Home Acknowledgements Hacking Events Public Profiles Background education Resources Talks

Miguel Santareno

OSINT Dojo - OSINT challenge week 07/18/2022 - MikroTik Cryptojacking

The challenge is the following:


Based on the IP above mentioned i seach for the IP on shodan and i saw a CoinHive key on a iframe on the IP mentioned above on port 3001

Next i search for that key in shodan to retreive the other IP's that are running the same key


Other MikroTik Cryptojacking Campaigns


What indicator(s) are there that this device was previously compromised??

CoinHive key found on a iframe on the IP mentioned above on port 3001

Can you locate two other devices likely compromised by the same actor?



Quote of the day: Try Harder!