Recent malware Affecting Ubuntu and Firefox
Hi; I'm not very good with forums and so those who read my comments here will have to forgive my ineptitude with html, etc.
In the past two weeks my Ubuntu machine, running Ubuntu v18.04.2 has been hit with multiple examples of malware that is being lodged in Firefox and appears to be write-protected so that Bleachbit cannot delete it.
I will list below some of the objects removed this past week by ClamTK:
Win.Trojan.Xored-1 (8-7)
Js.Coinminer.Generic-7104549-0 (8-8)
Win.Exploit.CVE_2012_1461-1 (8-6)
Win.Exploit.CVE_2012_1461-1 (8-4)
Win.Exploit.CVE_2012_1461-1 (8-2)
uBlock@raymondhill.net.xpi -- Js.Coinminer.Generic-7-10459-0 8-8-19
Win.Exploit.CVE_2012_1461-1 -- 8-9-19
uBlock@raymondhill.net.xpi -- Js.Coinminer.Generic-7104549-0 -- 2 examples 8-9-19
Firefox/ok1tk16v.default/cache2/doomed/1964705863 -- Win.Exploit.CVE_2012_1461-1
Some of the malware objects being removed by Clam were received DIRECTLY from the Raymond Hill ad blocker upon installation. Following scans using ClamTK the Raymond Hill object was deleted, which also deletes the ad blocker. Vicious circle. I've been forced to stop using the latter because of this. My second choice in ad blockers remains AdBlock Plus, which is now running in my Firefox.
Linux is no longer impervious to attacks, which thing is made clear by the foregoing.
My advice is to use caution browsing and run frequent scans with an antivirus/anti-malware program.
So far the only antivirus I've ever used has been the Cisco Systems' ClamAV.
I hope this helps.
Comments
-
Greetings everyone!
There is some good news to report. After installing the rootkit remover, chkrootkit and running scans in Terminal i was able to identify a number of malware 'sniffers' living in the usr/lib and other associated folders, and restore my machine!
I'd suspected that something was cohabiting in my laptop with me that you wouldn't want to introduce to Mama, and i'm very pleased that my old install of Ubuntu is now back up to par (although i'm definitely knocking on wood).
Ubuntu is generally worry free where it comes to unwanted gifts of the malware kind, but one can easily encounter such gremlins via downloads.
The best policy is to avoid ALL downloads that can't be accessed through the devs and easily installed via Terminal by entering sudo apt-get install (software name), or by running Synaptic Package Manager, one of the most useful tools the Ubuntu user can install.
ClamTK is apparently unable to detect sniffers so if you suspect your machine may have a hitch-hiker you are advised to run chkrootkit, which can be installed via terminal.
All the removal work you do once the latter discovers something must be performed manually, and this can be accomplished by:
1) Disconnecting from WAN (Pull the cat5 en cable or disconnect the fone wire on DSL systems; if using WiFi turn it OFF and in cable systems unscrew the WAN connector from the modem)
2) R-click in desktop field and select Terminal from the drop-down menu
3) 'Come big' by acting as ROOT: type sudo -i, enter (or you'll be denied access)
4) Type nautilus, enter
5) When you do the above a 640x480-ish copy of your Files program (the actual name of Files is Nautilus, as you see in the glyph of a file cabinet on Desktop) will appear. Use this to navigate sequentially to every 'suspect' file Chkrootkit lists in its summary and delete the final item in each line from the summary, leaving predecessor files in the tree intact
6) You should have a backup of Ubuntu to fall back on, and one can usually be made by slipping a postage-stamp SIM card into your machine's slot and using Terminal for the backup, by typing sudo deja-dup --backup and allowing the process to run.
If deja-dup isn't installed you can easily set it active by clicking the tic-tak-toe icon on your Desktop labeled, 'Show Applications,' then navigating to (what is usually the third page) Utilities/Backups and clicking Backups.
It's all self-explanatory from there.
7) Once all the sniffers and malware files are removed type: sudo reboot and enter.
Start pressing the Shift key as the system begins coming back up and when the Grub screen appears (in pink, no less) press the down arrow and select the dialog, *Advanced options for Ubuntu; enter, and upon redirect to a second Grub page use your arrows array to drop down one line and select Recovery mode for the kernel of your choice.
Allow the process to run; you will be required to enter your sda5_crypt password to continue, and when the process stops use your arrows again to scroll down to the line, 'Drop to root shell prompt,' press enter and then press enter again at the prompt; type sudo reboot and your machine will reboot, which is a good idea because it allows you to avoid level5 graphics issues following the second login.
I sincerely hope this verbose summary helps newbies and others struggling to master the many Linux processes.0 -
I have some malware here in new haven ct, that the police have deployed against me to like violate my civil rihts so that they can abuse me on behalf of a megaslumlord, it disables the rootkithunter and network manageter and terminal on boot in linux 6.8 it probably affects android to it locks the root on fedora 38, debian 11, and kali, im using a rpi4 with 8 gigs, i have a sampleof this i can compress and submit email me babianivan2@gmail.com and ill put it up in a downloadable googlelink compressed for analysis... im dd dev zeroing all my drives but i have a sandbox set up if anyone wants to look at this and break this police exploit so they can never use it again
0
Categories
- All Categories
- 167 LFX Mentorship
- 219 LFX Mentorship: Linux Kernel
- 801 Linux Foundation IT Professional Programs
- 358 Cloud Engineer IT Professional Program
- 180 Advanced Cloud Engineer IT Professional Program
- 83 DevOps Engineer IT Professional Program
- 149 Cloud Native Developer IT Professional Program
- 112 Express Training Courses
- 138 Express Courses - Discussion Forum
- 6.2K Training Courses
- 48 LFC110 Class Forum - Discontinued
- 17 LFC131 Class Forum
- 42 LFD102 Class Forum
- 227 LFD103 Class Forum
- 19 LFD110 Class Forum
- 39 LFD121 Class Forum
- 15 LFD133 Class Forum
- 7 LFD134 Class Forum
- 17 LFD137 Class Forum
- 63 LFD201 Class Forum
- 3 LFD210 Class Forum
- 5 LFD210-CN Class Forum
- 2 LFD213 Class Forum - Discontinued
- 128 LFD232 Class Forum - Discontinued
- 1 LFD233 Class Forum
- 2 LFD237 Class Forum
- 23 LFD254 Class Forum
- 697 LFD259 Class Forum
- 109 LFD272 Class Forum
- 3 LFD272-JP クラス フォーラム
- 10 LFD273 Class Forum
- 154 LFS101 Class Forum
- 1 LFS111 Class Forum
- 1 LFS112 Class Forum
- 1 LFS116 Class Forum
- 1 LFS118 Class Forum
- LFS120 Class Forum
- 7 LFS142 Class Forum
- 7 LFS144 Class Forum
- 3 LFS145 Class Forum
- 1 LFS146 Class Forum
- 3 LFS147 Class Forum
- 1 LFS148 Class Forum
- 15 LFS151 Class Forum
- 1 LFS157 Class Forum
- 34 LFS158 Class Forum
- 8 LFS162 Class Forum
- 1 LFS166 Class Forum
- 1 LFS167 Class Forum
- 3 LFS170 Class Forum
- 2 LFS171 Class Forum
- 1 LFS178 Class Forum
- 1 LFS180 Class Forum
- 1 LFS182 Class Forum
- 1 LFS183 Class Forum
- 29 LFS200 Class Forum
- 736 LFS201 Class Forum - Discontinued
- 2 LFS201-JP クラス フォーラム
- 14 LFS203 Class Forum
- 135 LFS207 Class Forum
- 1 LFS207-DE-Klassenforum
- 1 LFS207-JP クラス フォーラム
- 301 LFS211 Class Forum
- 55 LFS216 Class Forum
- 48 LFS241 Class Forum
- 48 LFS242 Class Forum
- 37 LFS243 Class Forum
- 15 LFS244 Class Forum
- LFS245 Class Forum
- LFS246 Class Forum
- 50 LFS250 Class Forum
- 1 LFS250-JP クラス フォーラム
- LFS251 Class Forum
- 155 LFS253 Class Forum
- LFS254 Class Forum
- LFS255 Class Forum
- 5 LFS256 Class Forum
- 1 LFS257 Class Forum
- 1.3K LFS258 Class Forum
- 10 LFS258-JP クラス フォーラム
- 122 LFS260 Class Forum
- 159 LFS261 Class Forum
- 42 LFS262 Class Forum
- 82 LFS263 Class Forum - Discontinued
- 15 LFS264 Class Forum - Discontinued
- 11 LFS266 Class Forum - Discontinued
- 20 LFS267 Class Forum
- 25 LFS268 Class Forum
- 31 LFS269 Class Forum
- 3 LFS270 Class Forum
- 199 LFS272 Class Forum
- 1 LFS272-JP クラス フォーラム
- LFS274 Class Forum
- 3 LFS281 Class Forum
- 10 LFW111 Class Forum
- 261 LFW211 Class Forum
- 182 LFW212 Class Forum
- 15 SKF100 Class Forum
- 1 SKF200 Class Forum
- 1 SKF201 Class Forum
- 782 Hardware
- 198 Drivers
- 68 I/O Devices
- 37 Monitors
- 96 Multimedia
- 174 Networking
- 91 Printers & Scanners
- 83 Storage
- 758 Linux Distributions
- 80 Debian
- 67 Fedora
- 15 Linux Mint
- 13 Mageia
- 23 openSUSE
- 143 Red Hat Enterprise
- 31 Slackware
- 13 SUSE Enterprise
- 348 Ubuntu
- 461 Linux System Administration
- 39 Cloud Computing
- 70 Command Line/Scripting
- Github systems admin projects
- 90 Linux Security
- 77 Network Management
- 101 System Management
- 46 Web Management
- 64 Mobile Computing
- 17 Android
- 34 Development
- 1.2K New to Linux
- 1K Getting Started with Linux
- 371 Off Topic
- 114 Introductions
- 174 Small Talk
- 19 Study Material
- 806 Programming and Development
- 304 Kernel Development
- 204 Software Development
- 1.8K Software
- 263 Applications
- 180 Command Line
- 3 Compiling/Installing
- 405 Games
- 309 Installation
- 97 All In Program
- 97 All In Forum
Upcoming Training
-
August 20, 2018
Kubernetes Administration (LFS458)
-
August 20, 2018
Linux System Administration (LFS301)
-
August 27, 2018
Open Source Virtualization (LFS462)
-
August 27, 2018
Linux Kernel Debugging and Security (LFD440)