty well with 6 tabs, though the fans start spinning up.

Chrome just gets basically shut off at 4 tabs, and start-up takes much longer.

Want to know which mobo to get?

Spoiler

Choose whatever you need. Any more, you're wasting your money. Any less, and you don't get the features you need.

 

Only you know what you need to do with your computer, so nobody's really qualified to answer this question except for you.

 

chEcK iNsidE sPoilEr fOr a tREat!

Link to comment
Share on other sites

Link to post
Share on other sites

Or, ya know, you can just press ctrl + W the instant you get a pop add, or hover over the browser and check what's open and close all the shit you didn't open. It's really not much of a hassle

I spent $2500 on building my PC and all i do with it is play no games atm & watch anime at 1080p(finally) watch YT and write essays...  nothing, it just sits there collecting dust...

Builds:

The Toaster Project! Northern Bee!

 

The original LAN PC build log! (Old, dead and replaced by The Toaster Project & 5.0)

Spoiler

"Here is some advice that might have gotten lost somewhere along the way in your life. 

 

#1. Treat others as you would like to be treated.

#2. It's best to keep your mouth shut; and appear to be stupid, rather than open it and remove all doubt.

#3. There is nothing "wrong" with being wrong. Learning from a mistake can be more valuable than not making one in the first place.

 

Follow these simple rules in life, and I promise you, things magically get easier. " - MageTank 31-10-2016

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, mr moose said:

I thought the problem was they could generate more domains than the AV could list.

The malware/script must use the correct domain to get the script. For this to occur it must be able to deterministically generate the domains , each entity must generate the same domains , hence there must be a hard coded algorithm for the domains as well as a limited time span over which they are valid.

The AV or NoScript whitelist only needs to generate the currently available domains and block these / place warnings on them if they generate conventional domains. 

 

6 hours ago, mr moose said:

It would just be for sites that are non interactive, like news sites, company information and PDF downloads and things like looking at timetables for trains.

 

I personally like the idea of an ad not being able to be anything other than be a picture that hyperlinks to a website.

You can whitelist / blacklist domains.

Sadly the image idea , although great, will not be implemented as "It would be less effective".

 

6 hours ago, hey_yo_ said:

Some AV programs detect behavior and don't rely on signatures so in the likelihood that someone comes up with a new mining script, the AV program detects the untrusted behavior characteristic of a cryptomining script and blocks it from executing and a lot of them constantly report unusual behavior to the AV cloud servers for analysis.

A script could then be adjusted to run using a PWM type system, not running the entire time so that it is not noticed by the user and is not classed as "suspicious" by an AV.

Link to comment
Share on other sites

Link to post
Share on other sites

18 minutes ago, ScratchCat said:

A script could then be adjusted to run using a PWM type system, not running the entire time so that it is not noticed by the user and is not classed as "suspicious" by an AV.

I don't know what a PWM type system is but just as I've said before, they crawl the internet all the time to classify sites, scripts and applications as malicious or not (cloud protection). I know that malware made sophisticated can slip past an anti-virus, my anti-virus program has never failed me in blocking mining scripts.

Spoiler

image.png.e523640a6a1f4bf778fd35b50f066ed6.pngimage.png.413332d116987b9687e18a872a9a4508.png

 

Edited by hey_yo_

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Luckily I cannot even recall browsing without noscript and Ublock. It is a bit of a hassle for the first few days to whitelist what needs to be white listed, but after that it is wonderful and you quickly learn what to white list and what not when visiting new pages.

 

Still sucks that this is all needed though.

"Hope, what a concept." - Deunan Knute

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, mr moose said:

It would just be for sites that are non interactive, like news sites, company information and PDF downloads and things like looking at timetables for trains.

In the tone of "Your call could not be connected. Please check the number and try again"

"Your browser could not load Sydney trains timetable, please check your browser settings and try again. JS not found"

 

Pretty much Sydney trains site is full of js interactivity

Western Sydney University - 4th year BCompSc student

Link to comment
Share on other sites

Link to post
Share on other sites

Windows should really be more proactive and not allow just any software to hijack either cpu or gpu. The large majority of people have no clue what ad blocks, no scripts is.

 

Another thing is websites should be more responsible with their ads, they keep asking to turn off adblock and when you do all hell breaks lose, even if it is not a hardware scam is some weird ads full of scams, weird shit that cures cancer with a banana. This even in high profile websites. Let alone discuss those pages that are half ads, half content, in your face bright colors, flashy ads.

 

.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×