Since April this year, Zoom has been protecting all conferences with a mandatory six-digit numeric…
It became enough for users to “unsuccessfully” go to any site with a special JavaScript Coinhive (or other similar service, of which there were dozens of them) embedded in the code, and the resources of the victims’ machines were already used to extract the Monero cryptocurrency. Although the Coinhive operators admitted that they did not want to create a tool for enriching cybercriminals at all and directly condemned the actions of the cybercriminals.
At its peak, Coinhive has been embedded in 200,000 routers, browser extensions, Microsoft Store apps, and even government websites.
However, in the end, in the spring of 2019, the service closed a year after the Monero hard fork, as the hash rate fell by more than 50%. In addition, the decision of the Coinhive developers influenced the overall “collapse” of the cryptocurrency market, since then XMR lost about 85% of its value.
As the founder of the leak aggregator Have I Been Pwned (HIBP) Troy Hunt now says in a blog post, he was given access to coinhive.com and other related domains for free, with the condition that he did something useful with them:
“In May 2020, I gained control of both the primary domain coinhive.com and several other secondary domains associated with the service, such as cnhv.co, which was used to shorten links (which also forced browsers to mine Monero). I’m not sure how much the person who provided me with these domains wants publicity, so the only thing I’ll say now is that they were provided to me for free to do something useful.”
Since the domains are hosted behind the Cloudflare, Hunt used built-in analytics and found that a huge number of visitors were still trying to download JavaScript from Coinhive.
While analyzing sites that are still driving traffic to Coinhive domains, Hunt noticed that scripts are active mainly on Chinese and Russian websites. Most of this traffic can be attributed to hacked MikroTik routers, which continue to inject Coinhive scripts whenever users visit any site.
In the end, the expert decided that he was using the coinhive.com domain to redirect people to his blog post about Coinhive. So, if people visit sites with Coinhive scripts, they see a dialog box that will warn them: “This site tried to run a cryptominer in your browser.” Moreover, the warning is a link that users can click on and learn more about Coinhive.
While Hunt is doing a good thing, the Coinhive example clearly shows that attackers can use abandoned domains to inject scripts into the browsers of unsuspecting visitors.
“Now I can run any JavaScript I want on a huge number of sites. So what could I do with JavaScript? I could make changes to how forms work, implement a keylogger, change the DOM, make external requests, redirect [visitors] to malicious files, and do other nasty things. This is the kind of power you give [to outsiders] when you embed someone else’s JS into your site, and that’s why sub-resource integrity is needed”, — warns Hunt.
Recall that After closure of Coinhive the number of crypto-jacking attacks decreased by 99%.
Kurlibat.xyz is a site that tries to trick you into clik to its browser notifications…
Initiateintenselyrenewedthe-file.top is a domain that tries to trick you into clik to its browser notifications…
Wotigorn.xyz is a site that tries to force you into subscribing to its browser notifications…
Initiateintenselyprogressivethe-file.top is a domain that tries to force you into clik to its browser notifications…
Nuesobatoxylors.co.in is a domain that tries to trick you into subscribing to its browser notifications…
Helistym.xyz is a site that tries to force you into clik to its browser notifications…