[Rkhunter-users] Potential rootkit warning, regarding systemd...
Brought to you by:
dogsbody
From: <ks...@gm...> - 2021-08-19 10:38:03
|
<html><head></head><body><div style="font-family: Verdana;font-size: 12.0px;"><div>Hello,</div> <div>I've got a Linux Server (openSUSE 15.2) that suddenly showed a suspicious warning during the night after a timed rkhunter scan (cron job), the days before it was quite.</div> <div>There was no update on the machine before, no reboot or something like that...</div> <div> </div> <div>RKHunter shows a warning about 'systemd' as a possible rootkit, can anybody help me with that?</div> <div>Any hints how I could verify what that means?</div> <div>Is there a known false positive relating to that message or something like that?</div> <div> </div> <div> </div> <div>Running Rootkit Hunter version 1.4.6 (updated):</div> <div> </div> <div>...</div> <div>[04:06:33] Info: Starting test name 'malware'<br/> [04:06:33] Performing malware checks<br/> [04:06:33]<br/> [04:06:33] Info: Test 'deleted_files' disabled at users request.<br/> [04:06:33]<br/> [04:06:33] Info: Starting test name 'running_procs'<br/> [04:06:50] Checking running processes for suspicious files [ Warning ]<br/> [04:06:50] Warning: The following processes are using suspicious files:<br/> [04:06:50] Command: systemd<br/> [04:06:50] UID: 0 PID: 1<br/> [04:06:50] Pathname:<br/> [04:06:50] Possible Rootkit: Unknown rootkit<br/> [04:06:50]<br/> [04:06:50] Info: Test 'hidden_procs' disabled at users request.<br/> [04:06:50]<br/> [04:06:50] Info: Test 'suspscan' disabled at users request.<br/> [04:06:50]<br/> [04:06:50] Info: Starting test name 'login_backdoors'<br/> [04:06:50] Checking for '/bin/.login' [ Not found ]<br/> [04:06:50] Checking for '/sbin/.login' [ Not found ]<br/> [04:06:50] Checking for login backdoors [ None found ]<br/> ...</div> <div> </div> <div>Thanks for any help!</div> <div> </div> <div>Bye</div> <div>Kristof S.</div> <div> </div> <div> </div> <div class="signature"> </div></div></body></html> |