Quantcast
Channel: Symantec Connect - Products - Articles
Viewing all articles
Browse latest Browse all 818

Javascript coin miners are on the rise - and you can't see them, must read article

$
0
0

Hello friends,

As a security administrator in my organization I can see a rising trand of JSCoinminer events

These events are users surfing to a web page which is infected with a malitious script

Unfortunatly you will not know about this at all as the default configuration in the SEPM is to ALLOW and NO LOG

This is the event:

15/02/2018 12:42:20

Browser Protection
Major and above
1

DOM
AVMAIN
My Company\Workstations\Domain Computers

CEO
10.0.0.10
Windows 10 Enterprise Edition

CEO
Default

Other
Inbound

Not applicable
Not applicable

[SID: 30358] Web Attack: JSCoinminer Download 8 attack blocked. Traffic has been blocked for this application: C:\Program Files\Internet Explorer\iexplore.exe

You need to go to your IPS policy --> Windows Settings --> Exceptions --> ADD

If you filter for action Allow you will see many interesting signatures, I really recommend checking them out by enabling LOGGING to see

if you have such traffic. You can see 3 JSCoinminer options.

Plus, you can detect TOR,IRC,P2P, PSExec traffic and many more which I block inside my network using these options


Viewing all articles
Browse latest Browse all 818

Trending Articles