Post
Topic
Board Mining (Altcoins)
Re: [ANN] lolMiner 0.4 - Mining Minexcoin (MNX) and Equihash 144.5 coins (BTG,XSG...
by
Racquemis1
on 24/07/2018, 13:33:47 UTC
@Lolliedieb
Could you explain why in this version you added a connection to a cloud hosting?
The first thing it does is connect to a mining site, it is OK
The second is a personal account in www.linode.com
It is not done directly from lolminer.exe, it is done trough explorer.exe
This looks to me you are doing this way to bypass firewalls
Very suspicious  Shocked Shocked Shocked
Quote
What?!?

lolMiner.exe can establish at most 3 connections:
1) The one you use for mining to your pool
2) The one for the dev fee, which currently will likely be (dependent of the coin) minexpool.nl, suprnova.cc or miningpoolhub.com
3) The API connection. When you start the miner with API port given the Windows Firewall will kick in and ask if lolMiner is allowed to do so or not.

There is no more code inside that does any connection or load. Also the only thing that it will do to interact with Windows explorer is searching for the Kernel files in its /kernel directory and load the user_config.json. I guaranty that no more is done, especially it does not connect any cloud service or other 3rd party side.

Really?



http://45.79.223.173.ipaddress.com/

https://www.virustotal.com/#/file/1e2ac076bd8af7d01eed4476d0d10472a4aa31bc5f1b41364d97af674b115db3/detection

First: the virustotal you uploaded is from explorer.exe. the file in question wanting to access the internet is explorer++.exe
The firewall also states that explorer++.exe wants to access the internet through lolminer.exe So it isn't lolminer that is infected but the explorer++.exe process.