heysoundude
Part of the Furniture
there are other crypto options to mine this way. some of them may even be ridiculously profitableThese hackers are going to be hugely disappointed if they're trying to turn our routers into bitcoin miners. LOL
there are other crypto options to mine this way. some of them may even be ridiculously profitableThese hackers are going to be hugely disappointed if they're trying to turn our routers into bitcoin miners. LOL
I would hope so... Because with a straight CPU like these, it might take about 43,092 years to mine a single coin.there are other crypto options to mine this way. some of them may even be ridiculously profitable
it might take about 43,092 years to mine a single coin
OMG. It's not a crypto miner. Jesus...............It's definitely malware. I decompiled the binary "https://download.iproyal.com/pawns-cli/latest/linux_armv5l/pawns-cli" in this link. It's a crypto miner.
It still sucks that it was on there, but having that on there is way better than a lot of alternatives. Below is a bit of the content from one of the files in the malware.
It's not a crypto miner, it's a proxy.Crypto mining botnets perhaps?
So... what you're telling me is.... ???OMG. It's not a crypto miner. Jesus...............
It's just command line interface version of the 'IPRoyal Pawns app'. You don't know what pawns.app don't you? The attacker is just using
command line interface version of the 'IPRoyal Pawns app' for illegal Proxy Service for the money. Crypto miner? lol.
Go to here and read. I already linked about it with one of my posts. How many times do I have to talk about Proxyjacking? If you don't know about this area please just stay away.
Proxyjacking has Entered the Chat
Did you know that you can effortlessly make a small passive income by simply letting an application run on your...sysdig.com
Update download page link · IPRoyal/pawns-cli@2fd756a
Contribute to IPRoyal/pawns-cli development by creating an account on GitHub.github.com
Pawns.app with Raspberry PI: passive income by sharing internet bandwidth
Passive earnings with Pawns.app and Raspberry PI by sharing your internet bandwidth. How to configure it and make your privacy assuredpeppe8o.com
I linked the evidence two times. Nobody understands the link for sure. OMG. I'll quit.
I love you.So... what you're telling me is.... ???
LOLI love you.
As much as I would like to believe this is the case, that went out the window today as I turned on several workstations that haven't been used in months. I updated the virus security definitions and ran security scans. Not a trace of infection on any. Ran virus checks on mobile devices as well. No infections detected.
It is possible it could have been embedded infection that was "woke" by the firmware checks, but then most likely more people would be here reporting the issue as I suspect other people would have had infected batches of firmware.
It's almost impossible to do here. Because some of users here always say it doesn't exist and can't be happened. They don't even know about the exploit which made you compromised. They only know the definition of Malware and Exploit on internet.
Pretty fascinating that there still isn't an obvious entry point for this exploit. Swistheater seems to have the common entry points disabled.
Well so far I am good. Nothing anomalous has taken place since I did the hard reset, I will just keep an eye out.If your virus scanner didn't catch it before, there is no reason to believe it will catch it now. You need to boot off a rescue disc with multiple engines and scan, and even then it is no guarantee. I cleaned one a while back that nothing would detect, had to look at running processes and task scheduler to track it down and remove it.
Here is theI don't think so. That code would only affect a terminal session. It hides the updater, updateservice and .profile output from ls, ps and cat.
If you still have a copy of the /jffs/asd.log file you might see something like this, if the malware even made it that far.
Code:1685259650[remove_file]Delete harmful file,/tmp/updateservice 1685259650[blockfile] /tmp/updateservice is binary.
Looking at the nvram variables it modifies a bit closer, some of them were removed from asuswrt firmware versions after 380.x. So my guess is that this is a modified version of some old malware that's been repurposed to monetize the theft of your bandwidth.
asd.log
from jffs and yes the asd.log was one of the things I copied. It looks like jibberish to me.Ah, OK. Looks like with asd 2.0 the contents that file are now encrypted. Thanks Asus .Here is theasd.log
from jffs and yes the asd.log was one of the things I copied. It looks like jibberish to me.
Hey if you know how to decrypt, (or if @RMerlin knows cough, cough....) feel free to take a stab at it.Ah, OK. Looks like with asd 2.0 the contents that file are now encrypted. Thanks Asus .
Probably not. There was a report of this malware prior to that asd update.Do you think it may be related to the wrong ASD update?
@ColinTaylor
Would it be safe to block these on the firewall?
Code:download.iproyal.com proton.me
they are in the malware script above.
download.iproyal.com
does nothing bad, it just downloads prebuilt binaries suitable for arm from this 3rd party platform.proton.me
is a widely used anonymous mailbox. And webupdate@proton.me
is the login account of this malware author in IPRoyalbasically correct.OMG. It's not a crypto miner. Jesus...............
It's just command line interface version of the 'IPRoyal Pawns app'. You don't know what pawns.app don't you? The attacker is just using
command line interface version of the 'IPRoyal Pawns app' for illegal Proxy Service for the money. Crypto miner? lol.
Go to here and read. I already linked about it with one of my posts. How many times do I have to talk about Proxyjacking? If you don't know about this area please just stay away.
Proxyjacking has Entered the Chat
Did you know that you can effortlessly make a small passive income by simply letting an application run on your...sysdig.com
Update download page link · IPRoyal/pawns-cli@2fd756a
Contribute to IPRoyal/pawns-cli development by creating an account on GitHub.github.com
Pawns.app with Raspberry PI: passive income by sharing internet bandwidth
Passive earnings with Pawns.app and Raspberry PI by sharing your internet bandwidth. How to configure it and make your privacy assuredpeppe8o.com
I linked the evidence two times. Nobody understands the link for sure. OMG. I'll quit.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!