Uploaded image for project: 'Apache Drill'
  1. Apache Drill
  2. DRILL-7484

Malware found with some antiviruses in the Drill test resources folder

VotersWatch issueWatchersLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Blocker
    • Resolution: Fixed
    • 1.17.0
    • 1.17.0
    • None

    Description

      Avast antivirus found Threat "MPPT97:ShellCode-O [Expl]" in the Apache Drill sources.

      File with virus alert:
      https://github.com/apache/drill/commits/master/exec/java-exec/src/test/resources/store/pcap/attack-trace.pcap

      OS Windows 10.
      Free Avast antivirus v. 19.8.2393 (build 19.8.4793.544)

      Steps to reproduce:

      Download archive with Drill sources from GitHub

      • open Chrome browser;
      • go to https://github.com/apache/drill link;
      • open the "Clone or download" menu;
      • click the "Download ZIP" button and save archive on a disk.
        Expected result - archive successfully downloaded.
        Actual result - Chrome browser canceled the download and deleted Drill sources archive fron the disk. Avast showed an alert window with virus description. Screenshot is in the attachments.

      Clone Drill sources from GitHub using git console version

      • open CMD;
      • type "git clone https://github.com/apache/drill.git";
      • scan clonned Drill sources folder using Avast antivirus.
        Expected result - Viruses were absent.
        Actual result - Avast showed an alert window with virus description.

      Here is the link with report from other antiviruses for this "attack-trace.pcap" file:
      https://r.virscan.org/language/en/report/4df38505462d3afedbbbff3d9217063d

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            cgivre Charles Givre
            denysord88 Denys Ordynskiy
            Arina Ielchiieva Arina Ielchiieva
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment