Author Topic: Question  (Read 11200 times)

0 Members and 1 Guest are viewing this topic.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Question
« on: January 03, 2014, 01:52:23 AM »
Hi, I do malware sampling with Steven and Polonus. I found 15 undetected files all for Linux. Where do I report them and too who? I'm using Avast! for Windows. So that'd be useless.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Question
« Reply #1 on: January 03, 2014, 05:30:21 PM »
I found 15 undetected files all for Linux. Where do I report them and too who?

Report them to: virus[at]avast.com
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Question
« Reply #2 on: January 03, 2014, 07:13:44 PM »
That's what I thought. Thanks Asyn
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Question
« Reply #3 on: January 03, 2014, 07:40:28 PM »
You're welcome.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

MAG

  • Guest
Re: Question
« Reply #4 on: January 05, 2014, 02:43:05 PM »
Hi, I do malware sampling with Steven and Polonus. I found 15 undetected files all for Linux. Where do I report them and too who? I'm using Avast! for Windows. So that'd be useless.

That's a lot of Linux specific malware.

Do you think you could also submit them to virustotal and post back the links so that we can see what and who is detecting?

Thanks

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Question
« Reply #5 on: January 05, 2014, 03:12:14 PM »
Hi Mag,

As I am not at my primary machine and on a very unsecure system right now I cannot. Steven Winderlich asked for the DL and to do Malware Analysis. He might be able to post VT links. If not It'll take me 2ish hours to get them for you.

Note: As I am not familiar with Linux malware, I don't know what an "exe" file is in comparison to windows. So the rest of the files might just be random files.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Question
« Reply #6 on: January 05, 2014, 03:49:51 PM »
Here are Virustotal Links:

https://www.virustotal.com/de/file/e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855/analysis/1388931790/
https://www.virustotal.com/de/file/2da21e720ea25ed6c01c80d4ec505171e28bc600b47c734dab4a40455a8ef51c/analysis/1388931880/
https://www.virustotal.com/de/file/14afcf4d9a22b2d884ecfc6ff76c9ab19f308dfb9ae8c0b2fc2ea5b004369256/analysis/1388931972/
https://www.virustotal.com/de/file/2965a5d3dcbf6b84aadf1b9cba8933f4c001337de98bd5026509cc566364d559/analysis/1388932047/
https://www.virustotal.com/de/file/a6f344ec62c9172377e1bbc237bfd2bc7df129a38f83a0686f651fc62545aea2/analysis/1388932143/
https://www.virustotal.com/de/file/9b1ba5c5121b6da67e984db6ecca9235c58fe6bb0545aa70297917fddf5e6ed4/analysis/1388932197/
https://www.virustotal.com/de/file/1d544b61c13a63b115d45fd9e2c8647d179cea8e027148ee48dfd5b421daf6ae/analysis/1388932249/
https://www.virustotal.com/de/file/e7031aaa218f814ec442f7fc5cc545980a537d777db491c425d60f0be3366074/analysis/1388932295/
https://www.virustotal.com/de/file/384d6253d953a4f9888e82111e910411cefed433b2db8dac89a7befb814b15fd/analysis/1388932355/
https://www.virustotal.com/de/file/00b0a356ee36e79f6d11222e833b12b5ff5843e237daaeb897ad6c60f63adff9/analysis/1388932408/
https://www.virustotal.com/de/file/338d943ce59720ece16294a88ce44bf905a1156d65bc035e631577090132ffbd/analysis/1388932452/
https://www.virustotal.com/de/file/5e092470ec616d5b866aab0f1a69309b74a48567eec7a250c9a328901a21a498/analysis/1388932503/
https://www.virustotal.com/de/file/cc3f6c535787c71bed14ec8ac3b6feb59fe3b09fc53c69f1fe592103f2632764/analysis/1388932571/
https://www.virustotal.com/de/file/2413af510a75ada34716165992a425b35f62ba1478f63746502afd8a8a156b80/analysis/1388932677/
https://www.virustotal.com/de/file/97093a1ef729cb954b2a63d7ccc304b18d0243e2a77d87bbbb94741a0290d762/analysis/1388932796/
https://www.virustotal.com/de/file/d0afe5b8470b5884f6133a8da4b6b20d06384149da8a4ffad5a7e8b19a259d9f/analysis/1388932865/
https://www.virustotal.com/de/file/93df64cc0ff902ad1e80ada56023610ec2c44c3ecde2d36d37a3a748c7fd42bd/analysis/1388932927/
https://www.virustotal.com/de/file/8132f80f6e82b84c06d1bd8c8a40902d53be94e1262acc71bb3e36df57eecd8f/analysis/1388932990/

Last one is just a text filw with an IP in it.
IP Scan: https://www.virustotal.com/de/url/580cef0b6d5c984a99a111d960a6a33bad324efc1a76ed92ee911601ee53cdf6/analysis/1388933253/
« Last Edit: January 05, 2014, 04:49:31 PM by Steven Winderlich »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

MAG

  • Guest
Re: Question
« Reply #7 on: January 05, 2014, 04:51:01 PM »
Many thanks for taking the time to do this.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Question
« Reply #8 on: January 05, 2014, 04:53:20 PM »
No problem.

These are script files i think, so they are executed in Terminal or via browser.
Or maybe with some else program. Cant get them to run here under Ubuntu 13.10 with latest updates.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Question
« Reply #9 on: January 05, 2014, 05:06:46 PM »
One of the malware files is running in memory. (Screenshot)

Also Ubuntu is unable to connect to my GMail Account. (Screenshot)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

MAG

  • Guest
Re: Question
« Reply #10 on: January 05, 2014, 08:49:46 PM »
I'm no malware expert, but when I come across references to linux malware I try to check to see which scannners detect it. This sample doesn't imply any reason to switch from my current scanner (comodo).

Thanks again.

Offline Abraxas

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 730
  • Perseverance Furthers...
    • PCLinuxOS-Forums
Re: Question
« Reply #11 on: January 12, 2014, 09:39:54 PM »
I think you'll find you have a bunch of False Positives.  ;)
(EDIT:Steven Winderlich I take it you're running windows, and Ubuntu as a Dual Boot setup, and have scanned your Linux partition with Avast! for Windows ?
Try installing the Linux scanner into Ubuntu, and running it.
It's very uncommon to have anything but 'Windows' viruses in Linux, which are harmless, and can be simply cleaned using Avast4Linuxworkstations.
)
Regards,

Tony.

This is a problem relating to a URL we had a while back.

The best action to take is described in my quote:
http://forum.avast.com/index.php?topic=141439.msg1032132#msg1032132
When faced with your Web site being deemed to contain Malware, or a problem with Avast! (generally for Windows) blocking access to your site please report it immediately to Avast! Support [AVAST Software a.s.] https://support.avast.com/Tickets/Submit/RenderForm

I found their direct intervention the quickest way to resolve such issues, the forum next to useless.

Choose your Problem

Submit a Ticket
Get a direct and fast response.

Having a site blocked needs to be quickly remedied, it may cost you customers, exposure, etc. as is reasonable to expect.
The Direct approach I found technically pertinent in clearing the instance of a False Positive.
Using the Avast Support Forum cost time, lots of it, and custom.

I hope this may help others who may have a problem, as I once did .  :)
« Last Edit: January 12, 2014, 09:47:57 PM by Abraxas »

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Question
« Reply #12 on: January 24, 2014, 11:10:44 PM »
Hi Abraxas,

no this is a virtual machine created with virtualbox, i would never ruzn Linux Malware on a dualboot system. :)

But maybe i will set up a Linux system like OpenSUSE or something
on my grandpas computer and maybe i will head over to linux too. But im not sure yet.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Abraxas

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 730
  • Perseverance Furthers...
    • PCLinuxOS-Forums
Re: Question
« Reply #13 on: January 26, 2014, 08:49:54 PM »
Hi Steven Winderlich,

you may have confused some issues raised by the OP.
alan1998:
Quote
Hi, I do malware sampling with Steven and Polonus. I found 15 undetected files all for Linux. Where do I report them and too who? I'm using Avast! for Windows. So that'd be useless.
Quote
Note: As I am not familiar with Linux malware, I don't know what an "exe" file is in comparison to windows. So the rest of the files might just be random files.
To clarify that statement, linux does not use 'exe' files.
This whole post is rather confused and misleading: Statements such as Linux Malware need to be backed up with a running Linux DE, stating found Malware, and why it is thought to be Linux Malware, which is quite an involved task. Much moreso than processing what is known Windows Malware ;)

I believe what you're seeing is Windows Malware, running in virtualbox, in or your Host Windows.

All viruses found by us running on our Linux DE's are Windows viruses, which are unable to execute, as they are based on an"exe" file, which don't run in linux.

The main purpose of running a Virus scanner like Avast!4linuxworkstations is so as not to transmit windows executable malware from a Linux system, to a friend who is using Windows. Transmission can be made via Email, or file sharing, etc.

Best Regards,

Abraxas

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Question
« Reply #14 on: February 07, 2014, 07:49:16 PM »
Hi Steven Winderlich,

you may have confused some issues raised by the OP.
alan1998:
Quote
Hi, I do malware sampling with Steven and Polonus. I found 15 undetected files all for Linux. Where do I report them and too who? I'm using Avast! for Windows. So that'd be useless.
Quote
Note: As I am not familiar with Linux malware, I don't know what an "exe" file is in comparison to windows. So the rest of the files might just be random files.
To clarify that statement, linux does not use 'exe' files.
This whole post is rather confused and misleading: Statements such as Linux Malware need to be backed up with a running Linux DE, stating found Malware, and why it is thought to be Linux Malware, which is quite an involved task. Much moreso than processing what is known Windows Malware ;)

I believe what you're seeing is Windows Malware, running in virtualbox, in or your Host Windows.

All viruses found by us running on our Linux DE's are Windows viruses, which are unable to execute, as they are based on an"exe" file, which don't run in linux.

The main purpose of running a Virus scanner like Avast!4linuxworkstations is so as not to transmit windows executable malware from a Linux system, to a friend who is using Windows. Transmission can be made via Email, or file sharing, etc.

Best Regards,

Abraxas

Re-Read what I said again. I said "I don't know what an "exe" file in comparison to Linux is.

Some file must have the properities to be luanched right? Whatis that file extension? Windows is .exe or .jar.

Hence, I don't know if it's malware. 3 of the files where detected already. It came inside a ZIP folder into my Windows PC. They were included. Like for FRST to run a fixlist. It has to be in the same location.

Also, why did you bring back an old thread when it had aslready been dealt with?
« Last Edit: February 07, 2014, 07:51:16 PM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.