My Symantec Endpoint protection is occasionally showing that it blocks a JSCoinminer Download 8 script that seems to run when on random TexAg pages.
Category: Intrusion Prevention
Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
12/4/2017 12:00:30 PM,High,An intrusion attempt by was blocked.,Blocked,No Action Required,Web Attack: JSCoinminer Download 8,No Action Required,No Action Required," (2400:cb00:2048:1::6818:7255, 80)",,****edited out personal computer ID*** ", (2400:cb00:2048:1::6818:7255),"TCP, www-http"
Network traffic from <b></b> matches the signature of a known attack. The attack was resulted from \DEVICE\HARDDISKVOLUME3\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE. To stop being notified for this type of traffic, in the <b>Actions</b> panel, click <b>Stop Notifying Me</b>.