↓
 

The PolyBlog

My view from the lilypads

  • Home
  • Goals
    • Goals (all posts)
    • #50by50 – Status of completion
    • PolyWogg’s Bucket List, updated for 2016
  • Life
    • Family (all posts)
    • Health and Spiritualism (all posts)
    • Learning and Ideas (all posts)
    • Computers (all posts)
    • Experiences (all posts)
    • Humour (all posts)
    • Quotes (all posts)
  • Photo Galleries
    • PandA Gallery
    • PolyWogg AstroPhotography
    • Flickr Account
  • Reviews
    • Books
      • Book Reviews (all posts)
      • Book reviews by…
        • Book Reviews List by Date of Review
        • Book Reviews List by Number
        • Book Reviews List by Title
        • Book Reviews List by Author
        • Book Reviews List by Rating
        • Book Reviews List by Year of Publication
        • Book Reviews List by Series
      • Special collections
        • The Sherlockian Universe
        • The Three Investigators
        • The World of Nancy Drew
      • PolyWogg’s Reading Challenge
        • 2026
        • 2023
        • 2022
        • 2021
        • 2020
        • 2019
        • 2015, 2016, 2017
    • Movies
      • Master Movie Reviews List (by Title)
      • Movie Reviews List (by Date of Review)
      • Movie Reviews (all posts)
    • Music and Podcasts
      • Master Music and Podcast Reviews (by Title)
      • Music Reviews (by Date of Review)
      • Music Reviews (all posts)
      • Podcast Reviews (by Date of Review)
      • Podcast Reviews (all posts)
    • Recipes
      • Master Recipe Reviews List (by Title)
      • Recipe Reviews List (by Date of Review)
      • Recipe Reviews (all posts)
    • Television
      • Master TV Season Reviews List (by Title)
      • TV Season Reviews List (by Date of Review)
      • Television Premieres (by Date of Post)
      • Television (all posts)
  • About Me
    • Subscribe
    • Contact Me
    • Privacy Policy
    • PolySites
      • ThePolyBlog.ca (Home)
      • PolyWogg.ca
      • AstroPontiac.ca
      • About ThePolyBlog.ca
    • WP colour choices
  • Andrea’s Corner

Tag Archives: background

Articles I Like: Tracking Emerging Cryptomining Threats

The PolyBlog
May 13 2018

The WordPress security plugin, Wordfence, published a blog entry describing how one of its techs working on cracking malware goes about doing the various steps in a recent day, analysing and developing responses to specific threats.

While the post seems at first to be highly technical, it’s quite readable by the informed layperson, and quite interesting to see. It also dispels the cryptocurrency baitclick headline to note it could have been running anything off the site, it just happened to be doing CCs.

One of our sources of threat data at Defiant is cleaning hacked websites. In this case, Ivan, a member of our SST team had cleaned a hacked site and handed me the forensic data for analysis. The site had been hacked for months before the owner discovered that it had been compromised.

My normal routine is to start by verifying the files we already detect to check if there is any new information inside any of them. Usually there is not, and this infection did not yield any surprises in the files that Wordfence already detected.

What did surprise me is that the server had a large number of malicious files we have not seen before. The server had been infected for a long time, which may have left the attacker feeling confident enough to upload more valuable code.

For us, a server with code we have not seen before is a treasure trove, because it immediately allows us to add new detection capability to the Wordfence malware scanner. If an attacker is caught in this situation, they generally have a bad day, because many of their files that may have previously been undetected by malware scanners will now be detected by our scan.

The first thing that made this attacker different from others is that, instead of using a standard javascript code obfuscator that just scrambles the code, they were using a finite wordlist to replace variable and function names in the code. When you look at the code, the variable and function names just seem like gibberish.

I immediately searched for other similar files out of the remaining samples and found several, then proceeded to write new signatures to detect those files. That accomplished, I moved on to the next file in the list. That was a basic PHP file that selectively redirects regular users, not search engines, to a malicious website. This is a standard thing we see, so I wrote a signature to detect this updated malware variant and moved on.

WordPress: Tracking Emerging Cryptomining Threats

Even the opening approach is quite illuminating, seeing the real work of defenders, not the Hollywood version.

Posted in Computers | Tagged background, computer, curation, security | Leave a reply

Countdown to Retirement

Days

Hours

Minutes

Seconds

Retirement!

One of my favourite sites

And it's new sister site

My Latest Posts

  • More workplanning on my new Calibre libraryMarch 28, 2026
    I wrote earlier this week (Using Calibre to embrace my inner librarian for ebooks) about the Poly Library 3.0, and when I did, I thought I had most of my “work” done. I had decided on three main areas (the book profile, user engagement, and user tools), although, truth be told, I had four categories … Continue reading →
  • An update on Jacob…March 24, 2026
    For those of you who don’t know, as I didn’t blog about this much before, Jacob decided to have surgery on his legs this year, which he did at the end of February. I’ve held off posting anything as I didn’t want to ask Jacob what he was comfortable with me sharing, but today was … Continue reading →
  • Using Calibre to embrace my inner librarian for ebooksMarch 23, 2026
    I have used Calibre literally for years to manage all my ebooks. It started way back when Kindle was doing a huge business of people pushing freebies of their ebooks. Some good, some slush, all free. But it meant a LOT of ebooks to manage. So I tried a couple of programs, most of which … Continue reading →
  • What would you put in a personal health dashboard / framework?March 8, 2026
    I started this year with a few short plans to work on health factors in my life. Some of it was prescribed; I needed a physical exam for certain pension forms. Others were ones that I was trying to do some proactive work on, like my teeth and my feet. And still others were more … Continue reading →
  • Book clubs 2026-03: Options for MarchMarch 8, 2026
    February wasn’t as productive as I had hoped, at least not for my “bookclub reading”. I had 28 from book clubs below as potential reads, but my Christmas present hangover reads occupied most of my attention, plus some non-reading projects. Oh, and life itself, I guess. I read This Book Made Me Think of You … Continue reading →

Archives

Categories

© 1996-2025 - PolyWogg Privacy Policy
↑