Windows Defender threat detections relating to LODA

Questions and Answers : Bugs : Windows Defender threat detections relating to LODA
Message board moderation

To post messages, you must log in.

AuthorMessage
Dave Studdert
Avatar

Send message
Joined: 11 Feb 23
Posts: 4
Credit: 2,711,824
RAC: 281
Message 873 - Posted: 30 Jan 2025, 15:15:31 UTC

I have seen several threat detections from windows defender this morning relating to LODA

Detected: Trojan:Win32/Commandrob.A!ml
Status: Removed
Details: This program is dangerous and executes commands from an attacker.

Affected items:
CmdLine: C:\Windows\System32\cmd.exe /c curl -fsSLo C:\ProgramData\BOINC/projects/boinc.loda-lang.org_loda\oeis\b\065\b065449.txt.gz http://api.loda-lang.org/miner/v1/oeis/b065449.txt.gz

Windows Defender has removed about 45 of these.

Many work units have error while computing and looking through the tasks several other users PC's have errored out on the same tasks.
Anybody else seen this on their systems. Any ideas what is going on?
ID: 873 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Christian Krause
Project administrator

Send message
Joined: 9 May 22
Posts: 272
Credit: 470,087
RAC: 229
Message 874 - Posted: 30 Jan 2025, 21:13:33 UTC - in response to Message 873.  

The curl command is part of Windows. LODA is executing it to fetch data. I checked the file b065449.txt.gz on the server and didn't find anything suspicious.
ID: 874 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Steve Dodd

Send message
Joined: 14 May 22
Posts: 3
Credit: 4,032,321
RAC: 8,862
Message 875 - Posted: 30 Jan 2025, 23:37:40 UTC - in response to Message 873.  

I've seen exactly the same thing.
ID: 875 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
mg13 [HWU]
Avatar

Send message
Joined: 26 May 22
Posts: 2
Credit: 235,320
RAC: 391
Message 876 - Posted: 30 Jan 2025, 23:43:57 UTC - in response to Message 873.  

I have seen several threat detections from windows defender this morning relating to LODA

Detected: Trojan:Win32/Commandrob.A!ml
Status: Removed
Details: This program is dangerous and executes commands from an attacker.

Affected items:
CmdLine: C:\Windows\System32\cmd.exe /c curl -fsSLo C:\ProgramData\BOINC/projects/boinc.loda-lang.org_loda\oeis\b\065\b065449.txt.gz http://api.loda-lang.org/miner/v1/oeis/b065449.txt.gz

Windows Defender has removed about 45 of these.

Many work units have error while computing and looking through the tasks several other users PC's have errored out on the same tasks.
Anybody else seen this on their systems. Any ideas what is going on?


I too from tonight I have had the same reports from Windows Defender 30 times and sent 5 WU error on other files:

CmdLine: C:\Windows\System32\cmd.exe /c curl -fsSLo D:\BOINC/projects/boinc.loda-lang.org_loda\oeis\b\168\b168692.txt.gz http://api.loda-lang.org/miner/v1/oeis/b168692.txt.gz
CmdLine: C:\Windows\System32\cmd.exe /c curl -fsSLo D:\BOINC/projects/boinc.loda-lang.org_loda\oeis\b\031\b031718.txt.gz http://api.loda-lang.org/miner/v1/oeis/b031718.txt.gz
CmdLine: C:\Windows\System32\cmd.exe /c curl -fsSLo D:\BOINC/projects/boinc.loda-lang.org_loda\oeis\b\193\b193349.txt.gz http://api.loda-lang.org/miner/v1/oeis/b193349.txt.gz
CmdLine: C:\Windows\System32\cmd.exe /c curl -fsSLo D:\BOINC/projects/boinc.loda-lang.org_loda\oeis\b\205\b205120.txt.gz http://api.loda-lang.org/miner/v1/oeis/b205120.txt.gz
CmdLine: C:\Windows\System32\cmd.exe /c curl -fsSLo D:\BOINC/projects/boinc.loda-lang.org_loda\oeis\b\107\b107078.txt.gz http://api.loda-lang.org/miner/v1/oeis/b107078.txt.gz
CmdLine: C:\Windows\System32\cmd.exe /c curl -fsSLo D:\BOINC/projects/boinc.loda-lang.org_loda\oeis\b\167\b167935.txt.gz http://api.loda-lang.org/miner/v1/oeis/b167935.txt.gz

Isn't there a risk that the server has been infected?
ID: 876 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Christian Krause
Project administrator

Send message
Joined: 9 May 22
Posts: 272
Credit: 470,087
RAC: 229
Message 877 - Posted: 31 Jan 2025, 15:54:41 UTC - in response to Message 876.  

There are no indications that the server has been infected. It is very likely a false positive.
You can find more background info here: https://gridinsoft.com/blogs/trojan-win32-commandrob-aml-remove/.
The reason might be that it is using an unsecured connection. We will try to switch to a secure connection, but it is not clear whether this will make the alert disappear.
ID: 877 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Christian Krause
Project administrator

Send message
Joined: 9 May 22
Posts: 272
Credit: 470,087
RAC: 229
Message 878 - Posted: 31 Jan 2025, 21:33:29 UTC - in response to Message 877.  

The new app version 250131 uses a secure connection. Please check if this problem still occurs with the new version.
ID: 878 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Dave Studdert
Avatar

Send message
Joined: 11 Feb 23
Posts: 4
Credit: 2,711,824
RAC: 281
Message 879 - Posted: 1 Feb 2025, 14:12:59 UTC
Last modified: 1 Feb 2025, 14:14:34 UTC

Tried to test new version to see if it stops the trojan warnings but all the work units just error out within 15 seconds. Looking at the workunit details there are up to 4 other machines that error out with a warning Too many errors (may have bug)

example https://boinc.loda-lang.org/loda/workunit.php?wuid=8730950
ID: 879 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Christian Krause
Project administrator

Send message
Joined: 9 May 22
Posts: 272
Credit: 470,087
RAC: 229
Message 881 - Posted: 1 Feb 2025, 16:05:13 UTC - in response to Message 879.  

Please try resetting the project. I suspect that your project directory got corrupted due to the previous errors.
ID: 881 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Dave Studdert
Avatar

Send message
Joined: 11 Feb 23
Posts: 4
Credit: 2,711,824
RAC: 281
Message 882 - Posted: 2 Feb 2025, 4:23:11 UTC - in response to Message 881.  

Please try resetting the project. I suspect that your project directory got corrupted due to the previous errors.


Thank you that fixed the error issues.

The new app version 250131 uses a secure connection. Please check if this problem still occurs with the new version.


I have done 50 odd workunits without any Trojan warnings, the new app version works a treat. Thank you again.
ID: 882 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Dave Studdert
Avatar

Send message
Joined: 11 Feb 23
Posts: 4
Credit: 2,711,824
RAC: 281
Message 883 - Posted: 2 Feb 2025, 10:54:04 UTC - in response to Message 882.  

Unfortunately the constant errors and threat warnings have returned, now reporting Trojan:Win32/Bearfoos.A!ml

Affected items:
file: C:\ProgramData\BOINC\projects\boinc.loda-lang.org_loda\loda-250131-windows.exe
ID: 883 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
Christian Krause
Project administrator

Send message
Joined: 9 May 22
Posts: 272
Credit: 470,087
RAC: 229
Message 884 - Posted: 2 Feb 2025, 15:39:32 UTC - in response to Message 883.  

This should be another false positive. See also the discussion here: https://www.reddit.com/r/cemu/comments/15s6d95/what_about_a_trojanwin32bearfoosaml/?rdt=54528. If it is acceptable for you, you can add the LODA/BOINC project folder to the exception list of Windows Defender to ignore the warning.
ID: 884 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote
mg13 [HWU]
Avatar

Send message
Joined: 26 May 22
Posts: 2
Credit: 235,320
RAC: 391
Message 885 - Posted: 2 Feb 2025, 22:21:16 UTC - in response to Message 884.  

For information, at the moment on my PC, the new application has updated, it has completed 5 WU and I have not had any warnings from Ms Defender and I have not reset the project.
ID: 885 · Rating: 0 · rate: Rate + / Rate - Report as offensive     Reply Quote

Questions and Answers : Bugs : Windows Defender threat detections relating to LODA

©2025 LODA Language