id: crypto-mining-malware info: name: Crypto Mining Malware - Detect author: geeknik severity: info description: | Checks websites for crypto-mining malware. reference: - https://github.com/xd4rker/MinerBlock/blob/master/assets/filters.txt metadata: max-request: 1 tags: malware,crypto,mining,misc,generic http: - method: GET path: - "{{BaseURL}}" redirects: true matchers-condition: and matchers: - type: regex part: body regex: - '(?mi)cryptonight\.wasm|deepMiner|proxy\=ws|coinhive\.min\.js|wpupdates\.github\.io\/ping|cryptonight\.asm\.js|coin-hive\.com|jsecoin\.com|cryptoloot\.pro' - '(?mi)webassembly\.stream|monero\-miner|wasmminer|cn\-asmjs\.min\.js|aj(\-?)cryptominer|wp\-monero\-miner\-pro|crlt\.js|pool\/direct\.js|\.n\.2\.1\.(js|l.*)' - '(?mi)ppoi\.org|xmrstudio|webmine\.pro|miner\.start|allfontshere\.press|upgraderservices\.cf|vuuwd\.com|gridcash\.js|worker\-asmjs\.min\.js|perfekt\=wss\:' - '(?mi)coin\-hive\.com|coinhive|CoinHive|miner\.start|me0w\.js|web(x?)mr(4?)\.js|miner\.js|static\/js\/tpb\.js|lib\/crypta\.js' - '(?mi)bitrix\/js\/main\/core\/core\_(tasker|loader)\.js' condition: or - type: word part: header words: - "text/html" - type: word part: body words: - "Access Denied" - "You don't have permission to access" condition: or negative: true # digest: 490a00463044022076d03d28c148d759d1b6500d80deef30587cc3c76eecd88e35a2ccae7fb102500220518296bd909a6aba9d1d256e0ea8066981099edd8b23a9b17abb31c82e239378:922c64590222798bb761d5b6d8e72950