https://labs.parabola.nu/https://labs.parabola.nu/favicon.ico?15367742552020-03-03T15:09:58ZParabola Issue TrackerPackages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=138522020-03-03T15:09:58Zfreemor
<ul></ul><p>Most likely a transient false positive. Can not reproduce.<br />Are you on i686 or arm? I haven't tried to reproduce on those yet.</p>
<p>As it is just a large ASCII cpio archive a false positive is more than possible.</p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=138532020-03-03T15:29:02ZGNUtooGNUtoo@cyberdimension.org
<ul></ul><p>I've tried on i686.</p>
<p>It's could also have fixed between the time you last updated your local malware database and the time I did the same.</p>
<p>I've done:<br /><pre>
sudo freshclam
pkgfile -u
clamscan /var/cache/pkgfile/community.files
</pre></p>
<p>And I've the following result:<br /><pre>
/var/cache/pkgfile/community.files: OK
----------- SCAN SUMMARY -----------
Known viruses: 6759120
Engine version: 0.101.2
Scanned directories: 0
Scanned files: 1
Infected files: 0
Data scanned: 0.00 MB
Data read: 146.79 MB (ratio 0.00:1)
Time: 161.971 sec (2 m 41 s)
</pre></p>
<p>Could you try after re-updating the malware database with freshclam?</p>
<p>By the way do you know if there is an easy way to update that database without giving root access to freshclam?</p>
<p>PS: Most of the time I don't agree network terms of services for things like WiFi when they prevent you from sending or transmitting viruses as there are legitimate cases where for instance you might want to send a virus sample to clamav, which is free software.</p>
<p>PPS: It would be an interesting project to use sandboxing for clamscan as in general programs like antivirus are parsing a lot of untrusted files. It has been done by the tracker project which is a project to parse and index files.</p>
<p>Denis.</p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=138552020-03-03T15:38:14Zfreemor
<ul></ul><p>clamscan can be easily sandboxed with firejail <br />it even comes with a pre-defined clamscan profile.</p>
<p>I'll take a look at updating clamscan as I can build for all archs</p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=138572020-03-03T15:50:07Zlibreuser
<ul></ul><p><a class="external" href="https://www.virustotal.com/gui/file/f54b012dd91f6cbdde351a5d334ef7518017d630e5c0a3f6f8f1f95ddd8f682f/detection">https://www.virustotal.com/gui/file/f54b012dd91f6cbdde351a5d334ef7518017d630e5c0a3f6f8f1f95ddd8f682f/detection</a></p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=138582020-03-03T15:57:13Zlibreuser
<ul></ul><p>CPU: x86_64</p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=138592020-03-03T18:05:12Zfreemor
<ul></ul><p>Well thats what I'm on and I am getting the same non-result as GNUtoo</p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=138602020-03-03T18:33:50Zfreemor
<ul></ul><p>from your Virustotal link it is definitely looking like a false positive,</p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=138742020-03-04T18:40:03Zlibreuser
<ul></ul><p>I think most virus scanners don't scan huge files like this. :/</p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=138752020-03-04T21:28:32Zfreemor
<ul></ul><p>The chances of this being an acutal virus are very low.</p>
<ul>
<li>Win.Trojan.Maljava-2 - Would indicate a Windows malware </li>
<li>The file is a just a huge ASCII file. so not executeable</li>
<li>The file is a fairly trivial format (cpio archive) so it's doubtful that there a flaw in the extractor</li>
<li>The file merely contains a bunch of text file named for packages which list the files/directories in thos packages</li>
<li>Java has nothing to do with this file in the normal rource of things (cause it's not a jar, cause it's not exectuable)</li>
</ul>
<p>The Chance of a false positive is high.</p>
<ul>
<li>All that is needed for a false positive is for there to be a string that matches what the IOC sting for that malware</li>
<li>with 170 MB of strings to look at it wouldn't take much</li>
</ul>
<p>if you still have the "Infected" file there are ways you could track down where the false positive is matching but that is a longer discussion.</p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=138762020-03-04T21:39:48Zfreemor
<ul></ul><p>Although if malware did by some fluke get injected in that cpio archive it'd be a very interesting find :)</p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=138772020-03-04T21:55:44Zfreemor
<ul></ul><p>And it looks like it has false positived in the past too.</p>
<p><a class="external" href="https://github.com/falconindy/pkgfile/issues/46">https://github.com/falconindy/pkgfile/issues/46</a></p>
<p>An it looks like there is a history of Clamav Falsing on this particular detection:</p>
<p><a class="external" href="http://www.edison-newworld.com/2017/04/clamav-false-positive-on-java-malware.html">http://www.edison-newworld.com/2017/04/clamav-false-positive-on-java-malware.html</a></p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=138782020-03-04T22:04:33Zfreemor
<ul><li><strong>Status</strong> changed from <i>unconfirmed</i> to <i>not-a-bug</i></li></ul> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=142282020-04-30T00:44:55Zbill-auger
<ul></ul><p>the proper thing to do of course, is to notify the maintainers of the virus scan program of this recurring false positive, and sending them an example pkgfile list which triggered it</p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=142292020-04-30T01:28:59Zlibreuser
<ul></ul><p>I already did. I mean I reported it on the clamav website <a class="external" href="https://www.clamav.net/reports/fp">https://www.clamav.net/reports/fp</a></p>
<p>Probably; twice. :)</p> Packages - Privacy Issue #2646: Win.Trojan.Maljava-2 FOUNDhttps://labs.parabola.nu/issues/2646?journal_id=142322020-04-30T03:06:33Zbill-auger
<ul></ul><p>for most bug reports, the arch and init information is usually not important - it gave me an idea though, to add that information to an optional post signature, definable in the user profile <a class="external" href="https://labs.parabola.nu/issues/2715">https://labs.parabola.nu/issues/2715</a></p>