OPEN SOURCE · MIT LICENSE · v2.0.0

ScannerSend

Behavioral crypto mining defense. Catches miners by what they do, not just what they look like. One script. Zero dependencies. Free forever.

Install · Any Linux · 30 seconds
curl -sS https://scannersend.org/install.sh | sudo bash
Copy

Scan-only by default. I believe in consent.  ·  Clean uninstall. Leave no trace.

crypto_annihilator.py
Threat Annihilation

When I find a miner,
it doesn't get to finish its last hash.

Six Reasons to Run It

Built from real attack experience. Every feature exists because something went wrong without it.

CORE
🧬

Behavioral Detection

Doesn't care what the binary looks like. Detects mining behavior — Stratum protocol, sustained CPU + network combos. Catches zero-days and custom miners.

CORE

Five Detection Layers

Network protocol. CPU behavioral analysis. Known signatures. Connection fingerprinting. Wallet forensics. If a miner runs, it dies — even custom-compiled, obfuscated, renamed miners.

CORE
📦

Single File. Zero Deps.

One Python file. No pip install. No Docker. No config files. Works on any Linux with Python 3.6+. Download and run. That's it.

NEW
🛡

Self-Healing Persistence

Run --fortify to install 5 independent persistence layers. Systemd, cron watchdog, rc.local, immutable binary, self-copy. Kill one — four more bring it back.

NEW
🗑

Clean Uninstall

Run --uninstall and every trace is removed. Service files, cron jobs, immutable flags, the binary itself. One command. Clean exit.

NEW
📊

Status Dashboard

Run --status to see your protection state at a glance. Which persistence layers are active, when the last scan ran, how many miners killed.

Five Layers of Protection

SELF-HEALING PERSISTENCE

Five layers. All independent.
All self-repairing.

Run --fortify and try to kill me.

0
Detection Layers
0
Persistence Layers
0
Dependencies
0
Lines of Code
MIT
License

Stop miners. Not processes.

Stratum protocol detection has zero false positives. CPU behavioral analysis uses configurable thresholds with --whitelist support for your workloads.

Your antivirus may flag the persistence layers. That's normal — here's why. Use --no-persist for AV-friendly mode.

curl -sS https://scannersend.org/install.sh | sudo bash
Copy
Now Live

ScannerSend Network

Every kill extracts the attacker's wallet address. The optional plugin reports it to a crowd-sourced database. The more servers that run it, the faster wallets get burned.

🔍
Wallet
Extraction
🔒
HMAC
Signed
🌐
Crowd
Validated
🛡
Zero
PII
Learn How It Works View Reported Wallets
admin