I am seeing this too. In our case I believe it is related to our Oracle cluster's heartbeat since it is only occurring on those servers. Not sure if that helps you any though.
-----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of x509v3 Sent: Friday, November 19, 2010 12:08 AM To: ossec-list Subject: [ossec-list] Anyone seeing false positives like this? : Port '60256'(tcp) hidden. Kernel-level rootkit or trojaned version of netstat. Hi, been running ossec for about a month now, after testing for another month. Tonight I received the following from one my production machines: OSSEC HIDS Notification. 2010 Nov 18 19:36:56 Received From: (host) 10.1.1.1->rootcheck Rule: 510 fired (level 7) -> "Host-based anomaly detection event (rootcheck)." Portion of the log(s): Port '60256'(tcp) hidden. Kernel-level rootkit or trojaned version of netstat. --END OF NOTIFICATION Host 10.1.1.1 is an IBM PowerPC host running AIX. I've seen this type of alert on my mac at home (PowerPC running 10.4), every once in a while. I confirmed from the Mac install DVD that the latter was a false positive. It's likely that this alert is a false positive too, but taking it offline isn't really an option unless we're sure there's an issue. Unfortunately, alerts like this trigger a mandatory incident response and be disruptive, so many false alarms will not be good. Anyone else seeing netstat-related false alarms list this?
