Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Minishift detected as malware #2912

Closed
sobkowiak opened this issue Oct 22, 2018 · 3 comments
Closed

Minishift detected as malware #2912

sobkowiak opened this issue Oct 22, 2018 · 3 comments

Comments

@sobkowiak
Copy link

sobkowiak commented Oct 22, 2018

General information

  • Minishift version: 1.25.0
  • OS: Windows
  • Hypervisor: VirtualBox

Steps to reproduce

  1. Invoke any command using minishift

Expected

Command successfully invoked

Actual

Each time following window is opened by Symantec

grafik

It looks like the latest executable is no more signed

grafik

The previous versions were signed by Red Hat

grafik

The executable is now detected as malware. I have got following email from my security department

SOC team noticed Command and Control domain ummydownloader.com detected for user : ksobkowi and last ip address of system is 10.42.16.43

PFB details of malicious connection.

Endpoint : CE16231

Malicious Files
File Name : minishift.exe
Path : c:\trainings\ocp
Certificate : Not Available
Blocked : No

SOC recommendations:

Kindly contact onsite support team to delete the malicious file and perform below actions:

- Make sure  system has updated with latest Antivirus Signature and Version  
- Make sure system has updated with latest Microsoft patches.
- Remove malicious software’s from system if any.
- Run full system scan and make sure there is no infection.

Was it intended that the executable is no more signed?

@praveenkumar
Copy link
Contributor

closed in favor of #2914

@praveenkumar
Copy link
Contributor

closed in favor of #2914

@praveenkumar
Copy link
Contributor

praveenkumar commented Oct 22, 2018 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants