trojan script?/

  • 6 replies
  • 2.5K views
lucid

The past few days kaspersky web protection has been picking up and blocking a trojan script on all the subscene subtitle pages. Initially from:
https://coin-hive.com/lib/coinhive.min.js;

HEUR:Trojan.Script.Generic;https://coin-hive.com/lib/coinhive.min.js; Trojan program

Now from:
https://subscene.com/Scripts/c.
js;HEUR:Trojan.Script.Generic;https://subscene.com/Scripts/c.js;Trojan program

Seems to be a Heuristic detection but all the same what is this and is there a problem? A corrupt ad server maybe?

Asuna

yeah eset also detect c.js as mining coin script

Sub-stance

malwarebytes is also blocking these too. even after shutting down browser, they continue to pop up until i restart my pc.

various website names all including coin-hive. there is atleast 100 attempts in a few minutes according to the protection log. all from the homepage https://subscene.com/ . i have included the pop up alert info . hopefully it helps get rid of this issue. i shall be going to another site for my subtitles until i see this is fixed

coin-hive
ip: 94.130.102.124

ws001.coin-hive
94.130.51.30

ws002.coin-hive
144.76.112.165

ws003.coin-hive
144.76.114.98

ws004.coin-hive
88.99.6.234

ws05.coin-hive
88.99.5.35

ws007.coin-hive
136.243.89.75

ws006.coin-hive
136.243.89.87

just to be clear even after closing browser and deleting cookies, these alerts still pop up. absolute disgrace if subscene are doing this on purpose

lucid

It seems to have stopped today. Have a look at this thread. They have been trying to use our browsers for bitcoin mining!!
https://forum.subscene.com/topic/subscene-com-tries-to-use-your-browser-as-a-blockchain-currency-miner

lucid

@Sub-stance
It sounds like Malwarebytes has allowed the browser to download the files as they are still active when you close the browser and is alerting you that they are active . Kaspersky is kicking in and preventing the actual downloads by the web scripts.

Asuna

new way to support Subscene LOL

lucid

they could just get a patreon page or something...