Re: [CentOS] ClamAV reports a trojan

2015-04-19 Thread James B. Byrne
On Sat, April 18, 2015 11:16, Jake Shipton wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 16/04/15 16:01, James B. Byrne wrote: This morning I discovered this in my clamav report from one of our imap servers: /usr/share/nmap/scripts/irc-unrealircd-backdoor.nse:

Re: [CentOS] ClamAV reports a trojan

2015-04-18 Thread Jake Shipton
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 16/04/15 16:01, James B. Byrne wrote: This morning I discovered this in my clamav report from one of our imap servers: /usr/share/nmap/scripts/irc-unrealircd-backdoor.nse: Unix.Trojan.MSShellcode-21 FOUND I have looked at this script

[CentOS] ClamAV reports a trojan

2015-04-16 Thread James B. Byrne
This morning I discovered this in my clamav report from one of our imap servers: /usr/share/nmap/scripts/irc-unrealircd-backdoor.nse: Unix.Trojan.MSShellcode-21 FOUND I have looked at this script and it appears to be part of the nmap distribution. It actually tests for irc backdoors. IRC is

Re: [CentOS] ClamAV reports a trojan

2015-04-16 Thread Les Mikesell
On Thu, Apr 16, 2015 at 10:01 AM, James B. Byrne byrn...@harte-lyne.ca wrote: This morning I discovered this in my clamav report from one of our imap servers: /usr/share/nmap/scripts/irc-unrealircd-backdoor.nse: Unix.Trojan.MSShellcode-21 FOUND I have looked at this script and it appears

Re: [CentOS] ClamAV reports a trojan

2015-04-16 Thread Valeri Galtsev
On Thu, April 16, 2015 10:09 am, Les Mikesell wrote: On Thu, Apr 16, 2015 at 10:01 AM, James B. Byrne byrn...@harte-lyne.ca wrote: This morning I discovered this in my clamav report from one of our imap servers: /usr/share/nmap/scripts/irc-unrealircd-backdoor.nse: Unix.Trojan.MSShellcode-21