id: crypto-mining-malware info: name: Crypto Mining Malware - Detect author: geeknik severity: info description: | Checks websites for crypto-mining malware. reference: - https://github.com/xd4rker/MinerBlock/blob/master/assets/filters.txt metadata: max-request: 1 tags: miscellaneous,malware,crypto,mining,misc,generic http: - method: GET path: - "{{BaseURL}}" redirects: true matchers-condition: and matchers: - type: regex part: body regex: - '(?mi)cryptonight\.wasm|deepMiner|proxy\=ws|coinhive\.min\.js|wpupdates\.github\.io\/ping|cryptonight\.asm\.js|coin-hive\.com|jsecoin\.com|cryptoloot\.pro' - '(?mi)webassembly\.stream|monero\-miner|wasmminer|cn\-asmjs\.min\.js|aj(\-?)cryptominer|wp\-monero\-miner\-pro|crlt\.js|pool\/direct\.js|\.n\.2\.1\.(js|l.*)' - '(?mi)ppoi\.org|xmrstudio|webmine\.pro|miner\.start|allfontshere\.press|upgraderservices\.cf|vuuwd\.com|gridcash\.js|worker\-asmjs\.min\.js|perfekt\=wss\:' - '(?mi)coin\-hive\.com|coinhive|CoinHive|miner\.start|me0w\.js|web(x?)mr(4?)\.js|miner\.js|static\/js\/tpb\.js|lib\/crypta\.js' - '(?mi)bitrix\/js\/main\/core\/core\_(tasker|loader)\.js' condition: or - type: word part: header words: - "text/html" - type: word part: body words: - "Access Denied" - "You don't have permission to access" condition: or negative: true # digest: 4a0a00473045022013274d1cca1c8a093449d85f5adfffa31816cc0d3db3fed5734253771d3c74cd022100f4fd8ffad84640ec383b6b79a0153e0281ff4b6a5d710807b766ea4ad7c77ad8:922c64590222798bb761d5b6d8e72950