Unidentified virus or malware detected across multiple operating systems (MacOS, Linux)
Unidentified virus or malware detected across multiple operating systems (MacOS, Linux)
All web content runs inside Docker containers. Databases like Bitwarden, Nextcloud, Sonarr, and Radarr are updated regularly without needing a direct link to the VM. Since this hasn't occurred before, I'm confident everything is under control. I'll post an update if it happens again. Appreciate your feedback!
It clearly suggests someone was attempting to install malware. FTP.exe serves as the primary file for enabling FTP transfers on Windows. Based on my limited understanding of PowerShell, it seems a firewall rule was added to FTP.exe so Windows Defender would bypass it, permitting a virus executable to be placed in the Windows installation startup folder and activate upon reboot. All this is based on theory, not deep expertise. @leadeater possesses far more knowledge about PowerShell than I do, and his skills likely helped Linus with the "These servers are TOO EXPENSIVE" video.
It's much better to see a train crash than to watch someone explain how to set up storage servers. Videos on that topic tend to be dull.