Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

Once I finally figured out all of life's answers, they changed the questions.


dovenet / Synchronet Discussion / Malwarebytes reports trojan

SubjectAuthor
* Malwarebytes reports trojanDumas Walker
`* Malwarebytes reports trojanMRO
 +* Malwarebytes reports trojDumas Walker
 |`- Malwarebytes reports trojMRO
 `* Malwarebytes reports trojDumas Walker
  `* Malwarebytes reports trojMRO
   `* Malwarebytes reports trojDumas Walker
    `- Malwarebytes reports trojMRO

1
Malwarebytes reports trojan

<65ABE9C6.70177.sync@capcity2.synchro.net>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=1946&group=DOVE-Net.Synchronet_Discussion#1946

  copy link   Newsgroups: DOVE-Net.Synchronet_Discussion
From: dumas.walker@VERT/CAPCITY2 (Dumas Walker)
To: All
Subject: Malwarebytes reports trojan
Message-ID: <65ABE9C6.70177.sync@capcity2.synchro.net>
Date: Sat, 20 Jan 2024 10:41:58 -0500
X-Comment-To: All
Path: rocksolidbbs.com!not-for-mail
Organization: Capitol City Online
Newsgroups: DOVE-Net.Synchronet_Discussion
X-FTN-PID: Synchronet 3.19c-Linux master/cb76b1463 Feb 20 2022 GCC 7.5.0
X-FTN-MSGID: 70177.sync@723:320/1 2a1231e7
X-FTN-CHRS: CP437 2
WhenImported: 20240120105659-0800 41e0
WhenExported: 20240120141336-0800 41e0
ExportedFrom: VERT sync 51054
WhenImported: 20240120104158-0500 412c
WhenExported: 20240120135663-0500 412c
ExportedFrom: CAPCITY2 sync 70177
Content-Type: text/plain; charset=IBM437
Content-Transfer-Encoding: 8bit
 by: Dumas Walker - Sat, 20 Jan 2024 15:41 UTC

A couple of weeks ago, one of my users reported that his Malwarebytes was
warning him of a potential Trojan when he tried to connect here via telnet. At
the time, I assumed it was because I have iptables set up to redirect the port
from 23 to the "non root" port that Syncrhonet is listening on.

However, I have since had a fellow sysop who connects here to exchange mail
report the same thing. Because the bink port that binkit listens on is not a
"needs root" port, I don't have that one redirected by iptables. He also tried
it via telnet and sent me the error message. I cannot see what Trojan it
thinks is on this end -- I don't think the message says.

I have asked him to resend the message as text so I can share it. Malwarebytes
was actually blocking our systems from exchanging mail.

I did scan with ClamAV and all it reports are some "potentially unwanted
applications" -- some DOS programs in my download directories that are
apparently compressed with PKlite.

As I only have linux machines, I don't have any experience with Malwarebytes.
Has anyone else run into this -- is it a case of Malwarebytes just not liking
BBSes or something else?

Thanks!
#

---
■ Synchronet ■ CAPCITY2 * capcity2.synchro.net * Telnet/SSH:2022/Rlogin/HTTP

Malwarebytes reports trojan

<65AD083E.9797.sync@bbses.info>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=1948&group=DOVE-Net.Synchronet_Discussion#1948

  copy link   Newsgroups: DOVE-Net.Synchronet_Discussion
From: mro@VERT/BBSESINF (MRO)
To: Dumas Walker
Subject: Malwarebytes reports trojan
Message-ID: <65AD083E.9797.sync@bbses.info>
Date: Sun, 21 Jan 2024 06:04:14 -0600
X-Comment-To: Dumas Walker
Path: rocksolidbbs.com!not-for-mail
Organization: bbses.info
Newsgroups: DOVE-Net.Synchronet_Discussion
In-Reply-To: <65ABE9C6.70177.sync@capcity2.synchro.net>
References: <65ABE9C6.70177.sync@capcity2.synchro.net>
X-FTN-PID: Synchronet 3.19b-Win32 master/a2a9dc027 Jan 2 2022 MSC 1928
X-FTN-MSGID: 51056.sync@1:103/705 2a130c6a
X-FTN-REPLY: 70177.sync@723:320/1 2a1231e7
X-FTN-CHRS: CP437 2
WhenImported: 20240121043258-0800 41e0
WhenExported: 20240121081329-0800 41e0
ExportedFrom: VERT sync 51056
WhenImported: 20240121060414-0600 4168
WhenExported: 20240121063255-0600 4168
ExportedFrom: BBSESINF sync 9797
Content-Type: text/plain; charset=IBM437
Content-Transfer-Encoding: 8bit
 by: MRO - Sun, 21 Jan 2024 12:04 UTC

Re: Malwarebytes reports trojan
By: Dumas Walker to All on Sat Jan 20 2024 10:41 am

>
> As I only have linux machines, I don't have any experience with
> Malwarebytes. Has anyone else run into this -- is it a case of Malwarebytes
> just not liking BBSes or something else?
>

it sounds like he's using the trial version or the paid version where you have more features. honestly it's just overkill unless you really ARE infected and you want to try to clean out your system.

i would install it to try on your system bu it's become so convoluted i wont want it on my systems.
---
■ Synchronet ■ ::: BBSES.info - free BBS services :::

Malwarebytes reports troj

<65AD3370.70181.sync@capcity2.synchro.net>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=1949&group=DOVE-Net.Synchronet_Discussion#1949

  copy link   Newsgroups: DOVE-Net.Synchronet_Discussion
From: dumas.walker@VERT/CAPCITY2 (Dumas Walker)
To: MRO
Subject: Malwarebytes reports troj
Message-ID: <65AD3370.70181.sync@capcity2.synchro.net>
Date: Sun, 21 Jan 2024 09:49:00 -0500
X-Comment-To: MRO
Path: rocksolidbbs.com!not-for-mail
Organization: Capitol City Online
Newsgroups: DOVE-Net.Synchronet_Discussion
In-Reply-To: <65AD083E.9797.sync@bbses.info>
References: <65AD083E.9797.sync@bbses.info>
X-FTN-PID: Synchronet 3.19c-Linux master/cb76b1463 Feb 20 2022 GCC 7.5.0
X-FTN-MSGID: 70181.sync@723:320/1 2a137b95
X-FTN-REPLY: 51056.sync@1:103/705 2a130c6a
X-FTN-CHRS: ASCII 1
WhenImported: 20240121105700-0800 41e0
WhenExported: 20240121141336-0800 41e0
ExportedFrom: VERT sync 51058
WhenImported: 20240121100832-0500 412c
WhenExported: 20240121135667-0500 412c
ExportedFrom: CAPCITY2 sync 70181
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 8bit
 by: Dumas Walker - Sun, 21 Jan 2024 14:49 UTC

> > As I only have linux machines, I don't have any experience with
> > Malwarebytes. Has anyone else run into this -- is it a case of Malwarebytes
> > just not liking BBSes or something else?

> it sounds like he's using the trial version or the paid version where you have
> ore features. honestly it's just overkill unless you really ARE infected and
> u want to try to clean out your system.

I think it is the paid version.

> i would install it to try on your system bu it's become so convoluted i wont w
> t it on my systems.

Isn't Malwarebytes a windows program?

* SLMR 2.1a * Tinnn Rooooooooof! --Rusted!

---
� Synchronet � CAPCITY2 * capcity2.synchro.net * Telnet/SSH:2022/Rlogin/HTTP

Malwarebytes reports troj

<65AD3370.70182.sync@capcity2.synchro.net>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=1950&group=DOVE-Net.Synchronet_Discussion#1950

  copy link   Newsgroups: DOVE-Net.Synchronet_Discussion
From: dumas.walker@VERT/CAPCITY2 (Dumas Walker)
To: ALL
Subject: Malwarebytes reports troj
Message-ID: <65AD3370.70182.sync@capcity2.synchro.net>
Date: Sun, 21 Jan 2024 09:54:00 -0500
X-Comment-To: ALL
Path: rocksolidbbs.com!not-for-mail
Organization: Capitol City Online
Newsgroups: DOVE-Net.Synchronet_Discussion
In-Reply-To: <65AD083E.9797.sync@bbses.info>
References: <65AD083E.9797.sync@bbses.info>
X-FTN-PID: Synchronet 3.19c-Linux master/cb76b1463 Feb 20 2022 GCC 7.5.0
X-FTN-MSGID: 70182.sync@723:320/1 2a137b96
X-FTN-REPLY: 51056.sync@1:103/705 2a130c6a
X-FTN-CHRS: ASCII 1
WhenImported: 20240121105700-0800 41e0
WhenExported: 20240121141336-0800 41e0
ExportedFrom: VERT sync 51059
WhenImported: 20240121100832-0500 412c
WhenExported: 20240121135667-0500 412c
ExportedFrom: CAPCITY2 sync 70182
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 8bit
 by: Dumas Walker - Sun, 21 Jan 2024 14:54 UTC

> As I only have linux machines, I don't have any experience with
> Malwarebytes. Has anyone else run into this -- is it a case of Malwarebytes
> just not liking BBSes or something else?

FYI, here is the message one of them is getting when trying to surf over
via the web (line wraped).

Location:
https://block.malwarebytes.com?lic=Licensed&cat=Trojan&lang=en&prod=MBAM-C&ver=4
..6.7.301&cpv=1.0.2222&upv=1.0.79814&ldr=290&ip=67.131.57.133&url=capitolcityonli
ne.net
Connection: close

Website blocked due to a Trojan

Your Malwarebytes Premium blocked this website because it may contain a Trojan.

The main thing I am concerned about is that any Windows sysop who runs
Malwarebytes Premium probably thinks that their connections have "gone
down" when in reality Malwarebytes is rerouting the outbound traffic to a
"127." address, and blocking the inbound traffic, to their hub or node.

* SLMR 2.1a * AAAAA - American Association Against Acronym Abuse

---
� Synchronet � CAPCITY2 * capcity2.synchro.net * Telnet/SSH:2022/Rlogin/HTTP

Malwarebytes reports troj

<65AD7C0A.9801.sync@bbses.info>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=1951&group=DOVE-Net.Synchronet_Discussion#1951

  copy link   Newsgroups: DOVE-Net.Synchronet_Discussion
From: mro@VERT/BBSESINF (MRO)
To: Dumas Walker
Subject: Malwarebytes reports troj
Message-ID: <65AD7C0A.9801.sync@bbses.info>
Date: Sun, 21 Jan 2024 14:18:18 -0600
X-Comment-To: Dumas Walker
Path: rocksolidbbs.com!not-for-mail
Organization: bbses.info
Newsgroups: DOVE-Net.Synchronet_Discussion
In-Reply-To: <65AD3370.70181.sync@capcity2.synchro.net>
References: <65AD3370.70181.sync@capcity2.synchro.net>
X-FTN-PID: Synchronet 3.19b-Win32 master/a2a9dc027 Jan 2 2022 MSC 1928
X-FTN-MSGID: 51060.sync@1:103/705 2a137dd3
X-FTN-REPLY: 70181.sync@723:320/1 2a137b95
X-FTN-CHRS: CP437 2
WhenImported: 20240121123647-0800 41e0
WhenExported: 20240121141336-0800 41e0
ExportedFrom: VERT sync 51060
WhenImported: 20240121141818-0600 4168
WhenExported: 20240121143645-0600 4168
ExportedFrom: BBSESINF sync 9801
Content-Type: text/plain; charset=IBM437
Content-Transfer-Encoding: 8bit
 by: MRO - Sun, 21 Jan 2024 20:18 UTC

Re: Malwarebytes reports troj
By: Dumas Walker to MRO on Sun Jan 21 2024 09:49 am

> > i would install it to try on your system bu it's become so convoluted i
> > wont w
> > t it on my systems.
>
> Isn't Malwarebytes a windows program?
>

yeah it is. it used to be good back in the day. i installed it in the middle of last year and it was just to convoluted and annoying to run.

i supposed if you download a lot of viruses it would be useful.
---
■ Synchronet ■ ::: BBSES.info - free BBS services :::

Malwarebytes reports troj

<65AD9B8F.9802.sync@bbses.info>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=1952&group=DOVE-Net.Synchronet_Discussion#1952

  copy link   Newsgroups: DOVE-Net.Synchronet_Discussion
From: mro@VERT/BBSESINF (MRO)
To: Dumas Walker
Subject: Malwarebytes reports troj
Message-ID: <65AD9B8F.9802.sync@bbses.info>
Date: Sun, 21 Jan 2024 16:32:47 -0600
X-Comment-To: Dumas Walker
Path: rocksolidbbs.com!not-for-mail
Organization: bbses.info
Newsgroups: DOVE-Net.Synchronet_Discussion
In-Reply-To: <65AD3370.70182.sync@capcity2.synchro.net>
References: <65AD3370.70182.sync@capcity2.synchro.net>
X-FTN-PID: Synchronet 3.19b-Win32 master/a2a9dc027 Jan 2 2022 MSC 1928
X-FTN-MSGID: 51061.sync@1:103/705 2a13a3c5
X-FTN-REPLY: 70182.sync@723:320/1 2a137b96
X-FTN-CHRS: CP437 2
WhenImported: 20240121151840-0800 41e0
WhenExported: 20240121201328-0800 41e0
ExportedFrom: VERT sync 51061
WhenImported: 20240121163247-0600 4168
WhenExported: 20240121171838-0600 4168
ExportedFrom: BBSESINF sync 9802
Content-Type: text/plain; charset=IBM437
Content-Transfer-Encoding: 8bit
 by: MRO - Sun, 21 Jan 2024 22:32 UTC

Re: Malwarebytes reports troj
By: Dumas Walker to ALL on Sun Jan 21 2024 09:54 am

> https://block.malwarebytes.com?lic=Licensed&cat=Trojan&lang=en&prod=M
> BAM-C&ver=4 .6.7.301&cpv=1.0.2222&upv=1.0.79814&ldr=290&ip=67.131.57.133&url
> =capitolcityonl i
> ne.net
> Connection: close

it's also possible that your ip got blacklisted by malwarebytes.
you could have got scanned by one of those shitty port scanners and you got put on a list for being compromised and malwarebytes used the list.

you can contact malwarebytes and try to get it removed.
---
■ Synchronet ■ ::: BBSES.info - free BBS services :::

Malwarebytes reports troj

<65AE7D88.70188.sync@capcity2.synchro.net>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=1956&group=DOVE-Net.Synchronet_Discussion#1956

  copy link   Newsgroups: DOVE-Net.Synchronet_Discussion
From: dumas.walker@VERT/CAPCITY2 (Dumas Walker)
To: MRO
Subject: Malwarebytes reports troj
Message-ID: <65AE7D88.70188.sync@capcity2.synchro.net>
Date: Mon, 22 Jan 2024 09:28:00 -0500
X-Comment-To: MRO
Path: rocksolidbbs.com!not-for-mail
Organization: Capitol City Online
Newsgroups: DOVE-Net.Synchronet_Discussion
In-Reply-To: <65AD9B8F.9802.sync@bbses.info>
References: <65AD9B8F.9802.sync@bbses.info>
X-FTN-PID: Synchronet 3.19c-Linux master/cb76b1463 Feb 20 2022 GCC 7.5.0
X-FTN-MSGID: 70188.sync@723:320/1 2a14c5b4
X-FTN-REPLY: 51061.sync@1:103/705 2a13a3c5
X-FTN-CHRS: ASCII 1
WhenImported: 20240122105704-0800 41e0
WhenExported: 20240122141332-0800 41e0
ExportedFrom: VERT sync 51065
WhenImported: 20240122093656-0500 412c
WhenExported: 20240122135709-0500 412c
ExportedFrom: CAPCITY2 sync 70188
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 8bit
 by: Dumas Walker - Mon, 22 Jan 2024 14:28 UTC

>it's also possible that your ip got blacklisted by malwarebytes.
>you could have got scanned by one of those shitty port scanners and you got put
>on a list for being compromised and malwarebytes used the list.

That is what I also suspect.

* SLMR 2.1a * Halloween is *not* Christmas, even though 31 oct = 25 dec

---
� Synchronet � CAPCITY2 * capcity2.synchro.net * Telnet/SSH:2022/Rlogin/HTTP

Malwarebytes reports troj

<65AEF0E8.9807.sync@bbses.info>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=1958&group=DOVE-Net.Synchronet_Discussion#1958

  copy link   Newsgroups: DOVE-Net.Synchronet_Discussion
From: mro@VERT/BBSESINF (MRO)
To: Dumas Walker
Subject: Malwarebytes reports troj
Message-ID: <65AEF0E8.9807.sync@bbses.info>
Date: Mon, 22 Jan 2024 16:49:12 -0600
X-Comment-To: Dumas Walker
Path: rocksolidbbs.com!not-for-mail
Organization: bbses.info
Newsgroups: DOVE-Net.Synchronet_Discussion
In-Reply-To: <65AE7D88.70188.sync@capcity2.synchro.net>
References: <65AE7D88.70188.sync@capcity2.synchro.net>
X-FTN-PID: Synchronet 3.19b-Win32 master/a2a9dc027 Jan 2 2022 MSC 1928
X-FTN-MSGID: 51067.sync@1:103/705 2a14f2cc
X-FTN-REPLY: 70188.sync@723:320/1 2a14c5b4
X-FTN-CHRS: CP437 2
WhenImported: 20240122150801-0800 41e0
WhenExported: 20240122201334-0800 41e0
ExportedFrom: VERT sync 51067
WhenImported: 20240122164912-0600 4168
WhenExported: 20240122170759-0600 4168
ExportedFrom: BBSESINF sync 9807
Content-Type: text/plain; charset=IBM437
Content-Transfer-Encoding: 8bit
 by: MRO - Mon, 22 Jan 2024 22:49 UTC

Re: Malwarebytes reports troj
By: Dumas Walker to MRO on Mon Jan 22 2024 09:28 am

> >it's also possible that your ip got blacklisted by malwarebytes.
> >you could have got scanned by one of those shitty port scanners and you got
> put
> >on a list for being compromised and malwarebytes used the list.
>
> That is what I also suspect.
>
>

the reason why that popped in my head is stuff like this happened to me more than a few times over the years, especially when i was running my servers off a residential ip address.
---
■ Synchronet ■ ::: BBSES.info - free BBS services :::

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor