Eclipse Community

How do you detect coinminers?

Post Reply   Page 1 of 1  [ 4 posts ]
Author Message
kmuland
Post subject: How do you detect coinminers?
Posted: 18 Sep 2025, 11:46
User avatar
Offline
 
Posts: 15
Joined: 26 Oct 2024, 08:31
OS: XP, 8.0
 
We are living in 2025 on planet Earth (not faeryland).
Guys releasing software for free are really really really few.. and today its a problem trying to find new software and be sure that it is free of miners.
I was used to get portables of every software.... but today I cant trust on anyone that release a commercial software portable "just for free", and just as easy as "click" "download" "unrar". Everyone want to become rich mining crypto currencies nowadays.

Of course using an AV, malwarebites or similar toys are for kids (the evil greedy guys are not idiots of course, and they check against these tools).
I bet that many 3D gamers are not aware of the problem.. powerful GPUs/CPUs dozen of fans making noise constantly.... for me would be hard in these machines to detect the presence of that malware.

So my question is:
what are you using nowadays to detect miners running on your computers when idle?


Top
Profile Quote
Nokiamies
Post subject: How do you detect coinminers?
Posted: 18 Sep 2025, 12:24
User avatar
Offline
 
Posts: 17
Joined: 17 Aug 2025, 16:11
Location: (Luckily) Outside ring 3
Mood: Cynical
OS: Windows ME
Contact: Website
 
It depends on coinminer. If it is jabbajavascript based on some website you can tell if it tried get too much cpu time. Best you can do is block JS by default with something like Ematrix, disable WASM and try avoid untrusted sites that try force on JS.

As for programs there is no 100% working way as it is mix of things. First of all I would have something like process hacker 2 for monitoring full network traffic. Then using something else to monitor GPU idle usage like hwmonitor. If gpu usage keep cranking up high while idle that is usually sign of some process utilizing it. For network you need understand what is normal and what is not normal connections and I cant really explain it properly, but you can detect if some program that should not make requests keep making them constantly to some odd ip address. It might also be telemetry or other spyware activity.

_________________

Hoot Hoot!
(Too bad Finnish saying "Ei Pöllömpi allekirjoitus" (not too owl signature, which can also mean not too bad signature) does not translate too well to English. Well that shall do it)


Top
Profile Quote
Duke
Post subject: How do you detect coinminers?
Posted: 18 Sep 2025, 19:00
Full Moderator
User avatar
Offline
 
Posts: 354
Joined: 16 Mar 2024, 13:32
OS: Windows 8.1 x64
 
Nokiamies wrote: *  18 Sep 2025, 12:24
It depends on coinminer. If it is jabbajavascript based on some website you can tell if it tried get too much cpu time. Best you can do is block JS by default with something like Ematrix, disable WASM and try avoid untrusted sites that try force on JS.
Just use NoScript ;)

There is also this list for uBlock Origin:
https://raw.githubusercontent.com/hoshsadiq/adblock-nocoin-list/master/nocoin.txt

You can also use some alternate DNS server like Quad9, Adguard or DNS.Watch which are blocking malware sites, ads and trackers.


That's for a browser but for a software there is not much you can do. You can block it from accessing the internet with a firewall, also use alternate DNS servers as seen before if internet access is required but the best is to download and use stuff from a trusted source ;)


Top
Profile Quote
Nokiamies
Post subject: How do you detect coinminers?
Posted: 18 Sep 2025, 19:33
User avatar
Offline
 
Posts: 17
Joined: 17 Aug 2025, 16:11
Location: (Luckily) Outside ring 3
Mood: Cynical
OS: Windows ME
Contact: Website
 
Duke wrote: *  18 Sep 2025, 19:00
Nokiamies wrote: *  18 Sep 2025, 12:24
It depends on coinminer. If it is jabbajavascript based on some website you can tell if it tried get too much cpu time. Best you can do is block JS by default with something like Ematrix, disable WASM and try avoid untrusted sites that try force on JS.
Just use NoScript ;)

There is also this list for uBlock Origin:
https://raw.githubusercontent.com/hoshsadiq/adblock-nocoin-list/master/nocoin.txt
It highly depends what do you want. If you want allow certain CDN or other on certain sites and deny it on other and also control Media, css, frames etc. eMatrix will sweep floor with noscript. There is version for "modern firefox" webextension (umatrix) but I still roll on UXP based browser.

Downside is of course amount of work per site eMatrix requires but it is fine for me since there is very few sites I use and most are pretty basic.

_________________

Hoot Hoot!
(Too bad Finnish saying "Ei Pöllömpi allekirjoitus" (not too owl signature, which can also mean not too bad signature) does not translate too well to English. Well that shall do it)


Top
Profile Quote
Display: Sort by: Direction:
Post Reply   Page 1 of 1  [ 4 posts ]
Return to “General Chat”
Jump to:

Who is online

Users browsing this forum: No registered users and 3 guests