Notices
Insert BS here A place to discuss anything you want

Am I crazy or does MazdaRoadster.net have an undisclosed crypto miner?

Thread Tools
 
Search this Thread
 
Old Aug 21, 2018 | 07:18 PM
  #1  
Spaceman Spiff's Avatar
Thread Starter
Junior Member
 
Joined: Apr 2018
Posts: 356
Total Cats: 93
From: Central Texas
Default Am I crazy or does MazdaRoadster.net have an undisclosed crypto miner?

Maybe it's just my computer (old i7-3xxx quad core workstation laptop) but closed out some heavier duty programs (SolidWorks/Mastercam and LabView if it matters) and noticed my laptop attempting to interview for a job as a wind tunnel along with really high CPU usage... If purposeful I think this is incredibly dishonest and sleazy.

miner active on homepage


after I end task corresponding to the MR.net tab

Old Aug 21, 2018 | 07:32 PM
  #2  
phocup's Avatar
Junior Member
 
Joined: Aug 2016
Posts: 343
Total Cats: 2
Default

You're not crazy. My CPU usage jumped from 18% with 20+ tabs open to 78% usage with just that site.
Old Aug 21, 2018 | 07:36 PM
  #3  
Spaceman Spiff's Avatar
Thread Starter
Junior Member
 
Joined: Apr 2018
Posts: 356
Total Cats: 93
From: Central Texas
Default

Old Aug 21, 2018 | 07:36 PM
  #4  
concealer404's Avatar
Elite Member
iTrader: (3)
 
Joined: Aug 2011
Posts: 10,917
Total Cats: 2,206
Default

Same here.

Also interesting to me: That site still exists.
Old Aug 21, 2018 | 07:39 PM
  #5  
Spaceman Spiff's Avatar
Thread Starter
Junior Member
 
Joined: Apr 2018
Posts: 356
Total Cats: 93
From: Central Texas
Default

Originally Posted by concealer404
Same here.

Also interesting to me: That site still exists.

¯\_(ツ)_/¯

the search for good used parts deals knows no end
Old Aug 21, 2018 | 07:41 PM
  #6  
Joe Perez's Avatar
Boost Pope
iTrader: (8)
 
Joined: Sep 2005
Posts: 34,402
Total Cats: 7,523
From: Chicago. (The less-murder part.)
Default

Spent a little time analyzing the page. I don't think they're doing anything malicious in the background, looks like it's just really poor-quality scripting and way too many external calls.
Old Aug 21, 2018 | 07:50 PM
  #7  
whitrzac's Avatar
Junior Member
iTrader: (1)
 
Joined: Jun 2013
Posts: 254
Total Cats: 5
Default

Took my overclocked 8core 5960x to 70% too. That's a lot of power and heat....
Old Aug 21, 2018 | 08:08 PM
  #8  
Erat's Avatar
Elite Member
iTrader: (5)
 
Joined: Oct 2011
Posts: 5,718
Total Cats: 830
From: Detroit (the part with no rules or laws)
Default

Even my 1800x was feeling it.

Old Aug 22, 2018 | 01:38 PM
  #9  
HarryB's Avatar
Senior Member
 
Joined: Jul 2015
Posts: 1,083
Total Cats: 155
Default

I noticed that too; however this has happened here as well last year if I recall correctly. Has anyone contacted the administrators over there?
Old Aug 22, 2018 | 01:45 PM
  #10  
Reverant's Avatar
Elite Member
iTrader: (10)
 
Joined: Jun 2006
Posts: 6,020
Total Cats: 369
From: Athens, Greece
Default

I blame this script: https://play.pocketgolf.host/start.php
Old Aug 22, 2018 | 03:50 PM
  #11  
Bryan's Avatar
Junior Member
 
Joined: Dec 2007
Posts: 66
Total Cats: 2
Default

For the record, it's working fine now. Seems to have been an issue with server disk space. Forum needs to move to a new host.
Old Aug 22, 2018 | 09:02 PM
  #12  
mgeoffriau's Avatar
Elite Member
iTrader: (7)
 
Joined: Jul 2009
Posts: 7,388
Total Cats: 474
From: Jackson, MS
Default

For the record, no, it isn't. It still makes my CPU jump from 5-15% utilization to 75%+ utilization.

Last edited by mgeoffriau; Aug 22, 2018 at 09:34 PM.
Old Aug 22, 2018 | 09:24 PM
  #13  
Bryan's Avatar
Junior Member
 
Joined: Dec 2007
Posts: 66
Total Cats: 2
Default

Originally Posted by mgeoffriau
For the record, no, it isn't. It still makes my CPU jump for 5-15% utilization to 75%+ utilization.
I refreshed the page once I went and all was well. Didn't have to close my browser.

Of course, now that I check again, it's back up. Guessing until the forum moves servers it'll be an issue.
Old Aug 22, 2018 | 09:39 PM
  #14  
mgeoffriau's Avatar
Elite Member
iTrader: (7)
 
Joined: Jul 2009
Posts: 7,388
Total Cats: 474
From: Jackson, MS
Default

Why would low disk space on the web server cause the CPU on my local machine to spike?
Old Aug 23, 2018 | 04:25 AM
  #15  
tehsuck's Avatar
Newb
 
Joined: Feb 2018
Posts: 2
Total Cats: 3
Default

Glad it's not just me. When you have dual 8-core Xeons and you suddenly hear your fans kick on under normal usage, something's not right.

Edit: Also just realized it's my first post here after lurking for some time. I'm getting ready to build a turbo Miata, I swear! MSPNP2 arrives tomorrow!
Old Aug 23, 2018 | 08:54 AM
  #16  
gooflophaze's Avatar
Senior Member
 
Joined: May 2007
Posts: 997
Total Cats: 156
From: Atlanta
Default

Originally Posted by Reverant
You're not wrong. Chrome -> ctrl+shift+i -> select and pause, cpu usage drops. js is pretty damn obsfucated (php my ***) dns whois is blocked, main page is blank. Only thing discernable is a callout to feesocrald.com which links to a google doc. Popped play.pockegolf.host into my hosts file, no problem. Also - chrome has it's own taskmanager (shift esc) that'll show which thread is beating up the cpu.

Storage my ***.

Last edited by gooflophaze; Aug 23, 2018 at 09:18 AM.
Old Aug 23, 2018 | 11:08 AM
  #17  
sixshooter's Avatar
Moderator
iTrader: (12)
 
Joined: Nov 2008
Posts: 22,204
Total Cats: 3,560
From: Tampa, Florida
Default

Pocketgolf is playing pocketpool inside your computer?
Old Aug 23, 2018 | 11:59 AM
  #18  
gooflophaze's Avatar
Senior Member
 
Joined: May 2007
Posts: 997
Total Cats: 156
From: Atlanta
Default

Pretty much, yeah.

More damning - started replacing the obsfucated hex strings with barnyard animal names to see if I could actually follow the code. While I was doing that pasted a few of the variable names into google to see if they were simply ascii bytes - and ran across https://www.hybrid-analysis.com/samp...ironmentId=100 - I'd not seen this analyzer before, so I threw pocketgolf into it - and yeap, it's tainted as ****. https://www.hybrid-analysis.com/samp...a3e105000e46e3
Old Aug 25, 2018 | 10:19 PM
  #19  
tehsuck's Avatar
Newb
 
Joined: Feb 2018
Posts: 2
Total Cats: 3
Default

I'm not THAT much of a computer whiz, but I'd say something's doing some mining, for sure.

Also, that's from pinning 16 logical processors on a dual Xeon E5-2687W setup to 100%.


Old Aug 26, 2018 | 08:04 AM
  #20  
Joe Perez's Avatar
Boost Pope
iTrader: (8)
 
Joined: Sep 2005
Posts: 34,402
Total Cats: 7,523
From: Chicago. (The less-murder part.)
Default

That's some good investigating there.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Savington
Insert BS here
29
Dec 11, 2014 12:05 PM
m2cupcar
Insert BS here
0
Jun 30, 2008 10:00 AM




All times are GMT -4. The time now is 04:09 PM.