Trick or Treat - Unveil the "Stratum" of the Mining Pools

Trick or Treat - Unveil the "Stratum" of the Mining Pools

NorthSec via YouTube Direct link

Intro

1 of 23

1 of 23

Intro

Class Central Classrooms beta

YouTube playlists curated by Class Central.

Classroom Contents

Trick or Treat - Unveil the "Stratum" of the Mining Pools

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 ryptomining malware is still a thing
  3. 3 Mining pools 101
  4. 4 We developed different strategies to identify Stratum servers
  5. 5 Let's hunt for interesting samples
  6. 6 Processing workflow (static analysis)
  7. 7 Here are some way to specify Stratum server
  8. 8 Dynamic analysis
  9. 9 Extracting Stratum configuration from PCAPS
  10. 10 Looking for stratum servers over the Internet
  11. 11 Search Engines for Connected Hosts
  12. 12 Keywords to identify stratum servers
  13. 13 Identifying Mining Pool Websites
  14. 14 Extracting config: JS config file + API call
  15. 15 Extracting config: parsing HTML
  16. 16 Extracting config: (Parsing HTML) + API Call
  17. 17 Stratum TCP Scanner
  18. 18 Collected data
  19. 19 Default ports?
  20. 20 Scanning Internet
  21. 21 Docker exploitations?
  22. 22 Killing the competition
  23. 23 Very persistent miner

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.