Since I have my log viewer working again I have found another issue. This one may be bad. It says I have a trojan and the suricata rules contain cobaltstrike.ja3; classtype:command-and-control. Is this a bug or is my system compromised? Here is a section of my log file:
02:47:29 suricata: [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature “drop tls $EXTERNAL_NET any → $HOME_NET any (msg:“ET JA3 Hash - Suspected Cobalt Strike Malleable C2 (ja3s) M1”; flow:established,from_server; ja3s.hash; content:“649d6810e8392f63dc311eecb6b7098b”; tls.cert_subject; content:!“servicebus.windows.net”; flowbits:isset,ET.cobaltstrike.ja3; classtype:command-and-control; sid:2028832; rev:1; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at
2019_10_15, deployment Perimeter, former_category JA3, malware_family Cobalt_Strike, signature_severity Major, updated_at 2019_10_15;)” from file /var/lib/suricata/emerging-ja3.rules at line 43
02:47:29 suricata: [ERRCODE: SC_WARN_JA3_DISABLED(309)] - ja3(s) support is not enabled
and another section:
02:47:29 suricata: [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature “alert tls $HOME_NET any → $EXTERNAL_NET any (msg:“ET JA3 Hash - Suspected Cobalt Strike Malleable C2 M1 (set)”; flow:established,to_server; ja3.hash; content:“eb88d0b3e1961a0562f006e5ce2a0b87”; ja3.string; content:“771,49192-49191-49172-49171”; flowbits:set,ET.cobaltstrike.ja3; flowbits:noalert; classtype:command-and-control; sid:2028831; rev:1; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2019_10_15, deployment Perimeter, former_category JA3, malware_family Cobalt_Strike, signature_severity Major, updated_at 2019_10_15;)” from file /var/lib/suricata/emerging-ja3.rules at line 41.
It appears my system is compromised. If it is, how do I prevent this from happening again if I wipe and reinstall? Any answers will be greatly appreciated. This is an issue of the kind that I will need all the help I can get. Thank you in advance for any replies.