LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-12-2021, 11:20 AM   #1
//////
Member
 
Registered: Nov 2005
Location: Land of Linux :: Finland
Distribution: Arch Linux && OpenBSD 7.4 && Pop!_OS && Kali && Qubes-Os
Posts: 824

Rep: Reputation: 350Reputation: 350Reputation: 350Reputation: 350
Question about maldet.


i ran scan of my box like this :
Code:
# maldet -a /
https://www.rfxn.com/projects/linux-malware-detect/
it took a LOOONG time to finish with 3 hits.
Code:
HOST:      arch
SCAN ID:   210208-2318.1637759
STARTED:   Feb  8 2021 23:18:15 +0200
COMPLETED: Feb 11 2021 03:46:18 +0200
ELAPSED:   188883s [find: 2s]

PATH:          /
TOTAL FILES:   414111
TOTAL HITS:    3
TOTAL CLEANED: 0

FILE HIT LIST:
HOST:      arch
SCAN ID:   210208-2318.1637759
STARTED:   Feb  8 2021 23:18:15 +0200
COMPLETED: Feb 11 2021 03:46:18 +0200
ELAPSED:   188883s [find: 2s]

PATH:          /
TOTAL FILES:   414111
TOTAL HITS:    3
TOTAL CLEANED: 0

FILE HIT LIST:
{HEX}php.exe.globals.414 : /usr/share/nmap/scripts/http-vuln-cve2012-1823.nse => /usr/local/maldetect/quarantine/http-vuln-cve2012-1823.nse.1356922472
{HEX}php.gzbase64.inject.452 : /usr/local/src/maldetect-1.6.4/files/clean/gzbase64.inject.unclassed => /usr/local/maldetect/quarantine/gzbase64.inject.unclassed.2182211307
{HEX}php.cmdshell.antichat.201 : /usr/local/src/maldetect-1.6.4/files/sigs/rfxn.yara => /usr/local/maldetect/quarantine/rfxn.yara.782222470
is that run time normal?
i know that those hits are false positives.

Last edited by //////; 02-13-2021 at 04:06 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
No command line access after running maldet OtagoHarbour Ubuntu 15 08-19-2019 01:43 AM
LXer: How to Detect and Clean Malware from a Linux Server with Maldet LXer Syndicated Linux News 0 08-23-2017 06:43 AM
[SOLVED] Maldet flags EmergingThreat Rules as Malware Hits OtagoHarbour Linux - Security 4 10-25-2014 08:09 AM
maldet and possible false positives? Zeno McDohl Linux - Security 1 07-28-2013 05:17 PM
Lilo/kernel question & font question phek Linux - General 9 09-18-2001 12:20 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:16 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration