How to block Crypto Miner (javascript)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to block Crypto Miner (javascript)

L3 Networker

This week I noticed a "CoinHive Javascript Detection" in the logs of our Palo Alto.

When reading on the subject I noticed that there are websites around that use Javascript to start mining Crypto coins on the users' computer.

 

https://live.paloaltonetworks.com/t5/Community-Blog/Unauthorized-Coin-Mining-in-the-Browser/ba-p/183...

 

Detailed description can be found here :

https://researchcenter.paloaltonetworks.com/2017/10/unit42-unauthorized-coin-mining-browser/

 

I noticed in the Palo Alto blog that : PANDB is able to block URLs hosting Coinhive JavaScript.

 

My question:

How does one actually block this?

When I visit for example https://coinhive.com/ and push the button "Start Mining" the CPU goes up to 100%.

1 ACCEPTED SOLUTION

Accepted Solutions

Also found the solution how to decrypt a site that is in a category that should not be decrypted.

Problem solved.

The Crypto sites are now succesfully blocked.

View solution in original post

11 REPLIES 11

L3 Networker

I have found how to block this in the AntiSpyware profile.

It appears that for many of the AntiSpyware actions the default setting is alert. Even for some of the critical ones.

Not sure why this is but I will play around with the settings to see if this can be set to block.

 

Unfortunately there is an additional challange.

This site is SSL encrypted and although there is SSL decryption enabled on the firewall, the site itself is classified as "Financial Services" which is excluded from SSL decryption due to regulations.

 

So if I find the solution on how to decrypt the site, I should be able to block this.

 

Thanks,

 

Also found the solution how to decrypt a site that is in a category that should not be decrypted.

Problem solved.

The Crypto sites are now succesfully blocked.

so do you block it by your spyware filters or it is blocked by PANDB filter? 

because to me it is still unclear how Palo blocks it (if it does)

It is part of the Anti Spyware module.

2017-12-12 11_15_22-FW-PA500-1.pngThe default action is alert so I changed mine to "reset-both"

 

2017-12-12 11_17_04-FW-PA500-1.png

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!