Questions tagged [malware]

Malware is any software application which subverts the will of the legitimate owner of a computer, by means of force or subterfuge, with or without personal or monetary gain on the part of the creator.

"Malware" is a portmanteau of "malicious" and "software"

Common forms of malware include:

  • Botnet clients, which grant the malware author some degree of control over the compromised operating system and are generally employed in sending spam e-mail and may be rented out to perform DDoS attacks.
  • Data exfiltrators, which collect and transmit data about the computer they reside on back to the creator. These are commonly used to target login and account details for financial, social networking, and gaming websites.
  • Rogue Utility Applications, which attempt to use scare tactics in order to entice the computer's user to purchase the "full version" of the Rogue Utility.
  • Adware, which causes advertisements to appear on the user's desktop, in webpages, or elsewhere.
  • Rootkits, which attempt to conceal the presence of both the root kit and (usually) an accompanying piece of malware from another category from standard system tools and diagnostic utilities.
333 questions
3
votes
0 answers

Linux Malware Detection Monitoring: Clean files after hit

I'm using LMD ("Maldet") for scanning a web server with different projects. For this purpose I'm using the inotify-monitoring. Well, the inotify-log shows, that the modified files are noticed, but I guess the filtering fails, because bad scripts are…
MyFault
  • 913
  • 3
  • 15
  • 36
3
votes
2 answers

High number connections coming from an IP

On our corporate network we're detecting workstations opening too many connections to the IP address 75.126.196.159 (port 3478) causing the Cisco ASA Firewall 5550 to detect a "SYN Attack" and reach its limit in terms of connections, causing a…
Andre
  • 1,341
  • 4
  • 19
  • 34
3
votes
2 answers

Strange scheduled tasks on Windows Server 2003

A few days ago, I noticed that our Windows Server 2003 system has strange scheduled tasks. I do not know where they came from or who set them up. I deleted them and they came up again today. They have names such as "At1","At2", "At3" and the status…
adopilot
  • 1,521
  • 6
  • 25
  • 41
3
votes
1 answer

I have many strange requests in my httpd access_log, does it mean I have a virus?

I have httpd log information as such which goes on and on forever. Firstly, does this mean I have a virus? is my server part of a botnet? My server is Linux Centos 5. tail -f /var/log/httpd/access_log Also how can I block this attack? How can I make…
Phil
  • 265
  • 2
  • 6
  • 13
3
votes
3 answers

Scan whole system or just user dirs with clamav

I'm in doubt about how to scan my Linux system with Clamav: do I just scan the places where users can upload files (homedirs, their webroots) or do I scan the whole system? The various sites I've read vary in opinion, some say you needn't scan the…
datadevil
  • 535
  • 1
  • 7
  • 22
3
votes
1 answer

Cisco reputation filters mis-identified site as malware or "misconfigured DNS"

A client came back to me this morning saying one of their clients couldn't access the website because their security service was identifying it as a threat. I searched for the particular error, but every result on all 4 pages of Google results were…
NealJMD
  • 131
  • 1
  • 4
3
votes
3 answers

Training High School Students on Security - What harmless "viruses" can I install that they can find?

I'm training some high school students interested in OS security (specifically, Windows Server 2003/2008), and though I've gone over a lot of the "in-theory" stuff, some hands on would be great. They're interested in learning about common security…
Brandon
  • 2,817
  • 1
  • 24
  • 28
3
votes
10 answers

google result redirect virus

I'm not so sure if this is the appropriate place for this, however I accidentally clicked this link which opened a video and infected my windows 2003 std server with this virus which not only creates popup ads but also redirects whatever link I…
phill
  • 327
  • 3
  • 13
  • 20
3
votes
1 answer

Google Web History shows

Google Web History Trends is showing URLs such as the following for 4 out of 10 of my Top Clicks (including the top…
user8568
3
votes
2 answers

How do I repair dhcp service after conficker infection on Windows 2003 Server?

How do I repair dhcp service after conficker infection on Windows 2003 Server? If the server is restarted with DHCP then it keeps attempting to acquire a network address. It seems to work fine if restarted with a static IP address however.
Thomas Bratt
  • 355
  • 2
  • 6
  • 16
3
votes
5 answers

Google is blocking our requests due to "automated queries"; what's the best way to find out why?

This started a few weeks ago and we thought it was a virus so we checked every computer and all though 50%(Yeah, that's right) were infected once they were cleaned the problem didn't go away. It's really frustrating so I want to figure it out so I…
Ryan Detzel
  • 707
  • 3
  • 7
  • 21
3
votes
1 answer

How to disable scheduled task services

As I am still fighting with Conficker infection on my Win Server 2003. I will like to temporarily disable scheduled task services on server. Until I can be sure that infection of network is over.
adopilot
  • 1,521
  • 6
  • 25
  • 41
3
votes
1 answer

Large Virus File with EICAR-Test-Signature not identified by the clamav library

If I add the Eicar Test Signature at the beginning of a large text file, will that file turn out to be malicious? I opened a 5 MB binary file on Sublime Text and added the signatue at the beginning. On scanning with the clamav library, it identified…
2
votes
0 answers

Detecting .Money Ransomware on Windows Server 2019

Problem A few weeks back we got hit with a Dharma Ransomware variant called "Money". We made the incorrect assumption that this variant began right at the time the user opened the malicious attachment or link. Saturday we found out that it was…
Aaron
  • 301
  • 2
  • 12
2
votes
2 answers

How to determine process which makes DNS Request?

I have a server on AWS, GuardDuty started send me notifications: *** "type":"Backdoor:EC2/C&CActivity.B!DNS", *** {"domain":"libcurl.so","protocol":"UDP","blocked":false} *** is querying a domain name associated with a known Command & Control…
kbu
  • 255
  • 4
  • 14