[Bug 1968806] Re: Clamscan reports Unix.Tool.Pnscan-8031486-0 in 1.12+git20180612-2 pnscan version

2022-06-18 Thread Launchpad Bug Tracker
[Expired for pnscan (Ubuntu) because there has been no activity for 60 days.] ** Changed in: pnscan (Ubuntu) Status: Incomplete => Expired -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report.

Re: [Bug 1968806] Re: Clamscan reports Unix.Tool.Pnscan-8031486-0 in 1.12+git20180612-2 pnscan version

2022-04-19 Thread Bob Presswood
Pnscan was the only report. I've been looking over the summaries for Pnscan-8031486-0 at https://malware.prevasio.io/ and it's obvious that pnscan is used by multiple malware packages and even a miner. In no case are the ancillary files in the summaries present on my system. But if they were

[Bug 1968806] Re: Clamscan reports Unix.Tool.Pnscan-8031486-0 in 1.12+git20180612-2 pnscan version

2022-04-19 Thread Seth Arnold
The frog is definitely weird, but clamscan is almost certainly just reporting a tool that might be used by attackers. There's lots of those. Does it also report tcpdump? wireshark? ettercap? nc? telnet? nmap? socat? stunnel? Thanks -- You received this bug notification because you are a member

Re: [Bug 1968806] Re: Clamscan reports Unix.Tool.Pnscan-8031486-0 in 1.12+git20180612-2 pnscan version

2022-04-19 Thread Bob Presswood
But maybe you're thinking that there's malware which loads pnscan? If so, that's different. At the same time I'd be hesitant to reinstall pnscan to investigate that. On Tue, Apr 19, 2022 at 9:29 PM Bob Presswood wrote: > Hi, > > I'm familiar with Brendan Gregg, although I haven't been

Re: [Bug 1968806] Re: Clamscan reports Unix.Tool.Pnscan-8031486-0 in 1.12+git20180612-2 pnscan version

2022-04-19 Thread Bob Presswood
Hi, I'm familiar with Brendan Gregg, although I haven't been following him closely. I have admired his work and sometimes I regret not buying his books yet. If you have the impression that my concern is with some load issue, let me clarify. I have not been using pnscan for any purpose. I just

[Bug 1968806] Re: Clamscan reports Unix.Tool.Pnscan-8031486-0 in 1.12+git20180612-2 pnscan version

2022-04-19 Thread Seth Arnold
Hello, my guess is clamav is helpfully pointing out that the program exists at all; I doubt it has any intelligence beyond looking for a few markers for pnscan within files named pnscan. Diagnosing load issues takes a bit of work; I suggest starting with

[Bug 1968806] Re: Clamscan reports Unix.Tool.Pnscan-8031486-0 in 1.12+git20180612-2 pnscan version

2022-04-19 Thread Seth Arnold
** Information type changed from Private Security to Public Security ** Changed in: pnscan (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1968806 Title: