You are not logged in.

#1 2022-02-28 22:49:33

ziomarco
Member
From: italy
Registered: 2018-09-09
Posts: 31

Clamav scan result

hello everybody,
today I ran clamav for the first time.

This is the result of the scan:

/home/user/.cache/mozilla/firefox/ff795j3p.default/cache2/entries/8451E98F85EBB8C00F67B1CB67F1C3C605B60905: PUA.Win.Tool.Packed-177 FOUND
/home/user/.cache/mozilla/firefox/ff795j3p.default/cache2/entries/1179BC32C3A3FC88B313DE336CF619103972B58E: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/user/.cache/mozilla/firefox/ff795j3p.default/cache2/entries/DDE0F9980EC4AACDA67CE58F2C9BD675E457413F: PUA.Win.Exploit.CVE_2012_1461-1 FOUND
/home/user/bk-win10/BACKUP_double_driver/Z83-V 25-03-2020 23-13-40/System/Microsoft Virtual Drive Enumerator/vdrvroot.sys: PUA.Win.Packer.Pequake-4 FOUND
/home/user/bk-win10/double_driver_4.1.0_portable/Double Driver/dd.exe: PUA.Win.Malware.Speedingupmypc-6718419-0 FOUND
/home/user/bk-win10/double_driver_4.1.0_portable/Double Driver/dd.dll: PUA.Win.Malware.Speedingupmypc-6718419-0 FOUND
/home/user/bk-win10/double_driver_4.1.0_portable/Double Driver/ddc.exe: PUA.Win.Malware.Speedingupmypc-6718419-0 FOUND
/home/user/.config/libreoffice/4/user/basic/Standard/Module1.xba: PUA.Doc.Tool.LibreOfficeMacro-2 FOUND
/home/user/Downloads/fineliner-wp/themeforest-6363903-fineliner-responsive-portfolio-wordpress-theme.zip: PUA.Win.Tool.Packed-177 FOUND
/home/user/Downloads/fineliner-wp/themeforest-6363903-fineliner-responsive-portfolio-wordpress-theme/Fineliner.zip: PUA.Win.Tool.Packed-177 FOUND
/home/user/Downloads/nouveau/plugins/LayerSlider.zip: PUA.Win.Tool.Packed-177 FOUND
/home/user/Downloads/themeforest-0AgmHetM-nouveau-multipurpose-retina-wordpress-theme-wordpress-theme.zip: PUA.Win.Tool.Packed-177 FOUND
/home/user/Downloads/themeforest-6363903-fineliner-responsive-portfolio-wordpress-theme.zip: PUA.Win.Tool.Packed-177 FOUND
/home/user/Downloads/themeforest-fBjq4AkC-nouveau-multipurpose-retina-wordpress-theme-wordpress-theme.zip: PUA.Win.Tool.Packed-177 FOUND
/home/user/Downloads/LiveYes_Setup_2.0.0.exe: PUA.Win.Malware.Speedingupmypc-6718419-0 FOUND
/home/user/Downloads/ML-1710_Win7_GDI.exe: PUA.Win.Packer.ArmadilloMinimumProtection-1 FOUND
/home/user/.wine/drive_c/windows/syswow64/kernel32.dll: PUA.Win.Packer.Ep-7 FOUND
/home/user/.wine/drive_c/windows/system32/kernel32.dll: PUA.Win.Packer.Ep-7 FOUND

----------- SCAN SUMMARY -----------
Known viruses: 8622448
Engine version: 0.104.2
Scanned directories: 11469
Scanned files: 50702
Infected files: 18
Data scanned: 8399.33 MB
Data read: 7260.77 MB (ratio 1.16:1)
Time: 9239.762 sec (153 m 59 s)
Start Date: 2022:02:28 20:23:52
End Date:   2022:02:28 22:57:52

I have read that PUA is not necessarily a threat, but I don't know what to do now...I'm afraid I have some problems anyway.
Some warnings are related to wordpress themes I that I have regularly purchased and installed on web sites that I developed...so i'm quite confused

Does anyone have to give me some advice?

Offline

#2 2022-02-28 23:35:25

loqs
Member
Registered: 2014-03-06
Posts: 18,982

Re: Clamav scan result

As the files are commercial my standard advise of submit it to www.virustotal.com may breach the license agreement.  Instead you could sha256sum the file and use that to see if it has already been submitted.

Offline

#3 2022-03-01 00:49:51

afader
Member
Registered: 2013-09-12
Posts: 207

Re: Clamav scan result

[deleted post]

Last edited by afader (2022-03-11 00:50:23)

Offline

#4 2022-03-01 15:50:45

mpan
Member
Registered: 2012-08-01
Posts: 1,621
Website

Re: Clamav scan result

afader:
Considering that they are likely to be run by wine: yes they can pose a threat, if that is indeed malware.

ziomarco:
In order:

  • All the “~/.cache/mozilla/” entries are Firefox cache. It has been present on websites and webapps you have visited. If that was ever to be executed, it has been in the past. Those files pose no threat anymore. The first one contains a piece of JavaScript decoding obfuscated payload. From the information available in this post it’s not possible to tell what it was decoding and executing or if the attack was successful. It is very likely a true positive. The other two are matching exploits against antivirus software from a decade ago. Likely true positive, but may match fancy archives with uncommon structure.⁽¹⁾ You may clear Firefox caches if it bothers you to see those files being reported.

  • “~/…/vdrvroot.sys”: a content obfuscator for Windows executables. Used either to deliver malware or to deter you from accessing “valuable intellectual property” in the file. Nearly certainly a true positive, as no such thing should be present in a file from Microsoft. That particular file is also common target for malware.

  • “~/bk-win10/double_driver_4.1.0_portable/Double Driver/*”: a variant of SpeedingUpMyPC. Certain true positive, based on an exact match to a large chunk of specific code and found in freeware. Unless you have explicitly agreed to have your system used for spamming, inflating clicks etc., this is malware.

  • “~/…/Module1.xba”: a generic detection of a macro. Unless you have a reason to think it shouldn’t be there: false positive.

  • The WordPress themes: the same as the files in the Firefox cache, a JavaScript that decodes obfuscated payload. Unlike with the cache files, which are not dangerous, that is going to be executed on the websites that use the theme. It’s not possible to tell, without inspecting the files, what exactly is being hidden. If you’re going to deploy that, the target may be either the visitors of your website, your WordPress login form, or your website (e.g. being turned into a link farm). Very likely a true positive.

  • “~/…/LiveYes_Setup_2.0.0.exe”: the same as for Double Driver, see above.

  • “~/…/ML-1710_Win7_GDI.exe”: similar to the “vdrvroot.sys”case above, but without a clear indication that it shouldn’t be there. The packer detection itself is a certain valid: an exact match on a large chunk of specific code.

  • The last two “kernel32.dll” files: seems a false positive. While a packer should certainly not be present in those files, the detection itself is based on a quite weak signature.

In this thread word “packer” appears multiple times. Note that there are various types of such tools with different purposes. In this case the important part is that those are obfuscators. For example UPX is also a packer, but its goal is making executables smaller. While in 2020s the usefullness of that tool is debatable⁽²⁾ and technically it can be used to make malware detection harder, its use is not by itself suspicious.

If you are willing to explore that yourself, ClamAV offers a tool named sigtool. To find a signature:

sigtool --find-sigs SIGNATURE_NAME

That raw output may be passed to `sigtool --decode` to print it in a format sometimes more readable to humans.⁽³⁾ ClamAV signature format documentation is available online. The rest is general knowledge, google-fu and experience.
____
⁽¹⁾ Story time: a few years ago I had to cut my ties with Kei.pl, because their antivirus was unable to scan one such an archive and was giving a warning. Since their workers were incapable of understand the AV output, threatened me with blocking the domain and bouncing me off meat-bots, the only option became moving elsewhere.
⁽²⁾ Saves a negligible fraction of modern storage media and has small impact on loading times, but increases memory usage.
⁽³⁾ Equally often less readable.

Last edited by mpan (2022-03-01 16:21:16)

Offline

#5 2022-03-02 23:54:44

ziomarco
Member
From: italy
Registered: 2018-09-09
Posts: 31

Re: Clamav scan result

Thank you mpan,
Your reply is very helpful!!

I will delete fireox cache, same decision for  wine files and liveyes (no longer used).
For ml1710 (backup of old printer driver) and wordpress theme  I'll do further investigation...

In any case your suggestions about sigtools and explanations about packer are very valuable!

Offline

#6 2022-03-10 02:09:05

afader
Member
Registered: 2013-09-12
Posts: 207

Re: Clamav scan result

[deleted post]

Last edited by afader (2022-03-11 00:50:10)

Offline

#7 2022-03-10 14:49:26

mpan
Member
Registered: 2012-08-01
Posts: 1,621
Website

Re: Clamav scan result

afader: normally I avoid responding to such things, but in this case this is the second time in this thread you post a response indicating you are lacking the basic understanding of the subject and acting frivorously in a situation where it has direct and serious impact on someone’s security. If you do not have a slightest idea, what you are talking about, consider not doing that. I am not qualified to tell, what’s the drive behind your responses, and perhaps you’re truly believing you are actually helping someone, but you are not. You are putting them at risk by carelessly and ignorantly shrugging off results as false positives despite contrary has been shown.

Of course my analysis may be wrong⁽¹⁾ and it may be challenged: but the challenge must address specific shortcomings and use arguments that lie no lower in hierarchy than the analysis itself. A post, that is a mix of handwaving, clipping of signature name and extending it to unrelated cases,⁽²⁾ is not fulfilling those requirements.
____
⁽¹⁾ I spent only like three dozen minutes on it.
⁽²⁾ Which, coincidently, has also been covered by my explanation. So why are you even bringing that topic, if it’s already defused as a potential argument?

Last edited by mpan (2022-03-10 14:51:58)

Offline

#8 2022-03-10 22:29:57

afader
Member
Registered: 2013-09-12
Posts: 207

Re: Clamav scan result

[deleted post]

Last edited by afader (2022-03-11 00:50:00)

Offline

#9 2022-03-11 00:43:35

mpan
Member
Registered: 2012-08-01
Posts: 1,621
Website

Re: Clamav scan result

No, you do not have “similar signatures”. Your scan shows very different signatures, which bear zero resemblance to those reported by ziomarco. Due to how much they differ, I am fairly certain that you did not even check those. Instead you merely clipped their name as it suited you, took a prefix shared with ziomarco’s report, and assumed they are in some way related. They are not. That prefix comes from a taxonomy not built to reflect anything of importance to risk assessment, detection accuracy or threat type similarity. Signature names guidelines are publicly available, if anyone wishes to check for themselves.

In case this thread lacks more responses from me: I am not willing to participate in that any further, unless a specific thing is properly addressed. It would only create noise at this point and this is going nowhere.

To avoid confusion: this and two earlier posts of mine shouldn’t be treated as an opposition to quick heuristical approach. That’s a sane way of evaluating situation and I used it many times in similar threads. But it is trumped by even the most rudimentary analysis and, in presence of such, must be rejected.

Last edited by mpan (2022-03-11 00:57:48)

Offline

Board footer

Powered by FluxBB