Skip to main content
Answer

i think this site have miner code

  • February 17, 2019
  • 12 replies
  • 72 views

durantash
Community Leader
Forum|alt.badge.img+37
website " www.root.ir " have not miner code , but when open it . cpu usage is very high.

after close website"tab" , cpu usage back to normaly " low "

any AV can not detected it .

Regards ,

Amir

Best answer by durantash

Hello,

We can confirm this site is using a javascript based miner to utilize 100% of CPU. We have reported it to our web threat team and the site will be blocked.

Regards,
Webroot Business Support

12 replies

Baldrick
Gold VIP
  • Gold VIP
  • February 17, 2019
Hi durantash

From what I can see from a reputation lookup that looks unlike given the following result returned:

URL lookup information

URL:www.root.irCategory & ConfidencePersonal Sites and Blogs: 93%

Reputation:88

This is a well known site with strong security practices, and rarely exhibits characteristics that expose the user to security risks. There is a very low probability that the user will be exposed to malicious links or payloads.

You may want to do a check by another means but as I said given the above...unlikely...regardless of CPU usage spikes, etc.

Regards, Baldrick

  • February 17, 2019
FWIW ~
with my content blocker on


with my content blocker off



YMMV

durantash
Community Leader
Forum|alt.badge.img+37
  • Author
  • Community Leader
  • February 17, 2019
interesting .

i view website source and can not find any coin miner code .

  • February 17, 2019
maybe, it's site content re: https://webchain.network/
IDK

Baldrick
Gold VIP
  • Gold VIP
  • February 17, 2019
Just because an advert is pushed out by a site does not mean that it will be also nefariously pushing mining-related code...that smacks of paranoia in the extreme.

I have also gone to the site and turned off my ad blockers...and absolutely no spike as far as I can see.

Suspect a 'storm in a tea cup'.

  • February 17, 2019
Um, do you run uBlock Origin medium mode


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • February 17, 2019
Both BrightCloud and VirusTotal say the site is safe! https://www.virustotal.com/en/url/8c43449368af83309575818baa7313f992c5c1f8947a3b4e582e7369a9303602/analysis/


durantash
Community Leader
Forum|alt.badge.img+37
  • Author
  • Community Leader
  • Answer
  • February 17, 2019
Hello,

We can confirm this site is using a javascript based miner to utilize 100% of CPU. We have reported it to our web threat team and the site will be blocked.

Regards,
Webroot Business Support

  • February 17, 2019



ProTruckDriver
Moderator
Thank you @durantash for finding and reporting that website. Kudo's. 😉

TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • February 18, 2019
Hello,

We can confirm this site is using a javascript based miner to utilize 100% of CPU. We have reported it to our web threat team and the site will be blocked.

Regards,
Webroot Business Support

Thanks! Very odd though but good to know and see this: https://sitecheck.sucuri.net/results/www.root.ir

Click on Picture to see full size!


durantash
Community Leader
Forum|alt.badge.img+37
  • Author
  • Community Leader
  • February 18, 2019
Thank you

i ask about can brightCloud automatically Blocked websites are this Method for coin mine ?

maybe we need making new Method for detect threats ? with more speedy .

Regards ,

Amir