The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

ClamAVConnector virus

Discussion in 'Security' started by LukeDouglas, Feb 11, 2016.

  1. LukeDouglas

    LukeDouglas Member

    Joined:
    Nov 22, 2010
    Messages:
    17
    Likes Received:
    1
    Trophy Points:
    3
    I got a very unusual alert from my antivirus program on an intrusion from what appears to be the Clam AntiVirus program.

    Code:
    Category: Intrusion Prevention
    Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
    2/11/2016 7:41:28 PM,High,An intrusion attempt by www.ATTACKINGDOMAINNAME.com was blocked.,Blocked,No Action Required,Fake App Attack: Fake Scan Webpage 4,No Action Required,No Action Required,"ATTACKINGDOMAINNAME (SERVERIP, 2082)",WEBSITEDOMAIN.EXT:2082/cpsess499112525/frontend/paper_lantern/clamavconnector/live_go.html?scan=pubhtml,"SCATMAN-DESKTOP (10.0.0.252, 53753)",www.ATTACKINGDOMAINNAME.com (198.1.81.235),"TCP, Port 2082"
    Network traffic from WEBSITEDOMAIN.EXT:2082/cpsess499112525/frontend/paper_lantern/clamavconnector/live_go.html?scan=pubhtml</b> matches the signature of a known attack.  The attack was resulted from \DEVICE\HARDDISKVOLUME3\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE.
    
    
    Can anyone tell me how this is happening and what I can do to
     
    #1 LukeDouglas, Feb 11, 2016
    Last edited by a moderator: Feb 12, 2016
  2. yasins

    yasins Registered

    Joined:
    Mar 5, 2014
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Root Administrator
    I have this error too.
    Antivirus software is Norton Security.
     
  3. quizknows

    quizknows Well-Known Member

    Joined:
    Oct 20, 2009
    Messages:
    940
    Likes Received:
    55
    Trophy Points:
    28
    cPanel Access Level:
    DataCenter Provider
    This seems like a likely false positive. I would guess it has known URLs for AV software like norton and clamav stored, and if it sees a URL with that name that is not the official site it could trigger IDS. This is most likely not a cPanel issue, probably a false positive from a feature meant to protect people from all the fake AV scam websites.
     
  4. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,678
    Likes Received:
    648
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    Hello :)

    The URL in question is not abnormal. You could review /usr/local/cpanel/logs/access_log to verify if the offending IP address is a known user (e.g. there are previous safe entries under that IP).

    Thank you.
     
Loading...

Share This Page