Questions tagged [malware]

Malware is any software application which subverts the will of the legitimate owner of a computer, by means of force or subterfuge, with or without personal or monetary gain on the part of the creator.

"Malware" is a portmanteau of "malicious" and "software"

Common forms of malware include:

  • Botnet clients, which grant the malware author some degree of control over the compromised operating system and are generally employed in sending spam e-mail and may be rented out to perform DDoS attacks.
  • Data exfiltrators, which collect and transmit data about the computer they reside on back to the creator. These are commonly used to target login and account details for financial, social networking, and gaming websites.
  • Rogue Utility Applications, which attempt to use scare tactics in order to entice the computer's user to purchase the "full version" of the Rogue Utility.
  • Adware, which causes advertisements to appear on the user's desktop, in webpages, or elsewhere.
  • Rootkits, which attempt to conceal the presence of both the root kit and (usually) an accompanying piece of malware from another category from standard system tools and diagnostic utilities.
333 questions
0
votes
4 answers

Network Security Device/Software

We currently run Symantec Antivirus Corporate 10.2. The software is really easy to manage on a network but the actual virus detection isn't bad but the malware detection is crap. We recently were infected with a email bot that got us put on some…
Campo
  • 1,609
  • 17
  • 33
0
votes
3 answers

My website is infected with JS:ScriptIP-inf [Trj]

I am using Network Solutions hosting. I was recently attacked with JS:Illredir-S [Trj], I asked my hosting providers to clean it and they cleaned it and updated all passwords, but now after a week my site got infected again with JS:ScriptIP-inf…
Rizwan Aaqil
0
votes
1 answer

Wine and windows virus

Does installing wine pose a risk of virus infection? I'm afraid a powerful virus can bypass wine sandbox and gain access to root linux. Thank you.
jack
0
votes
1 answer

fast way to find network user computer on domain hogging all wan bandwidth

i have a network of about 40 domain users and i have huge latency wan issues, like 1400ms for google.com pings. I have noticed that the problem goes away after everyone goes home for the day. I would like to know if i should use something like a hub…
dasko
  • 1,244
  • 1
  • 22
  • 30
0
votes
3 answers

Missing NIC and USB devices

Coming into work today, I've found we have a few different computers (different companies/networks/OS versions - all windows based) that are all having the same issue. 1) Network NIC is not able to be viewed from network connections. If you…
MJ.
  • 191
  • 3
  • 12
0
votes
0 answers

Cuckoo sandbox - Failure in AnalysisManager.run

I have cuckoo running on Debian 10 with an Ubuntu guest VM. I submit a file for analysis, it runs and says "reported" but the report loads a 404 page. I see the following on the cuckoo server: Traceback (most recent call last): File…
0
votes
0 answers

Someone installed a cryptominer on my Ubuntu server

It seems someone gained access to my ubuntu server and installed a cryptominer. This user added a crontab for the user "git" on my server. I disconnected the server from the internet and I am trying to find out how this person gained access to this…
Davidoffo
  • 3
  • 1
0
votes
0 answers

How to detect what is starting malicious processes on my server?

I recently noticed an exceptionally high outbound bandwidth from my Ubuntu 22.04 server. I saw a process with a random name (something like sdfgardfh) with a high CPU usage, and suspected that it caused the bandwidth overage. I killed the process,…
0
votes
0 answers

How to resolve infection SMW-INJ-15328-cron.bkdr.perl-3 found by ImunifyAv

I have a report of a malware infection from imunifyAv and this is all I'm given: SHELL="/usr/local/cpanel/bin/jailshell" */9 * * * * perl /var/tmp/CpUOSh >/dev/null 2>&1 Reason: SMW-INJ-15328-cron.bkdr.perl-3 ChatGPT tells me I need to remove the…
mediaguru
  • 101
  • 1
0
votes
0 answers

How does pandora.x86 infect cloud servers?

We have a cloud server instance hosted at vultr. A previous instance at this provider has been infected by pandora.x86 a few weeks ago, causing 100% CPU load and over 1TB of traffic. (We believe it is this one, due to the name of the process running…
merlin
  • 2,093
  • 11
  • 39
  • 78
0
votes
0 answers

Wordpress - can't get rid of malware - can I use .htaccess to restrict?

I'm not a newbie to WordPress, but definitely a newb to getting hacked. I am trying to remove some malware from a site but it just keeps coming back. I am using wordfence to find malware and I keep getting a single file back as a malicious file…
0
votes
0 answers

How do I identify malware in ubuntu?

I got an abuse report for AWS and they shut down one of my personal servers. I can SSH in, but no other connectivity is working right now until I can prove to them I addressed it. Full transparency, I'm minimally competent in linux. AWS says my…
nosnevel
  • 1
  • 2
0
votes
2 answers

Why not nuke an machine after malware cleanup?

So this is a noob question. Why do we perform a clean up on a machine that has been infected with malware and not nuke it directly instead? I understand that in some situations this would not be possible(like large DB servers or when we don't have a…
mcry
  • 3
  • 1
0
votes
0 answers

cyberscan.io: Do something against scanning?

I receive a lot of 404 from cyberscan.io: 34.159.13.2 - - [11/Aug/2022:17:32:18 +0200] "GET /cgi/en/index.html HTTP/1.1" 404 522 "-" "cyberscan.io" 34.159.13.2 - - [11/Aug/2022:17:32:18 +0200] "GET /mail/en/index.html HTTP/1.1" 404 522 "-"…
guettli
  • 3,591
  • 17
  • 72
  • 123
0
votes
0 answers

Malware causing untraceable entries in apache2's error_log

My apache Server version: Apache/2.4.54 (Ubuntu) Server built: 2022-06-08T15:59:20 is configured as follows ErrorLog ${APACHE_LOG_DIR}/error.log ErrorLogFormat "[%t] [%l] [pid %P] %F: %E: [client %a] %M" LogLevel warn However, there are numerous…
bilogic
  • 155
  • 6