RKHUNTER encontrou uns arquivos suspeitos [RESOLVIDO]

1. RKHUNTER encontrou uns arquivos suspeitos [RESOLVIDO]

Henrique
Henrique-RJ

(usa Outra)

Enviado em 25/10/2024 - 12:27h

Rodei esse programa que encontrou os arquivos abaixo e que pesquisando na internet não os encontrei:

[13:10:24] Warning: Suspicious file types found in /dev:
[13:10:24] /dev/shm/sem.WS_N7DA0CBA2: data
[13:10:24] /dev/shm/wiservice: very short file (no magic)
[13:10:24] /dev/shm/wimtxWS_N16F4F95B: data
[13:10:24] /dev/shm/wimtxWS_N1D1A924E: data
[13:10:25] Checking for hidden files and directories [ Warning ]
[13:10:25] Warning: Hidden directory found: /etc/.java


Alguém que tenha feito escaneamento com ele achou esses mesmos arquivos na pasta /dev/shm/ ?

Estou usando a distro derivada do Ubuntu chamada Bodhi Linux na versão de 5 anos atrás.

[quote][13:08:01] Running Rootkit Hunter version 1.4.6 on Henrique-Bodhi-5
[13:08:01]
[13:08:01] Info: Start date is qui out 24 13:08:01 -03 2024
[13:08:01]
[13:08:01] Checking configuration file and command-line options...
[13:08:01] Info: Detected operating system is 'Linux'
[13:08:01] Info: Found O/S name: Ubuntu 18.04.6 LTS
[13:08:01] Info: Command line is /usr/bin/rkhunter -c
[13:08:01] Info: Environment shell is /bin/bash; rkhunter is using dash
[13:08:01] Info: Using configuration file '/etc/rkhunter.conf'
[13:08:01] Info: Installation directory is '/usr'
[13:08:01] Info: Using language 'en'
[13:08:01] Info: Using '/var/lib/rkhunter/db' as the database directory
[13:08:01] Info: Using '/usr/share/rkhunter/scripts' as the support script directory
[13:08:01] Info: Using '/usr/local/sbin /usr/local/bin /usr/sbin /usr/bin /sbin /bin' as the command directories
[13:08:01] Info: Using '/var/lib/rkhunter/tmp' as the temporary directory
[13:08:01] Info: No mail-on-warning address configured
[13:08:01] Info: X will be automatically detected
[13:08:01] Info: Using second color set
[13:08:01] Info: Found the 'basename' command: /usr/bin/basename
[13:08:01] Info: Found the 'diff' command: /usr/bin/diff
[13:08:01] Info: Found the 'dirname' command: /usr/bin/dirname
[13:08:01] Info: Found the 'file' command: /usr/bin/file
[13:08:01] Info: Found the 'find' command: /usr/bin/find
[13:08:01] Info: Found the 'ifconfig' command: /sbin/ifconfig
[13:08:01] Info: Found the 'ip' command: /sbin/ip
[13:08:01] Info: Found the 'ipcs' command: /usr/bin/ipcs
[13:08:01] Info: Found the 'ldd' command: /usr/bin/ldd
[13:08:01] Info: Found the 'lsattr' command: /usr/bin/lsattr
[13:08:01] Info: Found the 'lsmod' command: /sbin/lsmod
[13:08:01] Info: Found the 'lsof' command: /usr/bin/lsof
[13:08:01] Info: Found the 'mktemp' command: /bin/mktemp
[13:08:01] Info: Found the 'netstat' command: /bin/netstat
[13:08:01] Info: Found the 'numfmt' command: /usr/bin/numfmt
[13:08:01] Info: Found the 'perl' command: /usr/bin/perl
[13:08:01] Info: Found the 'pgrep' command: /usr/bin/pgrep
[13:08:02] Info: Found the 'ps' command: /bin/ps
[13:08:02] Info: Found the 'pwd' command: /bin/pwd
[13:08:02] Info: Found the 'readlink' command: /bin/readlink
[13:08:02] Info: Found the 'stat' command: /usr/bin/stat
[13:08:02] Info: Found the 'strings' command: /usr/bin/strings
[13:08:02] Info: System is using prelinking
[13:08:02] Info: Found the 'prelink' command: /usr/sbin/prelink
[13:08:02] Info: Unable to find the 'sestatus' command
[13:08:02] Info: Using the prelink command (with SHA1) for the file hash checks
[13:08:02] Info: Stored hash values used hash function 'SHA1'
[13:08:02] Info: Stored hash values did not use a package manager
[13:08:02] Info: The hash function field index is set to 1
[13:08:02] Info: No package manager specified: using prelink command with 'SHA1'
[13:08:02] Info: Previous file attributes were stored
[13:08:02] Info: Enabled tests are: all
[13:08:02] Info: Disabled tests are: suspscan hidden_ports hidden_procs deleted_files packet_cap_apps apps
[13:08:02] Info: Found kernel symbols file '/proc/kallsyms'
[13:08:02] Info: Using syslog for some logging - facility/priority level is 'authpriv.warning'.
[13:08:02] Info: Found the 'logger' command: /usr/bin/logger
[13:08:02] Info: Using 'date' to process epoch second times
[13:08:02]
[13:08:02] Checking if the O/S has changed since last time...
[13:08:02] Info: Nothing seems to have changed.
[13:08:02] Info: Locking is not being used
[13:08:02]
[13:08:02] Starting system checks...
[13:08:02]
[13:08:02] Info: Starting test name 'system_commands'
[13:08:02] Checking system commands...
[13:08:02]
[13:08:02] Info: Starting test name 'strings'
[13:08:02] Performing 'strings' command checks
[13:08:02] Scanning for string /usr/sbin/ntpsx [ OK ]
[13:08:02] Scanning for string /usr/sbin/.../bkit-ava [ OK ]
[13:08:02] Scanning for string /usr/sbin/.../bkit-d [ OK ]
[13:08:02] Scanning for string /usr/sbin/.../bkit-shd [ OK ]
[13:08:02] Scanning for string /usr/sbin/.../bkit-f [ OK ]
[13:08:02] Scanning for string /usr/include/.../proc.h [ OK ]
[13:08:02] Scanning for string /usr/include/.../.bash_history [ OK ]
[13:08:02] Scanning for string /usr/include/.../bkit-get [ OK ]
[13:08:02] Scanning for string /usr/include/.../bkit-dl [ OK ]
[13:08:02] Scanning for string /usr/include/.../bkit-screen [ OK ]
[13:08:02] Scanning for string /usr/include/.../bkit-sleep [ OK ]
[13:08:02] Scanning for string /usr/lib/.../bkit-adore.o [ OK ]
[13:08:02] Scanning for string /usr/lib/.../ls [ OK ]
[13:08:02] Scanning for string /usr/lib/.../netstat [ OK ]
[13:08:02] Scanning for string /usr/lib/.../lsof [ OK ]
[13:08:02] Scanning for string /usr/lib/.../bkit-ssh/bkit-shdcfg [ OK ]
[13:08:02] Scanning for string /usr/lib/.../bkit-ssh/bkit-shhk [ OK ]
[13:08:02] Scanning for string /usr/lib/.../bkit-ssh/bkit-pw [ OK ]
[13:08:02] Scanning for string /usr/lib/.../bkit-ssh/bkit-shrs [ OK ]
[13:08:02] Scanning for string /usr/lib/.../bkit-ssh/bkit-mots [ OK ]
[13:08:03] Scanning for string /usr/lib/.../uconf.inv [ OK ]
[13:08:03] Scanning for string /usr/lib/.../psr [ OK ]
[13:08:03] Scanning for string /usr/lib/.../find [ OK ]
[13:08:03] Scanning for string /usr/lib/.../pstree [ OK ]
[13:08:03] Scanning for string /usr/lib/.../slocate [ OK ]
[13:08:03] Scanning for string /usr/lib/.../du [ OK ]
[13:08:03] Scanning for string /usr/lib/.../top [ OK ]
[13:08:03] Scanning for string /usr/sbin/... [ OK ]
[13:08:03] Scanning for string /usr/include/... [ OK ]
[13:08:03] Scanning for string /usr/include/.../.tmp [ OK ]
[13:08:03] Scanning for string /usr/lib/... [ OK ]
[13:08:03] Scanning for string /usr/lib/.../.ssh [ OK ]
[13:08:03] Scanning for string /usr/lib/.../bkit-ssh [ OK ]
[13:08:03] Scanning for string /usr/lib/.bkit- [ OK ]
[13:08:03] Scanning for string /tmp/.bkp [ OK ]
[13:08:03] Scanning for string /tmp/.cinik [ OK ]
[13:08:03] Scanning for string /tmp/.font-unix/.cinik [ OK ]
[13:08:03] Scanning for string /lib/.sso [ OK ]
[13:08:03] Scanning for string /lib/.so [ OK ]
[13:08:03] Scanning for string /var/run/...dica/clean [ OK ]
[13:08:03] Scanning for string /var/run/...dica/dxr [ OK ]
[13:08:03] Scanning for string /var/run/...dica/read [ OK ]
[13:08:03] Scanning for string /var/run/...dica/write [ OK ]
[13:08:03] Scanning for string /var/run/...dica/lf [ OK ]
[13:08:03] Scanning for string /var/run/...dica/xl [ OK ]
[13:08:03] Scanning for string /var/run/...dica/xdr [ OK ]
[13:08:03] Scanning for string /var/run/...dica/psg [ OK ]
[13:08:03] Scanning for string /var/run/...dica/secure [ OK ]
[13:08:03] Scanning for string /var/run/...dica/rdx [ OK ]
[13:08:03] Scanning for string /var/run/...dica/va [ OK ]
[13:08:03] Scanning for string /var/run/...dica/cl.sh [ OK ]
[13:08:03] Scanning for string /var/run/...dica/last.log [ OK ]
[13:08:03] Scanning for string /usr/bin/.etc [ OK ]
[13:08:03] Scanning for string /etc/sshd_config [ OK ]
[13:08:03] Scanning for string /etc/ssh_host_key [ OK ]
[13:08:03] Scanning for string /etc/ssh_random_seed [ OK ]
[13:08:03] Scanning for string /dev/ptyp [ OK ]
[13:08:03] Scanning for string /dev/ptyq [ OK ]
[13:08:03] Scanning for string /dev/ptyr [ OK ]
[13:08:03] Scanning for string /dev/ptys [ OK ]
[13:08:03] Scanning for string /dev/ptyt [ OK ]
[13:08:04] Scanning for string /dev/fd/.88/freshb-bsd [ OK ]
[13:08:04] Scanning for string /dev/fd/.88/fresht [ OK ]
[13:08:04] Scanning for string /dev/fd/.88/zxsniff [ OK ]
[13:08:04] Scanning for string /dev/fd/.88/zxsniff.log [ OK ]
[13:08:04] Scanning for string /dev/fd/.99/.ttyf00 [ OK ]
[13:08:04] Scanning for string /dev/fd/.99/.ttyp00 [ OK ]
[13:08:04] Scanning for string /dev/fd/.99/.ttyq00 [ OK ]
[13:08:04] Scanning for string /dev/fd/.99/.ttys00 [ OK ]
[13:08:04] Scanning for string /dev/fd/.99/.pwsx00 [ OK ]
[13:08:04] Scanning for string /etc/.acid [ OK ]
[13:08:04] Scanning for string /usr/lib/.fx/sched_host.2 [ OK ]
[13:08:04] Scanning for string /usr/lib/.fx/random_d.2 [ OK ]
[13:08:04] Scanning for string /usr/lib/.fx/set_pid.2 [ OK ]
[13:08:04] Scanning for string /usr/lib/.fx/setrgrp.2 [ OK ]
[13:08:04] Scanning for string /usr/lib/.fx/TOHIDE [ OK ]
[13:08:04] Scanning for string /usr/lib/.fx/cons.saver [ OK ]
[13:08:04] Scanning for string /usr/lib/.fx/adore/ava/ava [ OK ]
[13:08:04] Scanning for string /usr/lib/.fx/adore/adore/adore.ko [ OK ]
[13:08:04] Scanning for string /bin/sysback [ OK ]
[13:08:04] Scanning for string /usr/local/bin/sysback [ OK ]
[13:08:04] Scanning for string /usr/lib/.tbd [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/t0rns [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/du [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/ls [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/t0rnsb [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/ps [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/t0rnp [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/find [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/ifconfig [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/pg [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/ssh.tgz [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/top [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/sz [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/login [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/in.fingerd [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/1i0n.sh [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/pstree [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/in.telnetd [ OK ]
[13:08:04] Scanning for string /dev/.lib/lib/lib/mjy [ OK ]
[13:08:05] Scanning for string /dev/.lib/lib/lib/sush [ OK ]
[13:08:05] Scanning for string /dev/.lib/lib/lib/tfn [ OK ]
[13:08:05] Scanning for string /dev/.lib/lib/lib/name [ OK ]
[13:08:05] Scanning for string /dev/.lib/lib/lib/getip.sh [ OK ]
[13:08:05] Scanning for string /usr/info/.torn/sh* [ OK ]
[13:08:05] Scanning for string /usr/src/.[*****]/.1addr [ OK ]
[13:08:05] Scanning for string /usr/src/.[*****]/.1file [ OK ]
[13:08:05] Scanning for string /usr/src/.[*****]/.1proc [ OK ]
[13:08:05] Scanning for string /usr/src/.[*****]/.1logz [ OK ]
[13:08:05] Scanning for string /usr/info/.t0rn [ OK ]
[13:08:05] Scanning for string /dev/.lib [ OK ]
[13:08:05] Scanning for string /dev/.lib/lib [ OK ]
[13:08:05] Scanning for string /dev/.lib/lib/lib [ OK ]
[13:08:05] Scanning for string /dev/.lib/lib/lib/dev [ OK ]
[13:08:05] Scanning for string /dev/.lib/lib/scan [ OK ]
[13:08:05] Scanning for string /usr/src/.[*****] [ OK ]
[13:08:05] Scanning for string /usr/man/man1/man1 [ OK ]
[13:08:05] Scanning for string /usr/man/man1/man1/lib [ OK ]
[13:08:05] Scanning for string /usr/man/man1/man1/lib/.lib [ OK ]
[13:08:05] Scanning for string /usr/man/man1/man1/lib/.lib/.backup [ OK ]
[13:08:05]
[13:08:05] Info: Starting test name 'shared_libs'
[13:08:05] Performing 'shared libraries' checks
[13:08:05] Checking for preloading variables [ None found ]
[13:08:05] Checking for preloaded libraries [ None found ]
[13:08:05]
[13:08:05] Info: Starting test name 'shared_libs_path'
[13:08:05] Checking LD_LIBRARY_PATH variable [ Not found ]
[13:08:05]
[13:08:05] Info: Starting test name 'properties'
[13:08:05] Performing file properties checks
[13:08:05] Checking for prerequisites [ OK ]
[13:08:10] /usr/sbin/adduser [ OK ]
[13:08:10] Info: Found file '/usr/sbin/adduser': it is whitelisted for the 'script replacement' check.
[13:08:10] /usr/sbin/chroot [ OK ]
[13:08:10] /usr/sbin/cron [ OK ]
[13:08:11] /usr/sbin/groupadd [ OK ]
[13:08:11] /usr/sbin/groupdel [ OK ]
[13:08:11] /usr/sbin/groupmod [ OK ]
[13:08:11] /usr/sbin/grpck [ OK ]
[13:08:11] /usr/sbin/nologin [ OK ]
[13:08:12] /usr/sbin/prelink [ Warning ]
[13:08:12] Warning: The command '/usr/sbin/prelink' has been replaced by a script: /usr/sbin/prelink: Bourne-Again shell script, ASCII text executable
[13:08:12] /usr/sbin/pwck [ OK ]
[13:08:12] /usr/sbin/rsyslogd [ OK ]
[13:08:13] /usr/sbin/useradd [ OK ]
[13:08:13] /usr/sbin/userdel [ OK ]
[13:08:13] /usr/sbin/usermod [ OK ]
[13:08:13] /usr/sbin/vipw [ OK ]
[13:08:13] /usr/sbin/unhide [ OK ]
[13:08:13] /usr/sbin/unhide-linux [ OK ]
[13:08:13] /usr/sbin/unhide-posix [ OK ]
[13:08:14] /usr/sbin/unhide-tcp [ OK ]
[13:08:14] /usr/bin/awk [ OK ]
[13:08:14] /usr/bin/basename [ OK ]
[13:08:14] /usr/bin/chattr [ OK ]
[13:08:14] /usr/bin/curl [ OK ]
[13:08:14] /usr/bin/cut [ OK ]
[13:08:15] /usr/bin/diff [ OK ]
[13:08:15] /usr/bin/dirname [ OK ]
[13:08:15] /usr/bin/dpkg [ OK ]
[13:08:15] /usr/bin/dpkg-query [ OK ]
[13:08:15] /usr/bin/du [ OK ]
[13:08:15] /usr/bin/env [ OK ]
[13:08:15] /usr/bin/file [ OK ]
[13:08:16] /usr/bin/find [ OK ]
[13:08:16] /usr/bin/GET [ OK ]
[13:08:16] /usr/bin/groups [ OK ]
[13:08:16] /usr/bin/head [ OK ]
[13:08:16] /usr/bin/id [ OK ]
[13:08:16] /usr/bin/ipcs [ OK ]
[13:08:16] /usr/bin/killall [ OK ]
[13:08:17] /usr/bin/last [ OK ]
[13:08:17] /usr/bin/lastlog [ OK ]
[13:08:17] /usr/bin/ldd [ OK ]
[13:08:17] Info: Found file '/usr/bin/ldd': it is whitelisted for the 'script replacement' check.
[13:08:17] /usr/bin/less [ OK ]
[13:08:17] /usr/bin/locate [ OK ]
[13:08:17] /usr/bin/logger [ OK ]
[13:08:17] /usr/bin/lsattr [ OK ]
[13:08:17] /usr/bin/lsof [ OK ]
[13:08:18] /usr/bin/mail [ OK ]
[13:08:18] /usr/bin/md5sum [ OK ]
[13:08:18] /usr/bin/mlocate [ OK ]
[13:08:18] /usr/bin/newgrp [ OK ]
[13:08:18] /usr/bin/passwd [ OK ]
[13:08:18] /usr/bin/perl [ OK ]
[13:08:18] /usr/bin/pgrep [ OK ]
[13:08:19] /usr/bin/pkill [ OK ]
[13:08:19] /usr/bin/pstree [ OK ]
[13:08:19] /usr/bin/rkhunter [ OK ]
[13:08:19] /usr/bin/runcon [ OK ]
[13:08:19] /usr/bin/sha1sum [ OK ]
[13:08:19] /usr/bin/sha224sum [ OK ]
[13:08:19] /usr/bin/sha256sum [ OK ]
[13:08:20] /usr/bin/sha384sum [ OK ]
[13:08:20] /usr/bin/sha512sum [ OK ]
[13:08:20] /usr/bin/size [ OK ]
[13:08:20] /usr/bin/sort [ OK ]
[13:08:20] /usr/bin/ssh [ OK ]
[13:08:20] /usr/bin/stat [ OK ]
[13:08:20] /usr/bin/strace [ OK ]
[13:08:20] /usr/bin/strings [ OK ]
[13:08:21] /usr/bin/sudo [ OK ]
[13:08:21] /usr/bin/tail [ OK ]
[13:08:21] /usr/bin/telnet [ OK ]
[13:08:21] /usr/bin/test [ OK ]
[13:08:21] /usr/bin/top [ OK ]
[13:08:21] /usr/bin/touch [ OK ]
[13:08:21] /usr/bin/tr [ OK ]
[13:08:21] /usr/bin/uniq [ OK ]
[13:08:22] /usr/bin/users [ OK ]
[13:08:22] /usr/bin/vmstat [ OK ]
[13:08:22] /usr/bin/w [ OK ]
[13:08:22] /usr/bin/watch [ OK ]
[13:08:22] /usr/bin/wc [ OK ]
[13:08:22] /usr/bin/wget [ OK ]
[13:08:22] /usr/bin/whatis [ OK ]
[13:08:22] /usr/bin/whereis [ OK ]
[13:08:22] /usr/bin/which [ OK ]
[13:08:23] /usr/bin/who [ OK ]
[13:08:23] /usr/bin/whoami [ OK ]
[13:08:23] /usr/bin/numfmt [ OK ]
[13:08:23] /usr/bin/gawk [ OK ]
[13:08:23] /usr/bin/lwp-request [ Warning ]
[13:08:23] Warning: The command '/usr/bin/lwp-request' has been replaced by a script: /usr/bin/lwp-request: Perl script text executable
[13:08:23] /usr/bin/mail.mailutils [ OK ]
[13:08:23] /usr/bin/x86_64-linux-gnu-size [ OK ]
[13:08:23] /usr/bin/x86_64-linux-gnu-strings [ OK ]
[13:08:24] /usr/bin/telnet.netkit [ OK ]
[13:08:24] /usr/bin/w.procps [ OK ]
[13:08:24] /sbin/depmod [ OK ]
[13:08:24] /sbin/fsck [ OK ]
[13:08:25] /sbin/ifconfig [ OK ]
[13:08:25] /sbin/init [ OK ]
[13:08:25] /sbin/insmod [ OK ]
[13:08:25] /sbin/ip [ OK ]
[13:08:25] /sbin/lsmod [ OK ]
[13:08:25] /sbin/modinfo [ OK ]
[13:08:26] /sbin/modprobe [ OK ]
[13:08:26] /sbin/rmmod [ OK ]
[13:08:26] /sbin/route [ OK ]
[13:08:26] /sbin/runlevel [ OK ]
[13:08:27] /sbin/sulogin [ OK ]
[13:08:27] /sbin/sysctl [ OK ]
[13:08:27] /bin/bash [ OK ]
[13:08:27] /bin/cat [ OK ]
[13:08:28] /bin/chmod [ OK ]
[13:08:28] /bin/chown [ OK ]
[13:08:28] /bin/cp [ OK ]
[13:08:28] /bin/date [ OK ]
[13:08:28] /bin/df [ OK ]
[13:08:28] /bin/dmesg [ OK ]
[13:08:28] /bin/echo [ OK ]
[13:08:28] /bin/ed [ OK ]
[13:08:29] /bin/egrep [ OK ]
[13:08:29] Info: Found file '/bin/egrep': it is whitelisted for the 'script replacement' check.
[13:08:29] /bin/fgrep [ OK ]
[13:08:29] Info: Found file '/bin/fgrep': it is whitelisted for the 'script replacement' check.
[13:08:29] /bin/fuser [ OK ]
[13:08:29] /bin/grep [ OK ]
[13:08:29] /bin/ip [ OK ]
[13:08:29] /bin/kill [ OK ]
[13:08:30] /bin/less [ OK ]
[13:08:30] /bin/login [ OK ]
[13:08:30] /bin/ls [ OK ]
[13:08:30] /bin/lsmod [ OK ]
[13:08:30] /bin/mktemp [ OK ]
[13:08:30] /bin/more [ OK ]
[13:08:31] /bin/mount [ OK ]
[13:08:31] /bin/mv [ OK ]
[13:08:31] /bin/netstat [ OK ]
[13:08:31] /bin/ping [ OK ]
[13:08:31] /bin/ps [ OK ]
[13:08:31] /bin/pwd [ OK ]
[13:08:31] /bin/readlink [ OK ]
[13:08:32] /bin/sed [ OK ]
[13:08:32] /bin/sh [ OK ]
[13:08:32] /bin/su [ OK ]
[13:08:32] /bin/touch [ OK ]
[13:08:32] /bin/uname [ OK ]
[13:08:33] /bin/which [ OK ]
[13:08:33] Info: Found file '/bin/which': it is whitelisted for the 'script replacement' check.
[13:08:33] /bin/kmod [ OK ]
[13:08:33] /bin/systemd [ OK ]
[13:08:33] /bin/systemctl [ OK ]
[13:08:33] /bin/dash [ OK ]
[13:08:35] /lib/systemd/systemd [ OK ]
[13:08:41]
[13:08:41] Info: Starting test name 'rootkits'
[13:08:41] Checking for rootkits...
[13:08:41]
[13:08:41] Info: Starting test name 'known_rkts'
[13:08:41] Performing check of known rootkit files and directories
[13:08:41]
[13:08:41] Checking for 55808 Trojan - Variant A...
[13:08:41] Checking for file '/tmp/.../r' [ Not found ]
[13:08:41] Checking for file '/tmp/.../a' [ Not found ]
[13:08:41] 55808 Trojan - Variant A [ Not found ]
[13:08:41]
[13:08:41] Checking for ADM Worm...
[13:08:41] Checking for string 'w0rm' [ Not found ]
[13:08:41] ADM Worm [ Not found ]
[13:08:41]
[13:08:41] Checking for AjaKit Rootkit...
[13:08:41] Checking for file '/dev/tux/.addr' [ Not found ]
[13:08:41] Checking for file '/dev/tux/.proc' [ Not found ]
[13:08:41] Checking for file '/dev/tux/.file' [ Not found ]
[13:08:41] Checking for file '/lib/.libgh-gh/cleaner' [ Not found ]
[13:08:41] Checking for file '/lib/.libgh-gh/Patch/patch' [ Not found ]
[13:08:41] Checking for file '/lib/.libgh-gh/sb0k' [ Not found ]
[13:08:41] Checking for directory '/dev/tux' [ Not found ]
[13:08:41] Checking for directory '/lib/.libgh-gh' [ Not found ]
[13:08:41] AjaKit Rootkit [ Not found ]
[13:08:41]
[13:08:41] Checking for Adore Rootkit...
[13:08:41] Checking for file '/usr/secure' [ Not found ]
[13:08:41] Checking for file '/usr/doc/sys/qrt' [ Not found ]
[13:08:41] Checking for file '/usr/doc/sys/run' [ Not found ]
[13:08:41] Checking for file '/usr/doc/sys/crond' [ Not found ]
[13:08:41] Checking for file '/usr/sbin/kfd' [ Not found ]
[13:08:41] Checking for file '/usr/doc/kern/var' [ Not found ]
[13:08:41] Checking for file '/usr/doc/kern/string.o' [ Not found ]
[13:08:41] Checking for file '/usr/doc/kern/ava' [ Not found ]
[13:08:41] Checking for file '/usr/doc/kern/adore.o' [ Not found ]
[13:08:41] Checking for file '/var/log/ssh/old' [ Not found ]
[13:08:41] Checking for directory '/lib/security/.config/ssh' [ Not found ]
[13:08:42] Checking for directory '/usr/doc/kern' [ Not found ]
[13:08:42] Checking for directory '/usr/doc/backup' [ Not found ]
[13:08:42] Checking for directory '/usr/doc/backup/txt' [ Not found ]
[13:08:42] Checking for directory '/lib/backup' [ Not found ]
[13:08:42] Checking for directory '/lib/backup/txt' [ Not found ]
[13:08:42] Checking for directory '/usr/doc/work' [ Not found ]
[13:08:42] Checking for directory '/usr/doc/sys' [ Not found ]
[13:08:42] Checking for directory '/var/log/ssh' [ Not found ]
[13:08:42] Checking for directory '/usr/doc/.spool' [ Not found ]
[13:08:42] Checking for directory '/usr/lib/kterm' [ Not found ]
[13:08:42] Adore Rootkit [ Not found ]
[13:08:42]
[13:08:42] Checking for aPa Kit...
[13:08:42] Checking for file '/usr/share/.aPa' [ Not found ]
[13:08:42] aPa Kit [ Not found ]
[13:08:42]
[13:08:42] Checking for Apache Worm...
[13:08:42] Checking for file '/bin/.log' [ Not found ]
[13:08:42] Apache Worm [ Not found ]
[13:08:42]
[13:08:42] Checking for Ambient (ark) Rootkit...
[13:08:42] Checking for file '/usr/lib/.ark?' [ Not found ]
[13:08:42] Checking for file '/dev/ptyxx/.log' [ Not found ]
[13:08:42] Checking for file '/dev/ptyxx/.file' [ Not found ]
[13:08:42] Checking for file '/dev/ptyxx/.proc' [ Not found ]
[13:08:42] Checking for file '/dev/ptyxx/.addr' [ Not found ]
[13:08:42] Checking for directory '/dev/ptyxx' [ Not found ]
[13:08:42] Ambient (ark) Rootkit [ Not found ]
[13:08:42]
[13:08:42] Checking for Balaur Rootkit...
[13:08:42] Checking for file '/usr/lib/liblog.o' [ Not found ]
[13:08:42] Checking for directory '/usr/lib/.kinetic' [ Not found ]
[13:08:42] Checking for directory '/usr/lib/.egcs' [ Not found ]
[13:08:42] Checking for directory '/usr/lib/.wormie' [ Not found ]
[13:08:42] Balaur Rootkit [ Not found ]
[13:08:42]
[13:08:42] Checking for BeastKit Rootkit...
[13:08:42] Checking for file '/usr/sbin/arobia' [ Not found ]
[13:08:42] Checking for file '/usr/sbin/idrun' [ Not found ]
[13:08:42] Checking for file '/usr/lib/elm/arobia/elm' [ Not found ]
[13:08:42] Checking for file '/usr/lib/elm/arobia/elm/hk' [ Not found ]
[13:08:42] Checking for file '/usr/lib/elm/arobia/elm/hk.pub' [ Not found ]
[13:08:42] Checking for file '/usr/lib/elm/arobia/elm/sc' [ Not found ]
[13:08:42] Checking for file '/usr/lib/elm/arobia/elm/sd.pp' [ Not found ]
[13:08:42] Checking for file '/usr/lib/elm/arobia/elm/sdco' [ Not found ]
[13:08:42] Checking for file '/usr/lib/elm/arobia/elm/srsd' [ Not found ]
[13:08:42] Checking for directory '/lib/ldd.so/bktools' [ Not found ]
[13:08:43] BeastKit Rootkit [ Not found ]
[13:08:43]
[13:08:43] Checking for beX2 Rootkit...
[13:08:43] Checking for file '/usr/info/termcap.info-5.gz' [ Not found ]
[13:08:43] Checking for file '/usr/bin/sshd2' [ Not found ]
[13:08:43] Checking for directory '/usr/include/bex' [ Not found ]
[13:08:43] beX2 Rootkit [ Not found ]
[13:08:43]
[13:08:43] Checking for BOBKit Rootkit...
[13:08:43] Checking for file '/usr/sbin/ntpsx' [ Not found ]
[13:08:43] Checking for file '/usr/sbin/.../bkit-ava' [ Not found ]
[13:08:43] Checking for file '/usr/sbin/.../bkit-d' [ Not found ]
[13:08:43] Checking for file '/usr/sbin/.../bkit-shd' [ Not found ]
[13:08:43] Checking for file '/usr/sbin/.../bkit-f' [ Not found ]
[13:08:43] Checking for file '/usr/include/.../proc.h' [ Not found ]
[13:08:43] Checking for file '/usr/include/.../.bash_history' [ Not found ]
[13:08:43] Checking for file '/usr/include/.../bkit-get' [ Not found ]
[13:08:43] Checking for file '/usr/include/.../bkit-dl' [ Not found ]
[13:08:43] Checking for file '/usr/include/.../bkit-screen' [ Not found ]
[13:08:43] Checking for file '/usr/include/.../bkit-sleep' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../bkit-adore.o' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../ls' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../netstat' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../lsof' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../bkit-ssh/bkit-shdcfg' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../bkit-ssh/bkit-shhk' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../bkit-ssh/bkit-pw' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../bkit-ssh/bkit-shrs' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../bkit-ssh/bkit-mots' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../uconf.inv' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../psr' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../find' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../pstree' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../slocate' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../du' [ Not found ]
[13:08:43] Checking for file '/usr/lib/.../top' [ Not found ]
[13:08:43] Checking for directory '/usr/sbin/...' [ Not found ]
[13:08:43] Checking for directory '/usr/include/...' [ Not found ]
[13:08:43] Checking for directory '/usr/include/.../.tmp' [ Not found ]
[13:08:43] Checking for directory '/usr/lib/...' [ Not found ]
[13:08:43] Checking for directory '/usr/lib/.../.ssh' [ Not found ]
[13:08:43] Checking for directory '/usr/lib/.../bkit-ssh' [ Not found ]
[13:08:44] Checking for directory '/usr/lib/.bkit-' [ Not found ]
[13:08:44] Checking for directory '/tmp/.bkp' [ Not found ]
[13:08:44] BOBKit Rootkit [ Not found ]
[13:08:44]
[13:08:44] Checking for cb Rootkit...
[13:08:44] Checking for file '/dev/srd0' [ Not found ]
[13:08:44] Checking for file '/lib/libproc.so.2.0.6' [ Not found ]
[13:08:44] Checking for file '/dev/mounnt' [ Not found ]
[13:08:44] Checking for file '/etc/rc.d/init.d/init' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/cl' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/.x.tgz' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/statdx' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/wted' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/write' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/scan' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/sc' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/sl2' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/wroot' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/wscan' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/wu' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/v' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/read' [ Not found ]
[13:08:44] Checking for file '/usr/lib/sshrc' [ Not found ]
[13:08:44] Checking for file '/usr/lib/ssh_host_key' [ Not found ]
[13:08:44] Checking for file '/usr/lib/ssh_host_key.pub' [ Not found ]
[13:08:44] Checking for file '/usr/lib/ssh_random_seed' [ Not found ]
[13:08:44] Checking for file '/usr/lib/sshd_config' [ Not found ]
[13:08:44] Checking for file '/usr/lib/shosts.equiv' [ Not found ]
[13:08:44] Checking for file '/usr/lib/ssh_known_hosts' [ Not found ]
[13:08:44] Checking for file '/u/zappa/.ssh/pid' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.system/..<SP>/tcp.log' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/curatare/attrib' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/curatare/chattr' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/curatare/ps' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.zeen/..<SP>/curatare/pstree' [ Not found ]
[13:08:44] Checking for file '/usr/bin/.system/..<SP>/.x/xC.o' [ Not found ]
[13:08:44] Checking for directory '/usr/bin/.zeen' [ Not found ]
[13:08:44] Checking for directory '/usr/bin/.zeen/..<SP>/curatare' [ Not found ]
[13:08:44] Checking for directory '/usr/bin/.zeen/..<SP>/scan' [ Not found ]
[13:08:44] Checking for directory '/usr/bin/.system/..<SP>' [ Not found ]
[13:08:44] cb Rootkit [ Not found ]
[13:08:44]
[13:08:44] Checking for CiNIK Worm (Slapper.B variant)...
[13:08:44] Checking for file '/tmp/.cinik' [ Not found ]
[13:08:45] Checking for directory '/tmp/.font-unix/.cinik' [ Not found ]
[13:08:45] CiNIK Worm (Slapper.B variant) [ Not found ]
[13:08:45]
[13:08:45] Checking for Danny-Boy's Abuse Kit...
[13:08:45] Checking for file '/dev/mdev' [ Not found ]
[13:08:45] Checking for file '/usr/lib/libX.a' [ Not found ]
[13:08:45] Danny-Boy's Abuse Kit [ Not found ]
[13:08:45]
[13:08:45] Checking for Devil RootKit...
[13:08:45] Checking for file '/var/lib/games/.src' [ Not found ]
[13:08:45] Checking for file '/dev/dsx' [ Not found ]
[13:08:45] Checking for file '/dev/caca' [ Not found ]
[13:08:45] Checking for file '/dev/pro' [ Not found ]
[13:08:45] Checking for file '/bin/bye' [ Not found ]
[13:08:45] Checking for file '/bin/homedir' [ Not found ]
[13:08:45] Checking for file '/usr/bin/xfss' [ Not found ]
[13:08:45] Checking for file '/usr/sbin/tzava' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/stuff/holber' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/stuff/sense' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/stuff/clear' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/stuff/tzava' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/stuff/citeste' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/stuff/killrk' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/stuff/searchlog' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/stuff/gaoaza' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/stuff/cleaner' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/stuff/shk' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/stuff/srs' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/utile.tgz' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/webpage' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/getpsy' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/getbnc' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/getemech' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/localroot.sh' [ Not found ]
[13:08:45] Checking for file '/usr/doc/tar/.../.dracusor/stuff/old/sense' [ Not found ]
[13:08:45] Checking for directory '/usr/doc/tar/.../.dracusor' [ Not found ]
[13:08:45] Devil RootKit [ Not found ]
[13:08:45]
[13:08:45] Checking for Diamorphine LKM...
[13:08:45] Checking for kernel symbol 'diamorphine' [ Not found ]
[13:08:46] Checking for kernel symbol 'module_hide' [ Not found ]
[13:08:46] Checking for kernel symbol 'module_hidden' [ Not found ]
[13:08:46] Checking for kernel symbol 'is_invisible' [ Not found ]
[13:08:46] Checking for kernel symbol 'hacked_getdents' [ Not found ]
[13:08:46] Checking for kernel symbol 'hacked_kill' [ Not found ]
[13:08:46] Diamorphine LKM [ Not found ]
[13:08:46]
[13:08:46] Checking for Dica-Kit Rootkit...
[13:08:46] Checking for file '/lib/.sso' [ Not found ]
[13:08:46] Checking for file '/lib/.so' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/clean' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/dxr' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/read' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/write' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/lf' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/xl' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/xdr' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/psg' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/secure' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/rdx' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/va' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/cl.sh' [ Not found ]
[13:08:46] Checking for file '/var/run/...dica/last.log' [ Not found ]
[13:08:46] Checking for file '/usr/bin/.etc' [ Not found ]
[13:08:46] Checking for file '/etc/sshd_config' [ Not found ]
[13:08:46] Checking for file '/etc/ssh_host_key' [ Not found ]
[13:08:46] Checking for file '/etc/ssh_random_seed' [ Not found ]
[13:08:47] Checking for directory '/var/run/...dica' [ Not found ]
[13:08:47] Checking for directory '/var/run/...dica/mh' [ Not found ]
[13:08:47] Checking for directory '/var/run/...dica/scan' [ Not found ]
[13:08:47] Dica-Kit Rootkit [ Not found ]
[13:08:47]
[13:08:47] Checking for Dreams Rootkit...
[13:08:47] Checking for file '/dev/ttyoa' [ Not found ]
[13:08:47] Checking for file '/dev/ttyof' [ Not found ]
[13:08:47] Checking for file '/dev/ttyop' [ Not found ]
[13:08:47] Checking for file '/usr/bin/sense' [ Not found ]
[13:08:47] Checking for file '/usr/bin/sl2' [ Not found ]
[13:08:47] Checking for file '/usr/bin/logclear' [ Not found ]
[13:08:47] Checking for file '/usr/bin/(swapd)' [ Not found ]
[13:08:47] Checking for file '/usr/bin/initrd' [ Not found ]
[13:08:47] Checking for file '/usr/bin/crontabs' [ Not found ]
[13:08:47] Checking for file '/usr/bin/snfs' [ Not found ]
[13:08:47] Checking for file '/usr/lib/libsss' [ Not found ]
[13:08:47] Checking for file '/usr/lib/libsnf.log' [ Not found ]
[13:08:47] Checking for file '/usr/lib/libshtift/top' [ Not found ]
[13:08:47] Checking for file '/usr/lib/libshtift/ps' [ Not found ]
[13:08:47] Checking for file '/usr/lib/libshtift/netstat' [ Not found ]
[13:08:47] Checking for file '/usr/lib/libshtift/ls' [ Not found ]
[13:08:47] Checking for file '/usr/lib/libshtift/ifconfig' [ Not found ]
[13:08:47] Checking for file '/usr/include/linseed.h' [ Not found ]
[13:08:47] Checking for file '/usr/include/linpid.h' [ Not found ]
[13:08:47] Checking for file '/usr/include/linkey.h' [ Not found ]
[13:08:47] Checking for file '/usr/include/linconf.h' [ Not found ]
[13:08:47] Checking for file '/usr/include/iceseed.h' [ Not found ]
[13:08:47] Checking for file '/usr/include/icepid.h' [ Not found ]
[13:08:47] Checking for file '/usr/include/icekey.h' [ Not found ]
[13:08:47] Checking for file '/usr/include/iceconf.h' [ Not found ]
[13:08:47] Checking for directory '/dev/ida/.hpd' [ Not found ]
[13:08:47] Checking for directory '/usr/lib/libshtift' [ Not found ]
[13:08:47] Dreams Rootkit [ Not found ]
[13:08:47]
[13:08:47] Checking for Duarawkz Rootkit...
[13:08:47] Checking for file '/usr/bin/duarawkz/loginpass' [ Not found ]
[13:08:47] Checking for directory '/usr/bin/duarawkz' [ Not found ]
[13:08:47] Duarawkz Rootkit [ Not found ]
[13:08:47]
[13:08:47] Checking for Ebury backdoor...
[13:08:47] Checking for file '/lib/libns2.so' [ Not found ]
[13:08:47] Checking for file '/lib64/libns2.so' [ Not found ]
[13:08:47] Checking for file '/lib/libns5.so' [ Not found ]
[13:08:48] Checking for file '/lib64/libns5.so' [ Not found ]
[13:08:48] Checking for file '/lib/libpw3.so' [ Not found ]
[13:08:48] Checking for file '/lib64/libpw3.so' [ Not found ]
[13:08:48] Checking for file '/lib/libpw5.so' [ Not found ]
[13:08:48] Checking for file '/lib64/libpw5.so' [ Not found ]
[13:08:48] Checking for file '/lib/libsbr.so' [ Not found ]
[13:08:48] Checking for file '/lib64/libsbr.so' [ Not found ]
[13:08:48] Checking for file '/lib/libslr.so' [ Not found ]
[13:08:48] Checking for file '/lib64/libslr.so' [ Not found ]
[13:08:48] Checking for file '/lib/tls/libkeyutils.so.1' [ Not found ]
[13:08:48] Checking for file '/lib64/tls/libkeyutils.so.1' [ Not found ]
[13:08:48] Ebury backdoor [ Not found ]
[13:08:48]
[13:08:48] Checking for Enye LKM...
[13:08:48] Checking for file '/etc/.enyelkmHIDE^IT.ko' [ Not found ]
[13:08:48] Checking for file '/etc/.enyelkmOCULTAR.ko' [ Not found ]
[13:08:48] Enye LKM [ Not found ]
[13:08:48]
[13:08:48] Checking for Flea Linux Rootkit...
[13:08:48] Checking for file '/etc/ld.so.hash' [ Not found ]
[13:08:48] Checking for file '/lib/security/.config/ssh/sshd_config' [ Not found ]
[13:08:48] Checking for file '/lib/security/.config/ssh/ssh_host_key' [ Not found ]
[13:08:48] Checking for file '/lib/security/.config/ssh/ssh_host_key.pub' [ Not found ]
[13:08:48] Checking for file '/lib/security/.config/ssh/ssh_random_seed' [ Not found ]
[13:08:48] Checking for file '/usr/bin/ssh2d' [ Not found ]
[13:08:48] Checking for file '/usr/lib/ldlibns.so' [ Not found ]
[13:08:48] Checking for file '/usr/lib/ldlibps.so' [ Not found ]
[13:08:48] Checking for file '/usr/lib/ldlibpst.so' [ Not found ]
[13:08:48] Checking for file '/usr/lib/ldlibdu.so' [ Not found ]
[13:08:48] Checking for file '/usr/lib/ldlibct.so' [ Not found ]
[13:08:48] Checking for directory '/lib/security/.config/ssh' [ Not found ]
[13:08:48] Checking for directory '/dev/..0' [ Not found ]
[13:08:48] Checking for directory '/dev/..0/backup' [ Not found ]
[13:08:48] Flea Linux Rootkit [ Not found ]
[13:08:48]
[13:08:48] Checking for Fu Rootkit...
[13:08:48] Checking for file '/sbin/xc' [ Not found ]
[13:08:48] Checking for file '/usr/include/ivtype.h' [ Not found ]
[13:08:48] Checking for file '/bin/.lib' [ Not found ]
[13:08:48] Fu Rootkit [ Not found ]
[13:08:48]
[13:08:48] Checking for Fuck`it Rootkit...
[13:08:48] Checking for file '/lib/libproc.so.2.0.7' [ Not found ]
[13:08:48] Checking for file '/dev/proc/.bash_profile' [ Not found ]
[13:08:48] Checking for file '/dev/proc/.bashrc' [ Not found ]
[13:08:49] Checking for file '/dev/proc/.cshrc' [ Not found ]
[13:08:49] Checking for file '/dev/proc/fuckit/hax0r' [ Not found ]
[13:08:49] Checking for file '/dev/proc/fuckit/hax0rshell' [ Not found ]
[13:08:49] Checking for file '/dev/proc/fuckit/config/lports' [ Not found ]
[13:08:49] Checking for file '/dev/proc/fuckit/config/rports' [ Not found ]
[13:08:49] Checking for file '/dev/proc/fuckit/config/rkconf' [ Not found ]
[13:08:49] Checking for file '/dev/proc/fuckit/config/password' [ Not found ]
[13:08:49] Checking for file '/dev/proc/fuckit/config/progs' [ Not found ]
[13:08:49] Checking for file '/dev/proc/fuckit/system-bins/init' [ Not found ]
[13:08:49] Checking for file '/usr/lib/libcps.a' [ Not found ]
[13:08:49] Checking for file '/usr/lib/libtty.a' [ Not found ]
[13:08:49] Checking for directory '/dev/proc' [ Not found ]
[13:08:49] Checking for directory '/dev/proc/fuckit' [ Not found ]
[13:08:49] Checking for directory '/dev/proc/fuckit/system-bins' [ Not found ]
[13:08:49] Checking for directory '/dev/proc/toolz' [ Not found ]
[13:08:49] Fuck`it Rootkit [ Not found ]
[13:08:49]
[13:08:49] Checking for GasKit Rootkit...
[13:08:49] Checking for file '/dev/dev/gaskit/sshd/sshdd' [ Not found ]
[13:08:49] Checking for directory '/dev/dev' [ Not found ]
[13:08:49] Checking for directory '/dev/dev/gaskit' [ Not found ]
[13:08:49] Checking for directory '/dev/dev/gaskit/sshd' [ Not found ]
[13:08:49] GasKit Rootkit [ Not found ]
[13:08:49]
[13:08:49] Checking for Heroin LKM...
[13:08:49] Checking for kernel symbol 'heroin' [ Not found ]
[13:08:49] Heroin LKM [ Not found ]
[13:08:49]
[13:08:49] Checking for HjC Kit...
[13:08:49] Checking for directory '/dev/.hijackerz' [ Not found ]
[13:08:49] HjC Kit [ Not found ]
[13:08:49]
[13:08:49] Checking for ignoKit Rootkit...
[13:08:49] Checking for file '/lib/defs/p' [ Not found ]
[13:08:49] Checking for file '/lib/defs/q' [ Not found ]
[13:08:49] Checking for file '/lib/defs/r' [ Not found ]
[13:08:49] Checking for file '/lib/defs/s' [ Not found ]
[13:08:49] Checking for file '/lib/defs/t' [ Not found ]
[13:08:49] Checking for file '/usr/lib/defs/p' [ Not found ]
[13:08:49] Checking for file '/usr/lib/defs/q' [ Not found ]
[13:08:49] Checking for file '/usr/lib/defs/r' [ Not found ]
[13:08:49] Checking for file '/usr/lib/defs/s' [ Not found ]
[13:08:49] Checking for file '/usr/lib/defs/t' [ Not found ]
[13:08:49] Checking for file '/usr/lib/.libigno/pkunsec' [ Not found ]
[13:08:50] Checking for file '/usr/lib/.libigno/.igno/psybnc/psybnc' [ Not found ]
[13:08:50] Checking for directory '/usr/lib/.libigno' [ Not found ]
[13:08:50] Checking for directory '/usr/lib/.libigno/.igno' [ Not found ]
[13:08:50] ignoKit Rootkit [ Not found ]
[13:08:50]
[13:08:50] Checking for IntoXonia-NG Rootkit...
[13:08:50] Checking for kernel symbol 'funces' [ Not found ]
[13:08:50] Checking for kernel symbol 'ixinit' [ Not found ]
[13:08:50] Checking for kernel symbol 'tricks' [ Not found ]
[13:08:50] Checking for kernel symbol 'kernel_unlink' [ Not found ]
[13:08:50] Checking for kernel symbol 'rootme' [ Not found ]
[13:08:50] Checking for kernel symbol 'hide_module' [ Not found ]
[13:08:50] Checking for kernel symbol 'find_sys_call_tbl' [ Not found ]
[13:08:50] IntoXonia-NG Rootkit [ Not found ]
[13:08:50]
[13:08:50] Checking for Irix Rootkit...
[13:08:50] Checking for directory '/dev/pts/01' [ Not found ]
[13:08:50] Checking for directory '/dev/pts/01/backup' [ Not found ]
[13:08:50] Checking for directory '/dev/pts/01/etc' [ Not found ]
[13:08:51] Checking for directory '/dev/pts/01/tmp' [ Not found ]
[13:08:51] Irix Rootkit [ Not found ]
[13:08:51]
[13:08:51] Checking for Jynx Rootkit...
[13:08:51] Checking for file '/xochikit/bc' [ Not found ]
[13:08:51] Checking for file '/xochikit/ld_poison.so' [ Not found ]
[13:08:51] Checking for file '/omgxochi/bc' [ Not found ]
[13:08:51] Checking for file '/omgxochi/ld_poison.so' [ Not found ]
[13:08:51] Checking for file '/var/local/^^/bc' [ Not found ]
[13:08:51] Checking for file '/var/local/^^/ld_poison.so' [ Not found ]
[13:08:51] Checking for directory '/xochikit' [ Not found ]
[13:08:51] Checking for directory '/omgxochi' [ Not found ]
[13:08:51] Checking for directory '/var/local/^^' [ Not found ]
[13:08:51] Jynx Rootkit [ Not found ]
[13:08:51]
[13:08:51] Checking for Jynx2 Rootkit...
[13:08:51] Checking for file '/XxJynx/reality.so' [ Not found ]
[13:08:51] Checking for directory '/XxJynx' [ Not found ]
[13:08:51] Jynx2 Rootkit [ Not found ]
[13:08:51]
[13:08:51] Checking for KBeast Rootkit...
[13:08:51] Checking for file '/usr/_h4x_/ipsecs-kbeast-v1.ko' [ Not found ]
[13:08:51] Checking for file '/usr/_h4x_/_h4x_bd' [ Not found ]
[13:08:51] Checking for file '/usr/_h4x_/acctlog' [ Not found ]
[13:08:51] Checking for directory '/usr/_h4x_' [ Not found ]
[13:08:51] Checking for kernel symbol 'h4x_delete_module' [ Not found ]
[13:08:51] Checking for kernel symbol 'h4x_getdents64' [ Not found ]
[13:08:51] Checking for kernel symbol 'h4x_kill' [ Not found ]
[13:08:51] Checking for kernel symbol 'h4x_open' [ Not found ]
[13:08:52] Checking for kernel symbol 'h4x_read' [ Not found ]
[13:08:52] Checking for kernel symbol 'h4x_rename' [ Not found ]
[13:08:52] Checking for kernel symbol 'h4x_rmdir' [ Not found ]
[13:08:52] Checking for kernel symbol 'h4x_tcp4_seq_show' [ Not found ]
[13:08:52] Checking for kernel symbol 'h4x_write' [ Not found ]
[13:08:52] KBeast Rootkit [ Not found ]
[13:08:52]
[13:08:52] Checking for Kitko Rootkit...
[13:08:52] Checking for directory '/usr/src/redhat/SRPMS/...' [ Not found ]
[13:08:52] Kitko Rootkit [ Not found ]
[13:08:52]
[13:08:52] Checking for Knark Rootkit...
[13:08:52] Checking for file '/proc/knark/pids' [ Not found ]
[13:08:52] Checking for directory '/proc/knark' [ Not found ]
[13:08:52] Knark Rootkit [ Not found ]
[13:08:52]
[13:08:52] Checking for ld-linuxv.so Rootkit...
[13:08:52] Checking for file '/lib/ld-linuxv.so.1' [ Not found ]
[13:08:52] Checking for directory '/var/opt/_so_cache' [ Not found ]
[13:08:52] Checking for directory '/var/opt/_so_cache/ld' [ Not found ]
[13:08:52] Checking for directory '/var/opt/_so_cache/lc' [ Not found ]
[13:08:52] ld-linuxv.so Rootkit [ Not found ]
[13:08:52]
[13:08:52] Checking for Li0n Worm...
[13:08:52] Checking for file '/bin/in.telnetd' [ Not found ]
[13:08:52] Checking for file '/bin/mjy' [ Not found ]
[13:08:52] Checking for file '/usr/man/man1/man1/lib/.lib/mjy' [ Not found ]
[13:08:52] Checking for file '/usr/man/man1/man1/lib/.lib/in.telnetd' [ Not found ]
[13:08:52] Checking for file '/usr/man/man1/man1/lib/.lib/.x' [ Not found ]
[13:08:52] Checking for file '/dev/.lib/lib/scan/1i0n.sh' [ Not found ]
[13:08:52] Checking for file '/dev/.lib/lib/scan/hack.sh' [ Not found ]
[13:08:52] Checking for file '/dev/.lib/lib/scan/bind' [ Not found ]
[13:08:52] Checking for file '/dev/.lib/lib/scan/randb' [ Not found ]
[13:08:52] Checking for file '/dev/.lib/lib/scan/scan.sh' [ Not found ]
[13:08:53] Checking for file '/dev/.lib/lib/scan/pscan' [ Not found ]
[13:08:53] Checking for file '/dev/.lib/lib/scan/star.sh' [ Not found ]
[13:08:53] Checking for file '/dev/.lib/lib/scan/bindx.sh' [ Not found ]
[13:08:53] Checking for file '/dev/.lib/lib/scan/bindname.log' [ Not found ]
[13:08:53] Checking for file '/dev/.lib/lib/1i0n.sh' [ Not found ]
[13:08:53] Checking for file '/dev/.lib/lib/lib/netstat' [ Not found ]
[13:08:53] Checking for file '/dev/.lib/lib/lib/dev/.1addr' [ Not found ]
[13:08:53] Checking for file '/dev/.lib/lib/lib/dev/.1logz' [ Not found ]
[13:08:53] Checking for file '/dev/.lib/lib/lib/dev/.1proc' [ Not found ]
[13:08:53] Checking for file '/dev/.lib/lib/lib/dev/.1file' [ Not found ]
[13:08:53] Li0n Worm [ Not found ]
[13:08:53]
[13:08:53] Checking for Lockit / LJK2 Rootkit...
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_config' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_host_key.pub' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/ssh_random_seed*' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/sshd_config' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backdoor/RK1bd' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/du' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ifconfig' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/inetd.conf' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/locate' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/login' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ls' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/netstat' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/ps' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/pstree' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/rc.sysinit' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/syslogd' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/tcpd' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/backup/top' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1sauber' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/clean/RK1wted' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1parse' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/hack/RK1sniff' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1addr' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1dir' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1log' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/.RK1proc' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/hide/RK1phidemod.c' [ Not found ]
[13:08:53] Checking for file '/usr/lib/libmen.oo/.LJK2/modules/README.modules' [ Not found ]
[13:08:54] Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1hidem.c' [ Not found ]
[13:08:54] Checking for file '/usr/lib/libmen.oo/.LJK2/modules/RK1phide' [ Not found ]
[13:08:54] Checking for file '/usr/lib/libmen.oo/.LJK2/sshconfig/RK1ssh' [ Not found ]
[13:08:54] Checking for directory '/usr/lib/libmen.oo/.LJK2' [ Not found ]
[13:08:54] Lockit / LJK2 Rootkit [ Not found ]
[13:08:54]
[13:08:54] Checking for Mokes backdoor...
[13:08:54] Checking for file '/tmp/ss0-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9].sst' [ Not found ]
[13:08:54] Checking for file '/tmp/aa0-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9].aat' [ Not found ]
[13:08:54] Checking for file '/tmp/kk0-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9].kkt' [ Not found ]
[13:08:54] Checking for file '/tmp/dd0-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9][0-9][0-9][0-9]-[0-9][0-9][0-9].ddt' [ Not found ]
[13:08:54] Mokes backdoor [ Not found ]
[13:08:54]
[13:08:54] Checking for Mood-NT Rootkit...
[13:08:54] Checking for file '/sbin/init__mood-nt-_-_cthulhu' [ Not found ]
[13:08:54] Checking for file '/_cthulhu/mood-nt.init' [ Not found ]
[13:08:54] Checking for file '/_cthulhu/mood-nt.conf' [ Not found ]
[13:08:54] Checking for file '/_cthulhu/mood-nt.sniff' [ Not found ]
[13:08:54] Checking for directory '/_cthulhu' [ Not found ]
[13:08:54] Mood-NT Rootkit [ Not found ]
[13:08:54]
[13:08:54] Checking for MRK Rootkit...
[13:08:54] Checking for file '/dev/ida/.inet/pid' [ Not found ]
[13:08:54] Checking for file '/dev/ida/.inet/ssh_host_key' [ Not found ]
[13:08:54] Checking for file '/dev/ida/.inet/ssh_random_seed' [ Not found ]
[13:08:54] Checking for file '/dev/ida/.inet/tcp.log' [ Not found ]
[13:08:54] Checking for directory '/dev/ida/.inet' [ Not found ]
[13:08:54] Checking for directory '/var/spool/cron/.sh' [ Not found ]
[13:08:54] MRK Rootkit [ Not found ]
[13:08:54]
[13:08:54] Checking for Ni0 Rootkit...
[13:08:54] Checking for file '/var/lock/subsys/...datafile.../...net...' [ Not found ]
[13:08:54] Checking for file '/var/lock/subsys/...datafile.../...port...' [ Not found ]
[13:08:54] Checking for file '/var/lock/subsys/...datafile.../...ps...' [ Not found ]
[13:08:54] Checking for file '/var/lock/subsys/...datafile.../...file...' [ Not found ]
[13:08:54] Checking for directory '/tmp/waza' [ Not found ]
[13:08:54] Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[13:08:54] Checking for directory '/usr/sbin/es' [ Not found ]
[13:08:54] Ni0 Rootkit [ Not found ]
[13:08:54]
[13:08:54] Checking for Ohhara Rootkit...
[13:08:54] Checking for file '/var/lock/subsys/...datafile.../...datafile.../in.smbd.log' [ Not found ]
[13:08:54] Checking for directory '/var/lock/subsys/...datafile...' [ Not found ]
[13:08:54] Checking for directory '/var/lock/subsys/...datafile.../...datafile...' [ Not found ]
[13:08:54] Checking for directory '/var/lock/subsys/...datafile.../...datafile.../bin' [ Not found ]
[13:08:54] Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/bin' [ Not found ]
[13:08:54] Checking for directory '/var/lock/subsys/...datafile.../...datafile.../usr/sbin' [ Not found ]
[13:08:54] Checking for directory '/var/lock/subsys/...datafile.../...datafile.../lib/security' [ Not found ]
[13:08:55] Ohhara Rootkit [ Not found ]
[13:08:55]
[13:08:55] Checking for Optic Kit (Tux) Worm...
[13:08:55] Checking for directory '/dev/tux' [ Not found ]
[13:08:55] Checking for directory '/usr/bin/xchk' [ Not found ]
[13:08:55] Checking for directory '/usr/bin/xsf' [ Not found ]
[13:08:55] Checking for directory '/usr/bin/ssh2d' [ Not found ]
[13:08:55] Optic Kit (Tux) Worm [ Not found ]
[13:08:55]
[13:08:55] Checking for Oz Rootkit...
[13:08:55] Checking for file '/dev/.oz/.nap/rkit/terror' [ Not found ]
[13:08:55] Checking for directory '/dev/.oz' [ Not found ]
[13:08:55] Oz Rootkit [ Not found ]
[13:08:55]
[13:08:55] Checking for Phalanx Rootkit...
[13:08:55] Checking for file '/uNFuNF' [ Not found ]
[13:08:55] Checking for file '/etc/host.ph1' [ Not found ]
[13:08:55] Checking for file '/bin/host.ph1' [ Not found ]
[13:08:55] Checking for file '/usr/share/.home.ph1/phalanx' [ Not found ]
[13:08:55] Checking for file '/usr/share/.home.ph1/cb' [ Not found ]
[13:08:55] Checking for file '/usr/share/.home.ph1/kebab' [ Not found ]
[13:08:55] Checking for directory '/usr/share/.home.ph1' [ Not found ]
[13:08:55] Checking for directory '/usr/share/.home.ph1/tty' [ Not found ]
[13:08:55] Phalanx Rootkit [ Not found ]
[13:08:55]
[13:08:55] Checking for Phalanx2 Rootkit...
[13:08:55] Checking for file '/etc/khubd.p2/.p2rc' [ Not found ]
[13:08:55] Checking for file '/etc/khubd.p2/.phalanx2' [ Not found ]
[13:08:55] Checking for file '/etc/khubd.p2/.sniff' [ Not found ]
[13:08:55] Checking for file '/etc/khubd.p2/sshgrab.py' [ Not found ]
[13:08:55] Checking for file '/etc/lolzz.p2/.p2rc' [ Not found ]
[13:08:55] Checking for file '/etc/lolzz.p2/.phalanx2' [ Not found ]
[13:08:55] Checking for file '/etc/lolzz.p2/.sniff' [ Not found ]
[13:08:55] Checking for file '/etc/lolzz.p2/sshgrab.py' [ Not found ]
[13:08:55] Checking for file '/etc/cron.d/zupzzplaceholder' [ Not found ]
[13:08:55] Checking for file '/usr/lib/zupzz.p2/.p-2.3d' [ Not found ]
[13:08:55] Checking for file '/usr/lib/zupzz.p2/.p2rc' [ Not found ]
[13:08:55] Checking for directory '/etc/khubd.p2' [ Not found ]
[13:08:55] Checking for directory '/etc/lolzz.p2' [ Not found ]
[13:08:55] Checking for directory '/usr/lib/zupzz.p2' [ Not found ]
[13:08:55] Phalanx2 Rootkit [ No


  


2. MELHOR RESPOSTA

Buckminster
Buckminster

(usa Debian)

Enviado em 25/10/2024 - 13:12h

A partição /dev/shm utiliza o sistema de arquivos tmpfs (sistema de arquivos usado para segmentos de memória compartilhada que um processo usa para se comunicar com outros processos), e é armazenada 100% na memória RAM.

Essa partição facilita a troca de informações entre diferentes processos do sistema operacional e deixa alguns processos mais rápidos. No Debian essa partição geralmente aloca metade da RAM, 50%.

$ df -h

Sist. Arq. Tam. Usado Disp. Uso% Montado em
udev 12G 0 12G 0% /dev
tmpfs 2,4G 1,4M 2,4G 1% /run
/dev/sda2 23G 15G 7,3G 67% /
tmpfs 12G 93M 12G 1% /dev/shm <<< veja, metade da RAM, 12G
tmpfs 5,0M 8,0K 5,0M 1% /run/lock
/dev/sda3 9,1G 3,9G 4,8G 46% /var
/dev/sda6 423G 14G 388G 4% /home
/dev/sda5 1,8G 12M 1,7G 1% /tmp
/dev/sda1 511M 5,9M 506M 2% /boot/efi
tmpfs 2,4G 68K 2,4G 1% /run/user/1000

xxx@xxx:/dev/shm$ ls -la

total 2228
drwxrwxrwt 2 root root 100 out 25 12:46 .
drwxr-xr-x 17 root root 3580 out 25 10:02 ..
-rw------- 1 postgres postgres 1048576 out 25 10:02 PostgreSQL.2005936928
-rw------- 1 postgres postgres 26976 out 25 10:02 PostgreSQL.2040927740
-rw-r--r-- 1 root root 1200720 out 25 10:02 ShM.c5fa4b64H8dd08c52

Veja esse link de 2023, tem um cara com o mesmo nome que o teu:
https://www.vivaolinux.com.br/topico/Duvidas-em-Geral/Arquivos-Suspeitos-com-o-RKHunter

E esse:
https://plus.diolinux.com.br/t/rootkits-rkunter-falsos-positivos/31204/9

Segundo esse link abaixo, esses arquivos aí são partes do Warsaw Internet Banking:
https://www.reddit.com/r/linuxbrasil/comments/gst0o7/warsaw/

Verifique com sudo lsof qual processo utiliza o arquivo:

xxx@xxx/dev/shm$ sudo lsof ShM.c5fa4b64H8dd08c52

lsof: WARNING: can't stat() fuse.portal file system /run/user/1000/doc
Output information may be incomplete.
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
apache2 1155 root mem REG 0,26 1200720 4 ShM.c5fa4b64H8dd08c52
apache2 1169 www-data mem REG 0,26 1200720 4 ShM.c5fa4b64H8dd08c52
apache2 1170 www-data mem REG 0,26 1200720 4 ShM.c5fa4b64H8dd08c52
apache2 1196 www-data mem REG 0,26 1200720 4 ShM.c5fa4b64H8dd08c52
apache2 1243 www-data mem REG 0,26 1200720 4 ShM.c5fa4b64H8dd08c52

Veja que, no meu caso, é o Apache2.

Caso você tinha (ou tem) internet banking, pode ser um falso positivo.
Pode ser também da Receita Federal que usa Java.
Verifique qual processo usa o arquivo, caso for um processo de um programa com nome desconhecido, pesquise o nome.


_________________________________________________________
Always listen the Buck!
Enquanto o cursor estiver pulsando, há vida!

3. Re: RKHUNTER encontrou uns arquivos suspeitos [RESOLVIDO]

Amarildo Sertorio dos Santos
amarildosertorio

(usa Fedora)

Enviado em 25/10/2024 - 12:46h

A ferramenta emitiu um alerta de arquivos suspeitos. Embora isso possa se tratar de um falso positivo, é importante contar com habilidades em segurança para realizar uma análise mais aprofundada.

Por exemplo, a presença desse diretório oculto pode ser normal se o Java estiver instalado.


4. Re: RKHUNTER encontrou uns arquivos suspeitos [RESOLVIDO]

Henrique
Henrique-RJ

(usa Outra)

Enviado em 25/10/2024 - 12:51h


amarildosertorio escreveu:

A ferramenta emitiu um alerta de arquivos suspeitos. Embora isso possa se tratar de um falso positivo, é importante contar com habilidades em segurança para realizar uma análise mais aprofundada.

Por exemplo, a presença desse diretório oculto pode ser normal se o Java estiver instalado.



O Java aqui está instalado sim por força do plugin de segurança dos bancos senão eu não o teria.



_______________________________________________________
E viu-se um grande sinal no céu: uma mulher vestida do sol, tendo a lua debaixo dos seus pés, e uma coroa de doze estrelas sobre a sua cabeça. Apocalipse 12:1 Nsa Sra de Fátima, Nsa Sra de Lourdes, Nsa Sra das Graças ...
_______________________________________________________
São Padre Pio de Pietrelcina, Santa Faustina Kowalska, São Francisco de Assis e Santa Gema Galgani foram alguns dos que tiveram os milagres dos Estigmas de Cristo em seus corpos, Feridas que sangravam
_______________________________________________________
Milagre Eucarístico que ocorreu em uma Igreja de Lanciano na Itália no ano de 750 em que o vinho se tornou sangue e o pão carne humana estão até hoje intactos. https://pt.wikipedia.org/wiki/Milagre_eucar%C3%ADstico_de_Lanciano


5. Re: RKHUNTER encontrou uns arquivos suspeitos

Henrique
Henrique-RJ

(usa Outra)

Enviado em 25/10/2024 - 13:35h

Buckminster escreveu:

A partição /dev/shm utiliza o sistema de arquivos tmpfs (sistema de arquivos usado para segmentos de memória compartilhada que um processo usa para se comunicar com outros processos), e é armazenada 100% na memória RAM.

Essa partição facilita a troca de informações entre diferentes processos do sistema operacional e deixa alguns processos mais rápidos. No Debian essa partição geralmente aloca metade da RAM, 50%.

$ df -h

Sist. Arq. Tam. Usado Disp. Uso% Montado em
udev 12G 0 12G 0% /dev
tmpfs 2,4G 1,4M 2,4G 1% /run
/dev/sda2 23G 15G 7,3G 67% /
tmpfs 12G 93M 12G 1% /dev/shm <<< veja, metade da RAM, 12G
tmpfs 5,0M 8,0K 5,0M 1% /run/lock
/dev/sda3 9,1G 3,9G 4,8G 46% /var
/dev/sda6 423G 14G 388G 4% /home
/dev/sda5 1,8G 12M 1,7G 1% /tmp
/dev/sda1 511M 5,9M 506M 2% /boot/efi
tmpfs 2,4G 68K 2,4G 1% /run/user/1000

xxx@xxx:/dev/shm$ ls -la

total 2228
drwxrwxrwt 2 root root 100 out 25 12:46 .
drwxr-xr-x 17 root root 3580 out 25 10:02 ..
-rw------- 1 postgres postgres 1048576 out 25 10:02 PostgreSQL.2005936928
-rw------- 1 postgres postgres 26976 out 25 10:02 PostgreSQL.2040927740
-rw-r--r-- 1 root root 1200720 out 25 10:02 ShM.c5fa4b64H8dd08c52

Veja esse link de 2023, tem um cara com o mesmo nome que o teu:
https://www.vivaolinux.com.br/topico/Duvidas-em-Geral/Arquivos-Suspeitos-com-o-RKHunter

E esse:
https://plus.diolinux.com.br/t/rootkits-rkunter-falsos-positivos/31204/9

Segundo esse link abaixo, esses arquivos aí são partes do Warsaw Internet Banking:
https://www.reddit.com/r/linuxbrasil/comments/gst0o7/warsaw/

Verifique com sudo lsof qual processo utiliza o arquivo:

xxx@xxx/dev/shm$ sudo lsof ShM.c5fa4b64H8dd08c52

lsof: WARNING: can't stat() fuse.portal file system /run/user/1000/doc
Output information may be incomplete.
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
apache2 1155 root mem REG 0,26 1200720 4 ShM.c5fa4b64H8dd08c52
apache2 1169 www-data mem REG 0,26 1200720 4 ShM.c5fa4b64H8dd08c52
apache2 1170 www-data mem REG 0,26 1200720 4 ShM.c5fa4b64H8dd08c52
apache2 1196 www-data mem REG 0,26 1200720 4 ShM.c5fa4b64H8dd08c52
apache2 1243 www-data mem REG 0,26 1200720 4 ShM.c5fa4b64H8dd08c52

Veja que, no meu caso, é o Apache2.

Caso você tinha (ou tem) internet banking, pode ser um falso positivo.
Pode ser também da Receita Federal que usa Java.
Verifique qual processo usa o arquivo, caso for um processo de um programa com nome desconhecido, pesquise o nome.


_________________________________________________________
Always listen the Buck!
Enquanto o cursor estiver pulsando, há vida!


@Buckminster

Matou a xarada ...

root@Henrique-Bodhi-5:/dev/shm# lsof sem.WS_N7DA0CBA2
lsof: WARNING: can't stat() fuse.gvfsd-fuse file system /run/user/1000/gvfs
Output information may be incomplete.
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
core 1135 root DEL REG 0,25 7 sem.WS_N7DA0CBA2


Esse " core " é do warsaw dos bancos

Ufa !!! menos um abacaxi ...

2GB ... metade de toda a minha memória que essa coisa consome ...

root@Henrique-Bodhi-5:/dev/shm# df -h
Sist. Arq. Tam. Usado Disp. Uso% Montado em
udev 1,9G 0 1,9G 0% /dev
tmpfs 394M 2,6M 391M 1% /run
/dev/sda1 34G 25G 7,4G 77% /
tmpfs 2,0G 16K 2,0G 1% /dev/shm
tmpfs 5,0M 8,0K 5,0M 1% /run/lock
tmpfs 2,0G 0 2,0G 0% /sys/fs/cgroup
tmpfs 394M 12K 394M 1% /run/user/1000

root@Henrique-Bodhi-5:/dev/shm# ls -la
total 16
drwxrwxrwt 2 root root 160 out 25 13:29 .
drwxr-xr-x 20 root root 4160 out 25 12:08 ..
-rw-rw-rw- 1 root root 32 out 25 12:08 sem.WS_N7DA0CBA2
-rw-rw-rw- 1 root root 41 out 25 12:08 wimtxWS_N16F4F95B
-rw-rw-rw- 1 root root 41 out 25 12:08 wimtxWS_N1D1A924E
-rw-rw-rw- 1 root root 1 out 25 12:08 wiservice
prw-rw-rw- 1 root root 0 out 25 12:08 wiservice1135
-rw-rw-rw- 1 root root 0 out 25 12:08 wiuser




_______________________________________________________
E viu-se um grande sinal no céu: uma mulher vestida do sol, tendo a lua debaixo dos seus pés, e uma coroa de doze estrelas sobre a sua cabeça. Apocalipse 12:1 Nsa Sra de Fátima, Nsa Sra de Lourdes, Nsa Sra das Graças ...
_______________________________________________________
São Padre Pio de Pietrelcina, Santa Faustina Kowalska, São Francisco de Assis e Santa Gema Galgani foram alguns dos que tiveram os milagres dos Estigmas de Cristo em seus corpos, Feridas que sangravam
_______________________________________________________
Milagre Eucarístico que ocorreu em uma Igreja de Lanciano na Itália no ano de 750 em que o vinho se tornou sangue e o pão carne humana estão até hoje intactos. https://pt.wikipedia.org/wiki/Milagre_eucar%C3%ADstico_de_Lanciano


6. Re: RKHUNTER encontrou uns arquivos suspeitos [RESOLVIDO]

Buckminster
Buckminster

(usa Debian)

Enviado em 25/10/2024 - 16:17h

Não consome metade da RAM, somente aloca o espaço e usa quando precisa, nem todos os programas utilizam o /dev/shm, como pode ver com o comando:

xxx@xxx:/dev/shm$ ls -lah

total 2,2M <<< veja o tamanho realmente ocupado na RAM
drwxrwxrwt 2 root root 100 out 25 16:16 .
drwxr-xr-x 17 root root 3,5K out 25 10:02 ..
-rw------- 1 postgres postgres 1,0M out 25 10:02 PostgreSQL.2005936928
-rw------- 1 postgres postgres 27K out 25 10:02 PostgreSQL.2040927740
-rw-r--r-- 1 root root 1,2M out 25 10:02 ShM.c5fa4b64H8dd08c52

Aloca metade da RAM por uma questão de prioridade, mas os processos usam quando for estritamente necessário.
Pode conferir também com o comando free.


_________________________________________________________
Always listen the Buck!
Enquanto o cursor estiver pulsando, há vida!


7. Re: RKHUNTER encontrou uns arquivos suspeitos [RESOLVIDO]

Henrique
Henrique-RJ

(usa Outra)

Enviado em 25/10/2024 - 16:21h


Buckminster escreveu:

Não consome metade da RAM, somente aloca o espaço e usa quando precisa, nem todos os programas utilizam o /dev/shm, como pode ver com o comando:

xxx@xxx:/dev/shm$ ls -lah

total 2,2M <<< veja o tamanho realmente ocupado na RAM
drwxrwxrwt 2 root root 100 out 25 16:16 .
drwxr-xr-x 17 root root 3,5K out 25 10:02 ..
-rw------- 1 postgres postgres 1,0M out 25 10:02 PostgreSQL.2005936928
-rw------- 1 postgres postgres 27K out 25 10:02 PostgreSQL.2040927740
-rw-r--r-- 1 root root 1,2M out 25 10:02 ShM.c5fa4b64H8dd08c52


_________________________________________________________
Always listen the Buck!
Enquanto o cursor estiver pulsando, há vida!




Entendi, se não é você a ajudar eu ia ficar sem saber como resolver essa pendenga.

Agradeço



_______________________________________________________
E viu-se um grande sinal no céu: uma mulher vestida do sol, tendo a lua debaixo dos seus pés, e uma coroa de doze estrelas sobre a sua cabeça. Apocalipse 12:1 Nsa Sra de Fátima, Nsa Sra de Lourdes, Nsa Sra das Graças ...
_______________________________________________________
São Padre Pio de Pietrelcina, Santa Faustina Kowalska, São Francisco de Assis e Santa Gema Galgani foram alguns dos que tiveram os milagres dos Estigmas de Cristo em seus corpos, Feridas que sangravam
_______________________________________________________
Milagre Eucarístico que ocorreu em uma Igreja de Lanciano na Itália no ano de 750 em que o vinho se tornou sangue e o pão carne humana estão até hoje intactos. https://pt.wikipedia.org/wiki/Milagre_eucar%C3%ADstico_de_Lanciano


8. Re: RKHUNTER encontrou uns arquivos suspeitos [RESOLVIDO]

Amarildo Sertorio dos Santos
amarildosertorio

(usa Fedora)

Enviado em 25/10/2024 - 17:58h

Falsos positivos são um dos desafios enfrentados pelos times de SOC.







Patrocínio

Site hospedado pelo provedor RedeHost.
Linux banner

Destaques

Artigos

Dicas

Tópicos

Top 10 do mês

Scripts