Re: [clamav-users] xlsm files

2020-12-22 Thread Joe Acquisto-j4
>>> > Hi there, > > On Tue, 22 Dec 2020, G.W. Haywood via clamav-users wrote: > >> If you try to stop evrything with signatures etc. > > Something went wrong with the connection between my brain and my > keyboard there, sorry. I meant to write ... > > If you try to stop everything with

Re: [clamav-users] xlsm files

2020-12-22 Thread G.W. Haywood via clamav-users
Hi there, On Tue, 22 Dec 2020, G.W. Haywood via clamav-users wrote: If you try to stop evrything with signatures etc. Something went wrong with the connection between my brain and my keyboard there, sorry. I meant to write ... If you try to stop everything with signatures etc. you'll spend

Re: [clamav-users] xlsm files

2020-12-22 Thread G.W. Haywood via clamav-users
Hi there, On Tue, 22 Dec 2020, Joe Acquisto-j4 wrote: ... "Please open" sort of messages. These are extremely common. They aren't all xlsm attachments but it's quite ususal for them to contain malicious macros - generally aimed at Windows boxes, but you must never be complacent even on

Re: [clamav-users] [External] xlsm files

2020-12-22 Thread Joe Acquisto-j4
>>On 12/22/2020 5:51 PM, Joe Acquisto-j4 wrote: >> Quite new to clamav. Using with Spamassassin on Linux and it appears to > scan properly and detects EICAR as an attachment. >> >> For last several weeks have been getting SPAM with xlsm file attached, > claiming to be invoice or payment

Re: [clamav-users] [External] xlsm files

2020-12-22 Thread Kevin A. McGrail via clamav-users
On 12/22/2020 5:51 PM, Joe Acquisto-j4 wrote: Quite new to clamav. Using with Spamassassin on Linux and it appears to scan properly and detects EICAR as an attachment. For last several weeks have been getting SPAM with xlsm file attached, claiming to be invoice or payment receipt or

[clamav-users] xlsm files

2020-12-22 Thread Joe Acquisto-j4
Quite new to clamav. Using with Spamassassin on Linux and it appears to scan properly and detects EICAR as an attachment. For last several weeks have been getting SPAM with xlsm file attached, claiming to be invoice or payment receipt or whatever. "Please open" sort of messages. Since these

Re: [clamav-users] Is there anything to do about encrypted viruses?

2020-12-22 Thread Paul Kosinski via clamav-users
Since the password has to be included for the victim to be able to decrypt, it ought to be possible to automatically find the password in the email. Of course, eventually the criminals will start hiding the password in some way that a human can easily find it, but non-AI automation can't. On

Re: [clamav-users] Is there anything to do about encrypted viruses?

2020-12-22 Thread G.W. Haywood via clamav-users
Hi there, On Tue, 22 Dec 2020, Alessandro Vesely via clamav-users wrote: Is there anything to do about encrypted viruses? Yes, indeed there is and it isn't too difficult. today I received a message with an encrypted zip attachment. I saved the attachment and loaded it to VirusTotal,

Re: [clamav-users] Looks like we've gotten a new variant of Emotet getting through...

2020-12-22 Thread Joel Esler (jesler) via clamav-users
Isn’t that literally the opposite of what needs to happen? On Dec 22, 2020, at 1:27 AM, Brent Clark via clamav-users mailto:clamav-users@lists.clamav.net>> wrote: Hiya Can you please submit to Sanesecurity too. https://sanesecurity.com/contact-us/ Regards Brent On 2020/12/21 18:44,

Re: [clamav-users] How can we consume .ldb files in ClamAV Ubuntu?

2020-12-22 Thread Joel Esler (jesler) via clamav-users
Yes Sent from my  iPhone > On Dec 22, 2020, at 02:30, Luca Sironi via clamav-users > wrote: > >  > Hello, > are those signatures coming from FireEye github already included on the > regular update ? > > regards > Luca > > ___ > > clamav-users

Re: [clamav-users] Is there anything to do about encrypted viruses?

2020-12-22 Thread Al Varnell via clamav-users
When you submit it, be sure to include the password so that the ClamAV signature team can properly asses it and provide a hash signature for the zip file. -Al- > On Dec 22, 2020, at 03:32, Alessandro Vesely via clamav-users > wrote: > > Hi all, > > > today I received a message with an

[clamav-users] Is there anything to do about encrypted viruses?

2020-12-22 Thread Alessandro Vesely via clamav-users
Hi all, today I received a message with an encrypted zip attachment. I saved the attachment and loaded it to VirusTotal, where no scanner detected anything: https://www.virustotal.com/gui/file/2cef2c979e60c1e2892e6a494814dd65db14c2076102279e6e74737d36c115a5/detection Then I unzipped the file

Re: [clamav-users] How can we consume .ldb files in ClamAV Ubuntu?

2020-12-22 Thread Steve Basford
On 22 December 2020 07:28:53 Luca Sironi via clamav-users wrote: Hello, are those signatures coming from FireEye github already included on the regular update ? Hi... Joel indicated the other day sigs to detect the problem files are already in the official Databases :) Cheers, Steve