ossec-hids icon indicating copy to clipboard operation
ossec-hids copied to clipboard

False positive : Trojaned version of file '/bin/diff' detected on Ubuntu 22

Open Nono-m0le opened this issue 3 years ago • 1 comments

Similar as https://github.com/ossec/ossec-hids/issues/2020 but for Ubuntu 22.04 LTS It follow an update from Ubuntu 20 to Ubuntu 22.

Rule: 510 (level 7) -> 'Host-based anomaly detection event (rootcheck).'
Trojaned version of file '/usr/bin/diff' detected. Signature used: 'bash|^/bin/sh|file\.h|proc\.h|/dev/[^n]|^/bin/.*sh' (Generic).

Nono-m0le avatar Jul 13 '22 10:07 Nono-m0le

I get the same log on 22.04 & Bullseye, seems others see the same thing on Arch and Fedora, so likely not OS-dependent since they all use the same GNU coreutils.

noahbailey avatar Aug 02 '22 17:08 noahbailey