Re: [clamav-users] FN with unknown virus attachment

2014-06-23 Thread Steve Basford
Okay, great, thanks. Can you describe the risk for me? What does it do, and what's necessary for the user to do to become infected? It appears to be a rogue link phishing attack? So it requires the user to open the Word doc then click the link, correct? Hi Alex, 1. I used strings on the

Re: [clamav-users] FN with unknown virus attachment

2014-06-22 Thread Alex
Hi, On Sat, Jun 21, 2014 at 2:43 PM, Steve Basford steveb_cla...@sanesecurity.com wrote: On Sat, June 21, 2014 2:00 pm, Alex wrote: Hi, I'm using clamav-0.98.4 on fedora20 with the sanesecurity and safebrowsing sigs and still seeing an unknown virus pass through our systems. I've

Re: [clamav-users] FN with unknown virus attachment

2014-06-22 Thread Al Varnell
On Sun, Jun 22, 2014 at 10:01 AM, Alex wrote: On Sat, Jun 21, 2014 at 2:43 PM, Steve Basford steveb_cla...@sanesecurity.com wrote: On Sat, June 21, 2014 2:00 pm, Alex wrote: Hi, I'm using clamav-0.98.4 on fedora20 with the sanesecurity and safebrowsing sigs and still seeing an unknown

[clamav-users] FN with unknown virus attachment

2014-06-21 Thread Alex
Hi, I'm using clamav-0.98.4 on fedora20 with the sanesecurity and safebrowsing sigs and still seeing an unknown virus pass through our systems. I've submitted it to the clamav false-negative upload, but haven't received a response, and 24hrs later it's still not being tagged. I was hoping someone

Re: [clamav-users] FN with unknown virus attachment

2014-06-21 Thread Joel Esler (jesler)
Thanks Alex, We'll have a look. -- Joel Esler Sent from my iPhone On Jun 21, 2014, at 9:00, Alex mysqlstud...@gmail.com wrote: Hi, I'm using clamav-0.98.4 on fedora20 with the sanesecurity and safebrowsing sigs and still seeing an unknown virus pass through our systems. I've submitted

Re: [clamav-users] FN with unknown virus attachment

2014-06-21 Thread Steve Basford
On Sat, June 21, 2014 2:00 pm, Alex wrote: Hi, I'm using clamav-0.98.4 on fedora20 with the sanesecurity and safebrowsing sigs and still seeing an unknown virus pass through our systems. I've submitted it to the clamav false-negative upload, but haven't received a response, and 24hrs later