From owner-freebsd-questions@freebsd.org Mon Nov 26 08:13:18 2018 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 2C9E41151082 for ; Mon, 26 Nov 2018 08:13:18 +0000 (UTC) (envelope-from 4250.10.freebsd-questions=freebsd.org@email-od.com) Received: from s1-b0c6.socketlabs.email-od.com (s1-b0c6.socketlabs.email-od.com [142.0.176.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 6EEB98C684 for ; Mon, 26 Nov 2018 08:13:17 +0000 (UTC) (envelope-from 4250.10.freebsd-questions=freebsd.org@email-od.com) DKIM-Signature: v=1; a=rsa-sha256; d=email-od.com;i=@email-od.com;s=dkim; c=relaxed/relaxed; q=dns/txt; t=1543219997; x=1545811997; h=content-transfer-encoding:content-type:mime-version:references:in-reply-to:message-id:subject:cc:to:from:date:x-thread-info; bh=04nDkCZroPbR5QDSI34YmjwEAY0b8oCYBF7i5xOYY7k=; b=XZHfNcwEb0OGyFD2BCLbja2/Hc3VPlRlPKhudFw1OCFdYhLHvSmpyJvO0YfgvmgLZdj4FSBfeVAyU6u00PwQKfzfP7RlWx3XwmAbn9CxNo0mHxPe/gXIFiErGtdChhOoBR8lbpbut+sSLIbD+SfYn08eoKkOvVQ41FDxMKuX73E= X-Thread-Info: NDI1MC4xMi4xYTEwMDAwMDBjZDM5M2EuZnJlZWJzZC1xdWVzdGlvbnM9ZnJlZWJzZC5vcmc= Received: from r4.us-east.aws.in.socketlabs.com (r4.us-east.aws.in.socketlabs.com [52.5.202.82]) by mxsg2.email-od.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Mon, 26 Nov 2018 03:13:12 -0500 Received: from smtp.lan.sohara.org (EMTPY [89.127.62.20]) by r4.us-east.aws.in.socketlabs.com with ESMTP(version=Tls12 cipher=Aes256 bits=256); Mon, 26 Nov 2018 03:13:12 -0500 Received: from [192.168.63.1] (helo=steve.lan.sohara.org) by smtp.lan.sohara.org with smtp (Exim 4.91 (FreeBSD)) (envelope-from ) id 1gRC10-0002T2-R0; Mon, 26 Nov 2018 08:13:10 +0000 Date: Mon, 26 Nov 2018 08:13:10 +0000 From: Steve O'Hara-Smith To: freebsd-questions@freebsd.org Cc: Paul Schmehl Subject: Re: New Virus that targets *.nix Message-Id: <20181126081310.026376ddcaad286971909626@sohara.org> In-Reply-To: <948738C25BB780D76F9A2A5A@Pauls-MacBook-Pro.local> References: <948738C25BB780D76F9A2A5A@Pauls-MacBook-Pro.local> X-Mailer: Sylpheed 3.7.0 (GTK+ 2.24.32; amd64-portbld-freebsd11.1) X-Clacks-Overhead: "GNU Terry Pratchett" Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Rspamd-Queue-Id: 6EEB98C684 X-Spamd-Result: default: False [-2.86 / 15.00]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-0.996,0]; R_DKIM_ALLOW(-0.20)[email-od.com]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; R_SPF_ALLOW(-0.20)[+ip4:142.0.176.0/20]; MV_CASE(0.50)[]; MIME_GOOD(-0.10)[text/plain]; DMARC_NA(0.00)[sohara.org]; FORGED_SENDER_VERP_SRS(0.00)[]; NEURAL_HAM_LONG(-0.99)[-0.989,0]; RCVD_COUNT_THREE(0.00)[4]; TO_MATCH_ENVRCPT_SOME(0.00)[]; DKIM_TRACE(0.00)[email-od.com:+]; MX_GOOD(-0.01)[cached: mxbh.socketlabs.com]; RCVD_IN_DNSWL_NONE(0.00)[198.176.0.142.list.dnswl.org : 127.0.15.0]; NEURAL_HAM_SHORT(-0.69)[-0.695,0]; ENVFROM_VERP(0.00)[]; FORGED_SENDER(0.00)[steve@sohara.org,4250.10.freebsd-questions=freebsd.org@email-od.com]; RCPT_COUNT_TWO(0.00)[2]; RCVD_TLS_LAST(0.00)[]; IP_SCORE(-0.17)[ip: (-0.39), ipnet: 142.0.176.0/22(-0.20), asn: 7381(-0.16), country: US(-0.09)]; ASN(0.00)[asn:7381, ipnet:142.0.176.0/22, country:US]; FROM_NEQ_ENVFROM(0.00)[steve@sohara.org,4250.10.freebsd-questions=freebsd.org@email-od.com]; MID_RHS_MATCH_FROM(0.00)[] X-Rspamd-Server: mx1.freebsd.org X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 26 Nov 2018 08:13:18 -0000 On Sun, 25 Nov 2018 18:26:00 -0600 Paul Schmehl wrote: > Here's a copy of parts of the "virus": > > > 1) It uses /bin/bash. Won't work on FreeBSD unless you've > aliased /bin/bash to /usr/local/bin/bash. Why would you do that? > 2) Uses yum and apt-get to installed needed utilities. Neither exists on > FreeBSD. OK it's not well written - good! -- Steve O'Hara-Smith