Closed ks7000 closed 6 years ago
https://gtg02.bestsecurepractice.com/lib/harrypotter-asmjs.min.js
Deobfuscated w/ http://jsbeautifier.org confirms that they are mining:
{ LIB_URL: 'https://gtg02.bestsecurepractice.com/lib/', WEBSOCKET_SHARDS: [['wss://gtg02.bestsecurepractice.com/proxy']], CAPTCHA_URL: 'https://gtg02.bestsecurepractice.com/captcha/' };
wss://gtg02.bestsecurepractice.com/proxy https://gtg02.bestsecurepractice.com/lib/*
Thanks for the link http://jsbeautifier.org/ ! Thanks for all ! I am a Padawan !
Detects but doesn't block mining on UltimasNoticiasComVe: spikes up 97% http://www.ultimasnoticias.com.ve
Suspecious
Dubious: https://gtg02.bestsecurepractice.com/un.js