-
hycNews Flash: someone is using supercomputers to mine monero randomX !!!#!!11
-
sech1
-
cohcho
-
cohchofrom there ^: "I feel left out since I don’t have a botnet for all this RandomX business. Who really benefits here?"
-
cohchoreal example of randomx malware: twitter.com/JosephCoscia/status/1207587736267501570
-
cohcho"C:\ProgramData\WindowsTask\AMD.exe -o stratum+tcp://185.204.3.125:3333 -u AMD --donate-level=1 -k" from taskhostw.com/randomx/configAMDX.html
-
cohchoHa, botnets donates to miner developer
-
cohchoI've checked all miner configs from that taskhostw.com, here is the summary: cn/gpu(ryo), cn/r(sumokoin) and rx/0 (monero)
-
wow-discord<sech1> Botnet mining GPU coin, haha 😄
-
wow-discord<sech1> Who told us all the time that GPU algo is botnet free?
-
cohchoI've checked all stratum urls with real miner and according to seed_hash it was 100% monero, and according to height sumokoin and ryo accordingly.
-
cohchoIt's interesting to check what randomx miner is being used, xmrig or not.
-
tevadorif it has CN/R then antivirus can already detect it without randomx sniffer
-
wow-discord<sech1> Judging by command line, it's stock XMRig binary (but renamed)
-
cohchoIt looks familiar for me too, but I need better proof.
-
tevadorthey probably use stock XMRig because they can download directly from github
-
tevadorwithout a risk of getting blocked
-
cohchothat tweet has link to visualization of winapi calls of that binary, it has builtin miner withoun external downloading, you can check by yourself
-
tevadorthen I have no other explanation why they would use stock XMRig apart from laziness
-
cohchoI don't beleive that botnet operators are lazy people, It should very competitive market.
-
cohcho"survival of the fittest..."
-
tevadorthere is also low effort malware
-
cohchos/It should/It must/
-
tevadoryou can find links weekly on bitcointalk
-
cohchoDo you mean phishing with fake miners like sech1 posted some time ago?
-
tevadoryes
-
cohchoThere is no data about cost and value per customer for this way of initial intjection.
-
cohchoI beleive total audience is too small.