Please immediately ban this user. they are hacking open claymore management port and pointing to this address
-zpool zec.coinmine.pl:7007
-zwal Stromfreser.Stromfresser1
-zpsw jamjam
-allpools 1
#-tt 75
How can I verify this?
Im working on it. Ive just posted in the claymore thread. see my config. ill get more as soon as i can.
04:41:44:215 1ff8 sent: 164
04:41:48:090 1630 recv: 51
04:41:48:090 1630 srv pck: 50
04:41:48:137 1630 srv bs: 0
04:41:48:137 1630 sent: 164
04:41:49:152 1010 recv: 51
04:41:49:152 1010 srv pck: 50
04:41:49:199 1010 srv bs: 0
04:41:49:199 1010 sent: 164
04:41:49:246 19c0 ZEC: put share nonce c567
04:41:49:246 19c0 ZEC round found 1 shares
04:41:49:262 21cc ZEC: 11/18/16-04:41:49 - SHARE FOUND - (GPU 2)
04:41:49:262 21cc send share: {"id": 4, "method": "mining.submit", "params": ["d57heinz.Hp3gpu","21e","38da2e58","67c50000000000000000000000000000000000000000000000000000","fd40050024865542ca2e9a7ebf004594df4f9da5d7b1114c3fe897a89
04:41:49:324 21cc got 36 bytes
04:41:49:324 21cc buf: {"id":4,"result":true,"error":null}
04:41:49:324 21cc parse packet: 35
04:41:49:340 21cc ZEC: Share accepted (78 ms)!
04:41:49:340 21cc new buf size: 0
04:41:53:090 235c recv: 51
04:41:53:090 235c srv pck: 50
04:41:53:137 235c srv bs: 0
04:41:53:137 235c sent: 164
04:41:54:152 d9c recv: 51
04:41:54:152 d9c srv pck: 50
04:41:54:199 d9c srv bs: 0
04:41:54:215 d9c sent: 164
04:41:57:793 1978 GPU0 t=60C fan=69%, GPU1 t=66C fan=47%, GPU2 t=70C fan=49%
04:41:57:809 1978 em hbt: 0, fm hbt: 47,
04:41:57:809 1978 watchdog - thread 0, hb time 94
04:41:57:809 1978 watchdog - thread 1, hb time 172
04:41:57:824 1978 watchdog - thread 2, hb time 250
04:41:57:824 1978 watchdog - thread 3, hb time 16
04:41:57:824 1978 watchdog - thread 4, hb time 156
04:41:57:840 1978 watchdog - thread 5, hb time 235
04:41:57:840 1978 watchdog - thread 6, hb time 16
04:41:57:840 1978 watchdog - thread 7, hb time 78
04:41:57:855 1978 watchdog - thread 8, hb time 78
04:41:57:855 1978 watchdog - thread 9, hb time 110
04:41:57:871 1978 watchdog - thread 10, hb time 31
04:41:57:871 1978 watchdog - thread 11, hb time -15
04:41:58:090 20 recv: 51
04:41:58:105 20 srv pck: 50
04:41:58:152 20 srv bs: 0
04:41:58:152 20 sent: 164
04:41:59:168 1a4c recv: 51
04:41:59:168 1a4c srv pck: 50
04:41:59:215 1a4c srv bs: 0
04:41:59:215 1a4c sent: 164
04:42:03:090 14b4 recv: 51
04:42:03:105 14b4 srv pck: 50
04:42:03:152 14b4 srv bs: 0
04:42:03:152 14b4 sent: 164
04:42:04:184 203c recv: 51
04:42:04:184 203c srv pck: 50
04:42:04:230 203c srv bs: 0
04:42:04:230 203c sent: 164
04:42:08:090 1a50 recv: 51
04:42:08:105 1a50 srv pck: 50
04:42:08:137 1a50 srv bs: 0
04:42:08:152 1a50 sent: 164
04:42:08:668 4bc recv: 270
04:42:08:668 4bc srv pck: 269
04:42:08:684 4bc Remote management: file config.txt was downloaded
04:42:08:684 4bc srv bs: 0
04:42:08:699 4bc sent: 40
04:42:09:199 1f24 recv: 51
04:42:09:199 1f24 srv pck: 50
04:42:09:246 1f24 srv bs: 0
04:42:09:246 1f24 sent: 164
04:42:11:559 21ec recv: 50
04:42:11:574 21ec srv pck: 49
04:42:11:574 21ec Remote management required restart
04:42:13:074 21ec Restarting OK, ex
04:42:15:762 18e8 args: -zpool zec.coinmine.pl:7007 -zwal Stromfreser.Stromfresser1 -zpsw jamjam -allpools 1
04:42:15:762 18e8
04:42:15:762 18e8 ÉÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ»
04:42:15:777 18e8 º Claymore's ZCash AMD GPU Miner v6.0 Beta º
04:42:15:777 18e8 ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍͼ
04:42:15:777 18e8
04:42:15:996 18e8 ZEC: 1 pool is specified
04:42:15:996 18e8 Main ZCash pool is zec.coinmine.pl:7007
04:42:16:887 18e8 OpenCL platform: AMD Accelerated Parallel Processing
04:42:16:902 18e8 OpenCL initializing...
04:42:16:902 18e8 AMD Cards available: 3
04:42:16:902 18e8 GPU #0: Tahiti, 3072 MB available, 32 compute units
04:42:16:918 18e8 GPU #0 recognized as Radeon 280X/380X
04:42:16:918 18e8 GPU #1: Tahiti, 3072 MB available, 32 compute units
04:42:16:918 18e8 GPU #1 recognized as Radeon 280X/380X
04:42:16:934 18e8 GPU #2: Hawaii, 8192 MB available, 44 compute units
04:42:16:934 18e8 GPU #2 recognized as Radeon 390X
04:42:16:949 18e8 POOL version
04:42:16:949 18e8 b225
04:42:16:949 18e8 Platform: Windows
04:42:16:980 18e8 start building OpenCL program for GPU 0...
04:42:16:980 18e8 done
04:42:17:105 18e8 Frontend phase failed compilation.
Error: Compilation from LLVMIR binary to IL text failed!
04:42:17:105 18e8 16x binary failed, try 15x
04:42:17:152 18e8 start building OpenCL program for GPU 0...
04:42:18:340 18e8 done
04:42:18:465 18e8 start building OpenCL program for GPU 1...
04:42:18:465 18e8 done
04:42:18:590 18e8 Frontend phase failed compilation.
Error: Compilation from LLVMIR binary to IL text failed!
04:42:18:590 18e8 16x binary failed, try 15x
04:42:18:605 18e8 start building OpenCL program for GPU 1...
04:42:19:777 18e8 done
04:42:19:902 18e8 start building OpenCL program for GPU 2...
04:42:19:902 18e8 done
04:42:20:027 18e8 Error: AMD HSA Code Object loading failed.
04:42:20:027 18e8 16x binary failed, try 15x
04:42:20:043 18e8 start building OpenCL program for GPU 2...
04:42:20:043 18e8 done
04:42:20:168 18e8 GPU #0 intensity 4
04:42:20:168 18e8 GPU #1 intensity 4
04:42:20:168 18e8 GPU #2 intensity 4
04:42:20:184 18e8 Total cards: 3
04:42:31:575 1274 ZEC: Stratum - connecting to 'zec.coinmine.pl' <168.235.96.102> port 7007
04:42:31:613 18e8 "-allpools" option is set, default pools can be used for devfee, check "Readme" file for details.
04:42:31:613 18e8 Watchdog enabled
04:42:31:613 18e8 Remote management is enabled on port 3333
04:42:31:629 18e8
04:42:31:629 1274 send: {"id": 1, "method": "mining.subscribe", "params": ["equihashminer", null, "zec.coinmine.pl", "7007"]}
04:42:31:644 1274 send: {"id": 2, "method": "mining.authorize", "params": ["Stromfreser.Stromfresser1","jamjam"]}
04:42:31:644 1274 send: {"id": 5, "method": "mining.extranonce.subscribe", "params": []}
04:42:31:660 1274 ZEC: Stratum - Connected (zec.coinmine.pl:7007)
04:42:31:729 1274 got 79 bytes
95.85.49.122 ip of the attacker
2016-11-01 08:48:07.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,1223
2016-11-01 08:48:13.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,8054
2016-11-01 08:48:21.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,2094
2016-11-01 08:48:27.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,2703
2016-11-01 08:49:13.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,245
2016-11-01 08:49:51.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,973
2016-11-01 08:50:21.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,2387
2016-11-01 08:50:29.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,5703
2016-11-01 08:50:50.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,8970
2016-11-01 08:51:30.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,7688
2016-11-01 08:52:50.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,8846
2016-11-01 08:53:06.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,374
2016-11-03 08:04:51.00 [PORT SCAN]UDP Packet - Source:188.214.128.75,5061 Destination:192.168.0.2,4444
2016-11-08 07:28:25.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,9693
2016-11-08 09:25:34.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,400
2016-11-08 09:25:42.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,4034
2016-11-08 09:32:29.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,8005
2016-11-08 10:15:10.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,485
2016-11-08 10:38:21.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,688
2016-11-08 10:49:22.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,5047
2016-11-08 10:49:28.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,4173
2016-11-08 10:56:17.00 [PORT SCAN]TCP Packet - Source:95.85.49.122,60000 Destination:192.168.0.2,5793
one way to check is you could look at that user and see where the ips are coming from that his account is getting work from. I can pm you my ip or you could just look at my user and see that the majority come from one ip 5/8 users and the other 3 from another. By looking these logs i would have no reason to swap that miner over plus i live in usa and was in bed when this occured. Obviously you cant take my word for it. but im sure with a little diggin on this guy you will find your answers. Im taking drastic measures to secure my coins.> 99% reside on trezor and paper ..
Best Regards
d57heinz