Insert BS here A place to discuss anything you want

Am I crazy or does MazdaRoadster.net have an undisclosed crypto miner?

Thread Tools
 
Search this Thread
 
Old 08-21-2018, 07:18 PM
  #1  
Junior Member
Thread Starter
 
Spaceman Spiff's Avatar
 
Join Date: Apr 2018
Location: Central Texas
Posts: 356
Total Cats: 93
Default Am I crazy or does MazdaRoadster.net have an undisclosed crypto miner?

Maybe it's just my computer (old i7-3xxx quad core workstation laptop) but closed out some heavier duty programs (SolidWorks/Mastercam and LabView if it matters) and noticed my laptop attempting to interview for a job as a wind tunnel along with really high CPU usage... If purposeful I think this is incredibly dishonest and sleazy.

miner active on homepage


after I end task corresponding to the MR.net tab

Spaceman Spiff is offline  
Old 08-21-2018, 07:32 PM
  #2  
Junior Member
 
phocup's Avatar
 
Join Date: Aug 2016
Posts: 343
Total Cats: 2
Default

You're not crazy. My CPU usage jumped from 18% with 20+ tabs open to 78% usage with just that site.
phocup is offline  
Old 08-21-2018, 07:36 PM
  #3  
Junior Member
Thread Starter
 
Spaceman Spiff's Avatar
 
Join Date: Apr 2018
Location: Central Texas
Posts: 356
Total Cats: 93
Default

Spaceman Spiff is offline  
Old 08-21-2018, 07:36 PM
  #4  
Elite Member
iTrader: (3)
 
concealer404's Avatar
 
Join Date: Aug 2011
Posts: 10,917
Total Cats: 2,201
Default

Same here.

Also interesting to me: That site still exists.
concealer404 is offline  
Old 08-21-2018, 07:39 PM
  #5  
Junior Member
Thread Starter
 
Spaceman Spiff's Avatar
 
Join Date: Apr 2018
Location: Central Texas
Posts: 356
Total Cats: 93
Default

Originally Posted by concealer404
Same here.

Also interesting to me: That site still exists.

¯\_(ツ)_/¯

the search for good used parts deals knows no end
Spaceman Spiff is offline  
Old 08-21-2018, 07:41 PM
  #6  
Boost Pope
iTrader: (8)
 
Joe Perez's Avatar
 
Join Date: Sep 2005
Location: Chicago. (The less-murder part.)
Posts: 33,048
Total Cats: 6,607
Default

Spent a little time analyzing the page. I don't think they're doing anything malicious in the background, looks like it's just really poor-quality scripting and way too many external calls.
Joe Perez is offline  
Old 08-21-2018, 07:50 PM
  #7  
Junior Member
iTrader: (1)
 
whitrzac's Avatar
 
Join Date: Jun 2013
Posts: 254
Total Cats: 5
Default

Took my overclocked 8core 5960x to 70% too. That's a lot of power and heat....
whitrzac is offline  
Old 08-21-2018, 08:08 PM
  #8  
Elite Member
iTrader: (5)
 
Erat's Avatar
 
Join Date: Oct 2011
Location: Detroit (the part with no rules or laws)
Posts: 5,677
Total Cats: 800
Default

Even my 1800x was feeling it.

Erat is offline  
Old 08-22-2018, 01:38 PM
  #9  
Senior Member
 
HarryB's Avatar
 
Join Date: Jul 2015
Posts: 1,015
Total Cats: 140
Default

I noticed that too; however this has happened here as well last year if I recall correctly. Has anyone contacted the administrators over there?
HarryB is offline  
Old 08-22-2018, 01:45 PM
  #10  
Elite Member
iTrader: (10)
 
Reverant's Avatar
 
Join Date: Jun 2006
Location: Athens, Greece
Posts: 5,979
Total Cats: 356
Default

I blame this script: https://play.pocketgolf.host/start.php
Reverant is offline  
Old 08-22-2018, 03:50 PM
  #11  
Junior Member
 
Bryan's Avatar
 
Join Date: Dec 2007
Posts: 66
Total Cats: 2
Default

For the record, it's working fine now. Seems to have been an issue with server disk space. Forum needs to move to a new host.
Bryan is offline  
Old 08-22-2018, 09:02 PM
  #12  
Elite Member
iTrader: (7)
 
mgeoffriau's Avatar
 
Join Date: Jul 2009
Location: Jackson, MS
Posts: 7,388
Total Cats: 474
Default

For the record, no, it isn't. It still makes my CPU jump from 5-15% utilization to 75%+ utilization.

Last edited by mgeoffriau; 08-22-2018 at 09:34 PM.
mgeoffriau is offline  
Old 08-22-2018, 09:24 PM
  #13  
Junior Member
 
Bryan's Avatar
 
Join Date: Dec 2007
Posts: 66
Total Cats: 2
Default

Originally Posted by mgeoffriau
For the record, no, it isn't. It still makes my CPU jump for 5-15% utilization to 75%+ utilization.
I refreshed the page once I went and all was well. Didn't have to close my browser.

Of course, now that I check again, it's back up. Guessing until the forum moves servers it'll be an issue.
Bryan is offline  
Old 08-22-2018, 09:39 PM
  #14  
Elite Member
iTrader: (7)
 
mgeoffriau's Avatar
 
Join Date: Jul 2009
Location: Jackson, MS
Posts: 7,388
Total Cats: 474
Default

Why would low disk space on the web server cause the CPU on my local machine to spike?
mgeoffriau is offline  
Old 08-23-2018, 04:25 AM
  #15  
Newb
 
tehsuck's Avatar
 
Join Date: Feb 2018
Posts: 2
Total Cats: 3
Default

Glad it's not just me. When you have dual 8-core Xeons and you suddenly hear your fans kick on under normal usage, something's not right.

Edit: Also just realized it's my first post here after lurking for some time. I'm getting ready to build a turbo Miata, I swear! MSPNP2 arrives tomorrow!
tehsuck is offline  
Old 08-23-2018, 08:54 AM
  #16  
Senior Member
 
gooflophaze's Avatar
 
Join Date: May 2007
Location: Atlanta
Posts: 997
Total Cats: 156
Default

Originally Posted by Reverant
You're not wrong. Chrome -> ctrl+shift+i -> select and pause, cpu usage drops. js is pretty damn obsfucated (php my ***) dns whois is blocked, main page is blank. Only thing discernable is a callout to feesocrald.com which links to a google doc. Popped play.pockegolf.host into my hosts file, no problem. Also - chrome has it's own taskmanager (shift esc) that'll show which thread is beating up the cpu.

Storage my ***.

Last edited by gooflophaze; 08-23-2018 at 09:18 AM.
gooflophaze is offline  
Old 08-23-2018, 11:08 AM
  #17  
Moderator
iTrader: (12)
 
sixshooter's Avatar
 
Join Date: Nov 2008
Location: Tampa, Florida
Posts: 20,663
Total Cats: 3,013
Default

Pocketgolf is playing pocketpool inside your computer?
sixshooter is offline  
Old 08-23-2018, 11:59 AM
  #18  
Senior Member
 
gooflophaze's Avatar
 
Join Date: May 2007
Location: Atlanta
Posts: 997
Total Cats: 156
Default

Pretty much, yeah.

More damning - started replacing the obsfucated hex strings with barnyard animal names to see if I could actually follow the code. While I was doing that pasted a few of the variable names into google to see if they were simply ascii bytes - and ran across https://www.hybrid-analysis.com/samp...ironmentId=100 - I'd not seen this analyzer before, so I threw pocketgolf into it - and yeap, it's tainted as ****. https://www.hybrid-analysis.com/samp...a3e105000e46e3
gooflophaze is offline  
Old 08-25-2018, 10:19 PM
  #19  
Newb
 
tehsuck's Avatar
 
Join Date: Feb 2018
Posts: 2
Total Cats: 3
Default

I'm not THAT much of a computer whiz, but I'd say something's doing some mining, for sure.

Also, that's from pinning 16 logical processors on a dual Xeon E5-2687W setup to 100%.


tehsuck is offline  
Old 08-26-2018, 08:04 AM
  #20  
Boost Pope
iTrader: (8)
 
Joe Perez's Avatar
 
Join Date: Sep 2005
Location: Chicago. (The less-murder part.)
Posts: 33,048
Total Cats: 6,607
Default

That's some good investigating there.
Joe Perez is offline  
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Savington
Insert BS here
29
12-11-2014 12:05 PM
m2cupcar
Insert BS here
0
06-30-2008 10:00 AM



Quick Reply: Am I crazy or does MazdaRoadster.net have an undisclosed crypto miner?



All times are GMT -4. The time now is 02:34 PM.