searching biosrootkit

Bios Rootkit <[email protected]> Thu, 26 Dec 2019 13:21:50 +0100
Newsgroups dev.linux.lists.oe-chipsec
Message-ID <[email protected]>
--===============6544597101622906085==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable

Hi,
I have some suspects I have a rootkit around, but I don't know where. I tri=
ed to dump my uefi installation and I extracted some strings.
This is what I found:
<30>[   31.343046] systemd[1]: Set hostname to <amnesia>.
<30>[   31.346636] systemd[1]: Initializing machine ID from random generato=
r.
<29>[   32.879891] systemd[1]: /lib/systemd/system/tor(a)default.service:9:=
 PIDFile=3D references path below legacy directory /var/run/, updating /var=
/run/tor/tor.pid =

<28>[   32.910650] systemd[1]: /lib/systemd/system/tails-gdm-failed-to-star=
t.service:11: Ignoring unknown escape sequences: "MAX_LENGTH=3D254 ;       =
PREFIX=3D"Error starting GDM with your graphics card: " ;       SUFFIX=3D".=
 Please =

take note of this error and visit https://tails.boum.org/gdm for troublesho=
oting." ;       MAX_VIDEO_CARD_LENGTH=3D$(($MAX_LENGTH - $(echo -n "$PREFIX=
$SUFFIX" | wc -c))) ;       VIDEO_CARD=3D$(lspci -d::0300 -nn | sed -E "s,.=
* VGA =

compatible controller \[0300\]: *,," | cut -c "1-$MAX_VIDEO_CARD_LENGTH") ;=
       /bin/plymouth display-message --text=3D"$PREFIX$VIDEO_CARD$SUFFIX"  =
    "
<30>[   30.848308] systemd[1]: Inserted module 'autofs4'
<30>[   31.262810] systemd[1]: systemd 240 running in system mode. (+PAM +A=
UDIT +SELINUX +IMA +APPARMOR +SMACK +SYSVINIT +UTMP +LIBCRYPTSETUP +GCRYPT =
+GNUTLS +ACL +XZ +LZ4 +SECCOMP +BLKID +ELFUTILS +KMOD -IDN2 +IDN -PCRE2 def=
au
lt-hierarchy=3Dhybrid)
<30>[   31.282862] systemd[1]: Detected architecture x86-64.
<30>[   31.355048] systemd[1]: Set hostname to <amnesia>.
<30>[   31.356024] systemd[1]: Initializing machine ID from random generato=
r.
<29>[   32.853978] systemd[1]: /lib/systemd/system/tor(a)default.service:9:=
 PIDFile=3D references path below legacy directory /var/run/, updating /var=
/run/tor/tor.pid =


Is it normal systemd logs in uefi image dump ?
I have used tails 3 or 4 times then could be that uefi take the systemd log=
s, I don't know.
I have also found string like the following:
ASCII: %Microsoft Windows Production PCA 20110
ASCII: Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.c=
rl0Z
ASCII: >http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
ASCII: Canonical Ltd.1402
ASCII: +Canonical Ltd. Master Certificate Authority0

but these whould be parts of the certificates because of secure boot.
I also tried to check the image against the chipsec blacklist module, it gi=
ve me a loop error about lack of ram. It was something like "can't allocate=
 ram" or something like that.
Do I have to open a bug ?
Thank you very much for your help.
Bios
--===============6544597101622906085==--