home tags events about login
one honk maybe more

benjojo posted 12 Mar 2025 16:04 +0000

Juniper router/switches now have anti-virus. What a time to be alive.

root@Amnesiac> request system malware-scan quick-scan 
Found potential malware: No  

This seems to be part of JSA95385, that links to JSA93446

The JSA93446 is weirdly going out of it's way to say the victim was not Amazon:

At least one instance of malicious exploitation (not at Amazon) has been reported to the Juniper SIRT. Customers are encouraged to upgrade to a fixed release as soon as it's available and in the meantime take steps to mitigate this vulnerability.

But I enjoy(?) that the detailed report has the "pet names" that the Juniper teams names for each implant discovered in the wild.

The tl;dr of the wider thing is that one implant is JunOS specific, the rest are generic "open source malware" payloads that happen to run on FreeBSD/Linux

Malware Analysis This section describes the findings made during the reverse engineering effort, which included decomposition of each malware binary, static analysis of its metadata and flow, and an impact analysis on how it could affect Junos OS at run-time. All malware samples analyzed target Junos OS, Juniper Networks' FreeBSD-based operating system. The following malware implants were recovered from the MX Series routers: 1. The Local Memory Patching Attack Daemon (lmpad) 2. The Junos Denial of Service Daemon (jdosd) 3. The Internet Remote Access Daemon (irad) 4. A Poorly Plagiarized Implant Daemon (appid) 5. The TooObvious (to) 6. The Obscure Enigmatic Malware Daemon (oemd) NOTE: These names were crafted by Juniper based on malware behavior. They were not used by the malware authors themselves

benjojo replied 12 Mar 2025 16:04 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/tmvXQVqcsl2HkVrgv4

It also seems really obvious that the first thing that future implants is going to do is to patch the CLI to make request system malware-scan quick-scan not admit anything.

But I assume there is at least one customer who this gives a warm fuzzy feeling to