Since last update a week ago rkhunter report following Message:
Warning: Network TCP port 32982 is being used by /opt/sinusbot/sinusbot. Possible rootkit: Solaris Wanuk. Use the 'lsof -i' or 'netstat -an' command to check this.
netstat -anp | fgrep 32982 gives:
tcp 32 0 XXX.XXX.XXX.XXX:32982 104.18.40.220:443 CLOSE_WAIT
XXXX/sinusbot
It seems Sinusbot tryes to contact a me unknown server via HTTPS.
Even if there are no other hints for a rootkit on my server, I am a bit nervous now. Anyone else got this?
Greeting Frank
Warning: Network TCP port 32982 is being used by /opt/sinusbot/sinusbot. Possible rootkit: Solaris Wanuk. Use the 'lsof -i' or 'netstat -an' command to check this.
netstat -anp | fgrep 32982 gives:
tcp 32 0 XXX.XXX.XXX.XXX:32982 104.18.40.220:443 CLOSE_WAIT
XXXX/sinusbot
It seems Sinusbot tryes to contact a me unknown server via HTTPS.
Even if there are no other hints for a rootkit on my server, I am a bit nervous now. Anyone else got this?
Greeting Frank