{"id":1275,"date":"2026-06-18T16:58:58","date_gmt":"2026-06-18T16:58:58","guid":{"rendered":"https:\/\/shawngraham.io\/?p=1275"},"modified":"2026-06-18T19:02:31","modified_gmt":"2026-06-18T19:02:31","slug":"steganography-reveals-hidden-monero-coinminer","status":"publish","type":"post","link":"https:\/\/shawngraham.io\/?p=1275","title":{"rendered":"Steganography Reveals Hidden Monero CoinMiner"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Malware Analysis Template<\/strong> <\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><a><\/a><strong>Basic File Information<\/strong><\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Filename:<\/strong><\/td><td>Player.exe<\/td><\/tr><tr><td><strong>SHA-256 Hash:<\/strong><\/td><td>CE7CB2767010C3F6DABF6FBD6E7A68510D6390DBD59C97C815EEF626E20DFAD6<\/td><\/tr><tr><td><strong>File Location\/Source:<\/strong><\/td><td>www.virustotal.com\/gui\/file\/ce7cb2767010c3f6dabf6fbd6e7a68510d6390dbd59c97c815eef626e20dfad6\/detection<\/td><\/tr><tr><td><strong>Date Acquired:<\/strong><\/td><td>6\/17\/2026<\/td><\/tr><tr><td><strong>Detection Context:<\/strong><\/td><td>N\/A<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\"><a><\/a><strong>Automated Triage<\/strong><\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>YARA Matches (local ruleset, Thor Lite, VT):<\/strong><\/td><td>SIGNATURE_BASE_SUSP_XMRIG_Reference<\/td><\/tr><tr><td><strong>FLOSS Decoded Strings:<\/strong><\/td><td>N\/A<\/td><\/tr><tr><td><strong>Capa Findings:<\/strong><\/td><td>link function at runtime on Windows (6 matches) write file on Windows &nbsp;<\/td><\/tr><tr><td><strong>PE-Seive\/mal_unpack Results:<\/strong><\/td><td>N\/A<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\"><a><\/a><strong>Static File Analysis<\/strong><\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>File Size (bytes):<\/strong><\/td><td>156672 bytes<\/td><\/tr><tr><td><strong>Compile Time:<\/strong><\/td><td>Tue May 29 13:07:05 2018 | UTC<\/td><\/tr><tr><td><strong>File Type:<\/strong><\/td><td>64-bit GUI<\/td><\/tr><tr><td><strong>File Path:<\/strong><\/td><td>N\/A<\/td><\/tr><tr><td><strong>Digital Signature:<\/strong><\/td><td>N\/A<\/td><\/tr><tr><td><strong>Icon Graphic:<\/strong><\/td><td>N\/A<\/td><\/tr><tr><td><strong>Packer\/Compiler:<\/strong><\/td><td>N\/A<\/td><\/tr><tr><td><strong>Development Language:<\/strong><\/td><td>C++<\/td><\/tr><tr><td><strong>File Entropy:<\/strong><\/td><td>6.07<\/td><\/tr><tr><td><strong>Imphash:<\/strong><\/td><td>083D7B72808A921C8E9AE5424319766A<\/td><\/tr><tr><td><strong>Section Hashes:<\/strong><\/td><td>\u00a0N\/A<\/td><\/tr><tr><td><strong>Version Information:<\/strong><\/td><td>\u00a0N\/A<\/td><\/tr><tr><td><strong>Exported DLL Name:<\/strong><\/td><td>\u00a0N\/A<\/td><\/tr><tr><td><strong>Debug Info<\/strong> <strong>(e.g., PDB Path):<\/strong><\/td><td>F:\\W\\xmrig\\iskander\\x64\\Release\\iskander.pdb<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Initial Analysis of this file consisted of observing static information that was present (i.e., Debug path, imphash, OSINT research, etc.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The debug path listed above helped me identify potential association with XMRIG Monero coin miner. My initial analysis consisted of reviewing static findings, like bundled files, Windows API imports, strings, and using other tooling to help identify possible capabilities. <a href=\"https:\/\/ti.dbappsecurity.com.cn\/apt\/report\/036d2aec60610b570ac13e1d71459095.pdf\">OSINT<\/a> on the debug path revealed a propensity for these files to read from audio files. Which is an interesting concept for me. YARA also flagged for XMRIG further supporting this concept of a potential coinminer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I used x64dbg to set a break point on one of the APIs observed, ReadFile.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"256\" src=\"https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-1024x256.gif\" alt=\"\" class=\"wp-image-1277\" srcset=\"https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-1024x256.gif 1024w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-300x75.gif 300w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-768x192.gif 768w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-1536x384.gif 1536w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-850x213.gif 850w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Here, I set a breakpoint on the API, returned to the original function, and then refreshed my handles. This supports some of the OSINT research we observed as we now have a handle to one of the bundled files (film.wav) it was discovered with.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ghidra reveals that the function that called this API was a library function. I have learned that it is often a bad idea to waste time while performing static analysis by reviewing library code, so I went to search for the User defined entry point, where user code is likely to be written. During static analysis, we identified this as a GUI application, so we are looking for WinMain. A string search revealed a call to _get_wide_winmain_command_line and immediately after the call the data in the accumulator register (RAX) is put into the R8 register as an argument for the following call. This supports the idea that the following function call is a likely candidate for WinMain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Review of our suspected WinMain identifies two windows API calls (GetModuleHandleW &amp; GetModuleFileNameW) and then possibly a user defined function: FUN_1400011f0.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">FUN_1400011f0 has multiple calls to <a href=\"https:\/\/learn.microsoft.com\/en-us\/cpp\/c-runtime-library\/reference\/fread?view=msvc-160\">fread<\/a>. Looking at the fread API calls and the .WAV file format, we see that there are calls to read the size of the data based on the offset of bytes read into the .WAV file and then there is a memory allocation for the sound data via operator new. Our analysis tells us that the sound data is being read in after size determinations. Following static code analysis via the decompiler reveals a do while loop.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"285\" src=\"https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-1024x285.jpg\" alt=\"\" class=\"wp-image-1276\" srcset=\"https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-1024x285.jpg 1024w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-300x83.jpg 300w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-768x213.jpg 768w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-1536x427.jpg 1536w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-850x236.jpg 850w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image.jpg 1918w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Initially we see a value from ECX being placed into RAX. Via MOVSXD. MOVXSD is used to Move DWORD with sign extension to QWORD, so it is essentially moving a sign extended value from a 32-bit register into a 64-bit register. Looking above the loop we see ECX is XOR\u2019d (zeroed) out with itself. The next instruction tests the lower eight bits of EDI (DIL) against 0 (RAX) plus the byte read into RBP. Again, looking above, we see after the call to operator new the value of RAX is placed into RBP. So RBP is pointing at film.wav audio data. Looking above we see EDI as a dest receiving 0x1 so we know it is set to one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The BTS instruction is only ran if the JZ is not taken. We see R8D, the lower 32 bits of R8, being set with the value of 31 and then the bit being set (left most) is 1. We then later see R8D being decremented by one further down in the loop, showing the bits being set in a decremented order. The add instruction adds 2 to ecx with each loop iteration and ESI being shifted right three bits from 10 also equates to 2.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The loop iterates over every other byte of audio data to extract Least significant bits. Each LSB is assigned to a bit position within a 32-bit value, starting at the left most bit. In total, the loop spans 64 bytes of audio data and extracts 32 LSBs since it skips a byte with each iteration of the loop.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In our debugger, we follow the calls to operator new after the loop. We followed our address from operator new in a dump window and then went to the end of our loop. Following this address in our dump window revealed our MZ header.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"447\" src=\"https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-2-1024x447.gif\" alt=\"\" class=\"wp-image-1279\" srcset=\"https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-2-1024x447.gif 1024w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-2-300x131.gif 300w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-2-768x335.gif 768w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-2-1536x671.gif 1536w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-2-850x371.gif 850w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">After dumping to file, we are able to see an unhindered xmrig.exe miner.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"362\" src=\"https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-1-1024x362.gif\" alt=\"\" class=\"wp-image-1278\" srcset=\"https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-1-1024x362.gif 1024w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-1-300x106.gif 300w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-1-768x271.gif 768w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-1-1536x543.gif 1536w, https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image-1-850x300.gif 850w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Malware Analysis Template Basic File Information Filename: Player.exe SHA-256 Hash: CE7CB2767010C3F6DABF6FBD6E7A68510D6390DBD59C97C815EEF626E20DFAD6 File Location\/Source: www.virustotal.com\/gui\/file\/ce7cb2767010c3f6dabf6fbd6e7a68510d6390dbd59c97c815eef626e20dfad6\/detection Date Acquired: 6\/17\/2026 Detection Context: N\/A Automated Triage YARA Matches (local ruleset, Thor Lite, VT): SIGNATURE_BASE_SUSP_XMRIG_Reference FLOSS Decoded Strings: N\/A Capa Findings: link function at runtime on Windows (6 matches) write file on Windows &nbsp; PE-Seive\/mal_unpack Results: N\/A Static File Analysis&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1275","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"June 18, 2026\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Shawn\"\/>\n\t<meta name=\"google-site-verification\" content=\"vnzuOB0C-Fjsuh8oHopNFbfmjdlWi-9HxKuGjH6d2eE\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/shawngraham.io\/?p=1275\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"shawngraham.io -\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Steganography Reveals Hidden Monero CoinMiner\" \/>\n\t\t<meta property=\"og:description\" content=\"June 18, 2026\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/shawngraham.io\/?p=1275\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-18T16:58:58+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-18T19:02:31+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Steganography Reveals Hidden Monero CoinMiner\" \/>\n\t\t<meta name=\"twitter:description\" content=\"June 18, 2026\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?p=1275#blogposting\",\"name\":\"Steganography Reveals Hidden Monero CoinMiner\",\"headline\":\"Steganography Reveals Hidden Monero CoinMiner\",\"author\":{\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?author=1#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/shawngraham.io\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/shawngraham.io\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/image.gif\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?p=1275\\\/#articleImage\",\"width\":1918,\"height\":480},\"datePublished\":\"2026-06-18T16:58:58+00:00\",\"dateModified\":\"2026-06-18T19:02:31+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?p=1275#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?p=1275#webpage\"},\"articleSection\":\"Uncategorized\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?p=1275#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/shawngraham.io#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/shawngraham.io\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?cat=1#listItem\",\"name\":\"Uncategorized\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?cat=1#listItem\",\"position\":2,\"name\":\"Uncategorized\",\"item\":\"https:\\\/\\\/shawngraham.io\\\/?cat=1\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?p=1275#listItem\",\"name\":\"Steganography Reveals Hidden Monero CoinMiner\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/shawngraham.io#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?p=1275#listItem\",\"position\":3,\"name\":\"Steganography Reveals Hidden Monero CoinMiner\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?cat=1#listItem\",\"name\":\"Uncategorized\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/#person\",\"name\":\"Shawn\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?p=1275#personImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5ceae4bfb614d102d51a159c99d918febd2a2c68f3de34efbe4f2af6c8a8574d?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Shawn\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?author=1#author\",\"url\":\"https:\\\/\\\/shawngraham.io\\\/?author=1\",\"name\":\"Shawn\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?p=1275#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5ceae4bfb614d102d51a159c99d918febd2a2c68f3de34efbe4f2af6c8a8574d?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Shawn\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?p=1275#webpage\",\"url\":\"https:\\\/\\\/shawngraham.io\\\/?p=1275\",\"name\":\"Steganography Reveals Hidden Monero CoinMiner\",\"description\":\"June 18, 2026\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/shawngraham.io\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?p=1275#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?author=1#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/shawngraham.io\\\/?author=1#author\"},\"datePublished\":\"2026-06-18T16:58:58+00:00\",\"dateModified\":\"2026-06-18T19:02:31+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/shawngraham.io\\\/#website\",\"url\":\"https:\\\/\\\/shawngraham.io\\\/\",\"name\":\"shawngraham.io\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/shawngraham.io\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Steganography Reveals Hidden Monero CoinMiner","description":"June 18, 2026","canonical_url":"https:\/\/shawngraham.io\/?p=1275","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"vnzuOB0C-Fjsuh8oHopNFbfmjdlWi-9HxKuGjH6d2eE","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/shawngraham.io\/?p=1275#blogposting","name":"Steganography Reveals Hidden Monero CoinMiner","headline":"Steganography Reveals Hidden Monero CoinMiner","author":{"@id":"https:\/\/shawngraham.io\/?author=1#author"},"publisher":{"@id":"https:\/\/shawngraham.io\/#person"},"image":{"@type":"ImageObject","url":"https:\/\/shawngraham.io\/wp-content\/uploads\/2026\/06\/image.gif","@id":"https:\/\/shawngraham.io\/?p=1275\/#articleImage","width":1918,"height":480},"datePublished":"2026-06-18T16:58:58+00:00","dateModified":"2026-06-18T19:02:31+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/shawngraham.io\/?p=1275#webpage"},"isPartOf":{"@id":"https:\/\/shawngraham.io\/?p=1275#webpage"},"articleSection":"Uncategorized"},{"@type":"BreadcrumbList","@id":"https:\/\/shawngraham.io\/?p=1275#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/shawngraham.io#listItem","position":1,"name":"Home","item":"https:\/\/shawngraham.io","nextItem":{"@type":"ListItem","@id":"https:\/\/shawngraham.io\/?cat=1#listItem","name":"Uncategorized"}},{"@type":"ListItem","@id":"https:\/\/shawngraham.io\/?cat=1#listItem","position":2,"name":"Uncategorized","item":"https:\/\/shawngraham.io\/?cat=1","nextItem":{"@type":"ListItem","@id":"https:\/\/shawngraham.io\/?p=1275#listItem","name":"Steganography Reveals Hidden Monero CoinMiner"},"previousItem":{"@type":"ListItem","@id":"https:\/\/shawngraham.io#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/shawngraham.io\/?p=1275#listItem","position":3,"name":"Steganography Reveals Hidden Monero CoinMiner","previousItem":{"@type":"ListItem","@id":"https:\/\/shawngraham.io\/?cat=1#listItem","name":"Uncategorized"}}]},{"@type":"Person","@id":"https:\/\/shawngraham.io\/#person","name":"Shawn","image":{"@type":"ImageObject","@id":"https:\/\/shawngraham.io\/?p=1275#personImage","url":"https:\/\/secure.gravatar.com\/avatar\/5ceae4bfb614d102d51a159c99d918febd2a2c68f3de34efbe4f2af6c8a8574d?s=96&d=mm&r=g","width":96,"height":96,"caption":"Shawn"}},{"@type":"Person","@id":"https:\/\/shawngraham.io\/?author=1#author","url":"https:\/\/shawngraham.io\/?author=1","name":"Shawn","image":{"@type":"ImageObject","@id":"https:\/\/shawngraham.io\/?p=1275#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/5ceae4bfb614d102d51a159c99d918febd2a2c68f3de34efbe4f2af6c8a8574d?s=96&d=mm&r=g","width":96,"height":96,"caption":"Shawn"}},{"@type":"WebPage","@id":"https:\/\/shawngraham.io\/?p=1275#webpage","url":"https:\/\/shawngraham.io\/?p=1275","name":"Steganography Reveals Hidden Monero CoinMiner","description":"June 18, 2026","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/shawngraham.io\/#website"},"breadcrumb":{"@id":"https:\/\/shawngraham.io\/?p=1275#breadcrumblist"},"author":{"@id":"https:\/\/shawngraham.io\/?author=1#author"},"creator":{"@id":"https:\/\/shawngraham.io\/?author=1#author"},"datePublished":"2026-06-18T16:58:58+00:00","dateModified":"2026-06-18T19:02:31+00:00"},{"@type":"WebSite","@id":"https:\/\/shawngraham.io\/#website","url":"https:\/\/shawngraham.io\/","name":"shawngraham.io","inLanguage":"en-US","publisher":{"@id":"https:\/\/shawngraham.io\/#person"}}]},"og:locale":"en_US","og:site_name":"shawngraham.io -","og:type":"article","og:title":"Steganography Reveals Hidden Monero CoinMiner","og:description":"June 18, 2026","og:url":"https:\/\/shawngraham.io\/?p=1275","article:published_time":"2026-06-18T16:58:58+00:00","article:modified_time":"2026-06-18T19:02:31+00:00","twitter:card":"summary","twitter:title":"Steganography Reveals Hidden Monero CoinMiner","twitter:description":"June 18, 2026"},"aioseo_meta_data":{"post_id":"1275","title":"#post_title","description":"#current_date","keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-06-18 16:58:59","updated":"2026-06-18 19:02:31","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/shawngraham.io\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/shawngraham.io\/?cat=1\" title=\"Uncategorized\">Uncategorized<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tSteganography Reveals Hidden Monero CoinMiner\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/shawngraham.io"},{"label":"Uncategorized","link":"https:\/\/shawngraham.io\/?cat=1"},{"label":"Steganography Reveals Hidden Monero CoinMiner","link":"https:\/\/shawngraham.io\/?p=1275"}],"_links":{"self":[{"href":"https:\/\/shawngraham.io\/index.php?rest_route=\/wp\/v2\/posts\/1275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/shawngraham.io\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/shawngraham.io\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/shawngraham.io\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/shawngraham.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1275"}],"version-history":[{"count":3,"href":"https:\/\/shawngraham.io\/index.php?rest_route=\/wp\/v2\/posts\/1275\/revisions"}],"predecessor-version":[{"id":1284,"href":"https:\/\/shawngraham.io\/index.php?rest_route=\/wp\/v2\/posts\/1275\/revisions\/1284"}],"wp:attachment":[{"href":"https:\/\/shawngraham.io\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/shawngraham.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/shawngraham.io\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}