LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Linux Deepin
User Name
Password
Linux Deepin This forum is for the discussion of Linux Deepin.

Notices


Reply
  Search this Thread
Old 04-21-2017, 11:44 AM   #1
splintercdo
Member
 
Registered: Feb 2011
Posts: 141

Rep: Reputation: 11
Deepin Linux is a malware?


Hey, haven't written anything for ages.

Decided to check out Deepin Linux and got complaints from Avast!

Check out the attachment.
Attached Thumbnails
Click image for larger version

Name:	Screen Shot 2017-04-21 at 19.41.00.png
Views:	608
Size:	217.4 KB
ID:	24825  
 
Old 04-21-2017, 12:00 PM   #2
jsbjsb001
Senior Member
 
Registered: Mar 2009
Location: Earth, unfortunately...
Distribution: Currently: OpenMandriva. Previously: openSUSE, PCLinuxOS, CentOS, among others over the years.
Posts: 3,881

Rep: Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063Reputation: 2063
Quote:
Originally Posted by splintercdo View Post
Hey, haven't written anything for ages.

Decided to check out Deepin Linux and got complaints from Avast!

Check out the attachment.
Have you checked the MD5 sum for your iso?

You can check it with the command below:

Code:
md5sum name-of-iso-image.iso
It should match the one from here.
 
Old 04-21-2017, 12:10 PM   #3
splintercdo
Member
 
Registered: Feb 2011
Posts: 141

Original Poster
Rep: Reputation: 11
The moment, when avast blocks the page is when I am trying to download the iso (from the page you left the link to), somehow, I don't want to force the download through the warnings. :/
Edit:
To take a screenshot I returned to the page, and there weren't any warnings, I closed the browser went there again and warnings were back. I have visited the page four times and 3 of them were red.
Edit:
OK, I started the download using wget, will check the md5.
Edit:
Nah, I guess it's no use, wget is retrying regularly and the download speed is terrible estimated download time is 40+ hours.
What I actually wanted to know was, is it known for Deepin to be on the dark side, considering that it's from China.
Edit:
What I noticed is that the IP which is used by wget differs from IP in the screenshot. Could Avast get suspicious just because of the redirection? :/

Last edited by splintercdo; 04-21-2017 at 12:33 PM.
 
Old 04-21-2017, 12:31 PM   #4
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
i can see how a windows antivirus might see a linux distro .iso as a false positive...

to test, try a few other distros and see if they get flagged too.
if they do, you can be sure it's a false positive.
but that still doesn't mean that i would recommend deepin.
 
Old 04-21-2017, 12:36 PM   #5
splintercdo
Member
 
Registered: Feb 2011
Posts: 141

Original Poster
Rep: Reputation: 11
I have been using various linux isos for years, never had a problem.
It might be that the redirection of the IP might have caused Avast to spit out the warnings.
Edit:
OK, I cancelled wget download. I'll wait for a bit, if anyone has anything to add. Otherwise I'll close the thread.

Last edited by splintercdo; 04-21-2017 at 12:39 PM.
 
Old 04-22-2017, 12:24 AM   #6
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
^ so you got the warning from the attempted download, not the file itself?
i don't think downloading itself is dangerous.

but i'll say it again, try a test with another distro; avast might have changed its behavior since you last downloaded a linux .iso.
 
Old 04-22-2017, 02:19 AM   #7
273
LQ Addict
 
Registered: Dec 2011
Location: UK
Distribution: Debian Sid AMD64, Raspbian Wheezy, various VMs
Posts: 7,680

Rep: Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373
Is e reason why you're going to some random IP address and not to:
https://www.deepin.org/en/download/
I have NoScript installed, so perhaps I'm missing a redirrect, but the download link points to cdimage.deepin.com not some random IP address, at least for me.
Edit:
I pinged both sites above and the IP addresses are:
www.deepin.org 114.215.101.12
cdimage.deepin.com 202.141.160.114
These are nothing like the one in the screenshot so this suggests either a dodgy download site was chosen or the browser is in some way compromised.

Last edited by 273; 04-22-2017 at 02:22 AM.
 
Old 04-22-2017, 02:34 AM   #8
rob.rice
Senior Member
 
Registered: Apr 2004
Distribution: slack what ever
Posts: 1,076

Rep: Reputation: 205Reputation: 205Reputation: 205
Quote:
Originally Posted by splintercdo View Post
The moment, when avast blocks the page is when I am trying to download the iso (from the page you left the link to), somehow, I don't want to force the download through the warnings. :/
Edit:
To take a screenshot I returned to the page, and there weren't any warnings, I closed the browser went there again and warnings were back. I have visited the page four times and 3 of them were red.
Edit:
OK, I started the download using wget, will check the md5.
Edit:
Nah, I guess it's no use, wget is retrying regularly and the download speed is terrible estimated download time is 40+ hours.
What I actually wanted to know was, is it known for Deepin to be on the dark side, considering that it's from China.
Edit:
What I noticed is that the IP which is used by wget differs from IP in the screenshot. Could Avast get suspicious just because of the redirection? :/
LQ has a place to download distros
you could also have a look at
http://distrowatch.com/
a great place to look for a distro that's just right for you
 
Old 04-22-2017, 06:41 AM   #9
!!!
Member
 
Registered: Jan 2017
Location: Fremont, CA, USA
Distribution: Trying any&ALL on old/minimal
Posts: 997

Rep: Reputation: 382Reputation: 382Reputation: 382Reputation: 382
What does the site address resolve to for you? I get 183.91.33.46, so maybe there's some geographic cdn/dns issue.
Try 'my' ip# above, in your wget of: /releases/15.4/deepin-15.4-amd64.iso

https://github.com/linuxdeepin/deepi...Deepin.mirrors

Last edited by !!!; 04-22-2017 at 04:03 PM.
 
Old 04-22-2017, 06:45 AM   #10
273
LQ Addict
 
Registered: Dec 2011
Location: UK
Distribution: Debian Sid AMD64, Raspbian Wheezy, various VMs
Posts: 7,680

Rep: Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373
Quote:
Originally Posted by !!! View Post
What does the site address resolve to for you? I get 183.91.33.46, so maybe there's some geographic cdn/dns issue.
Try 'my' ip# above, in your wget of: /releases/15.4/deepin-15.4-amd64.iso
I'm not at a PC to test this but you could be correct about the DNS. However, for the IP adress to be exposed in the firefox window looks off to me regardless.
edit: perhaps one of the Deepin mirrors has either been compromised or isn't set up quite correctly?

Last edited by 273; 04-22-2017 at 06:47 AM.
 
Old 04-22-2017, 09:21 AM   #11
splintercdo
Member
 
Registered: Feb 2011
Posts: 141

Original Poster
Rep: Reputation: 11
Quote:
What does the site address resolve to for you? I get 183.91.33.46, so maybe there's some geographic cdn/dns issue.
Try 'my' ip# above, in your wget of: /releases/15.4/deepin-15.4-amd64.iso
Yes, that is the address avast is complaining about. Check out my initial post, there's a screenshot attached.
Anyway, it is not an urgent matter.
Hopefully this thread helps people to be more careful. I guess I could let deepin devs to know about this. I'll look into it, if it is sufficiently easy.
 
Old 04-22-2017, 10:37 AM   #12
splintercdo
Member
 
Registered: Feb 2011
Posts: 141

Original Poster
Rep: Reputation: 11
After posting this thread to deepin fb page.
Another person, with more free time on hand, posted this:
Quote:
Hello Deepin Team, The currnet md5sum for deepin-15.4-amd64.iso is d461304e4ab314373edbef60d9d6a4d6 on deepin mirrors (checked Poland, Russia and Slovakia), while the MD5SUMS file says it should be a4910104c76f24c112ce4a18ed518440. Also the deepin-15.4-amd64.iso file on the mirrors is less than 1.9 GB in size (with the date: 20.04.2017, 14:31), while the one on official http://cdimage.deepin.com/releases/15.4/ is over 2.4 GB in size (with the date: 19-Apr-2017 09:45). Please update MD5SUMS file, as it is confusing right now. Thanks for your great work : ) Best regards, - Dawid M.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Latest Deepin 2014 RC update disabled Deepin SW Center Nieuwkoop-75 Linux Deepin 13 01-04-2015 10:51 PM
What's going on, I can no longer access the Deepin forum website? Is Deepin defunct? ellisf Linux Deepin 2 08-26-2014 04:21 AM
LXer: Linux Deepin needs your help with the Deepin Localization Project LXer Syndicated Linux News 0 12-02-2013 10:41 PM
LXer: Use Linux Deepin Screenshot Tool "Deepin Scrot" In Other Linux Distributions LXer Syndicated Linux News 0 03-13-2012 05:50 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Linux Deepin

All times are GMT -5. The time now is 11:35 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration