On 02.09.23 17:04, Victor Sizov via clamav-users wrote:
Perhaps my Ubuntu computer is infected with a virus that redirects
html requests to "iyfbodn.com". To test it, I installed clamav (sudo
apt install clamav clamav-daemon). When I updated it (sudo freshclam)
I got the message:

...
Sat Sep 2 10:13:18 2023 -> DON'T PANIC! Read
https://docs.clamav.net/manual/Installing.html
Sat Sep 2 10:13:18 2023 -> ^FreshClam previously received error code
429 or 403 from the ClamAV Content Delivery Network (CDN).
Sat Sep 2 10:13:18 2023 -> This means that you have been rate limited
or blocked by the CDN.
Sat Sep 2 10:13:18 2023 -> 1. Verify that you're running a supported
ClamAV version.
Sat Sep 2 10:13:18 2023 -> See
https://docs.clamav.net/faq/faq-eol.html for details.

Which clamav version do you have? versions older than 0.103 are not supported.

...
I launched
curl -IL docs.clamav.net
and received:

HTTP/1.1 403 Forbidden
Date: Sat, 02 Sep 2023 07:19:15 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
X-Frame-Options: SAMEORIGIN
Referrer-Policy: same-origin
Cache-Control: max-age=15
Expires: Sat, 02 Sep 2023 07:19:30 GMT
Set-Cookie: 
__cf_bm=1MZmm2EcWi6S8fOiuha9zoaXngA5e44ph5LO2aXJchA-1693639155-0-AS7aYuYw1QJSTpioxNW76blxkMJKz2kTfvsaiUlH/kP9Z0sLbeMcLKgyf42ANBRqndUJQx
2dXrePUzX9Aj+RnvA=; path=/; expires=Sat, 02-Sep-23 07:49:15 GMT;
domain=.clamav.net; HttpOnly; SameSite=None
X-Content-Type-Options: nosniff
Server: cloudflare
CF-RAY: 8003fbd3bbe89d6d-DME

When I open https://docs.clamav.net in a browser, I get a message
about blocking in cloudfare:

Cloudflare Ray ID: 8005341f1fbc9daa • Your IP: 91.77.160.250

1) How I can resolve this to get last clamav updates?

clamav web and virus DB are protected from automated fetching. You need browser or freshclam new enough.

2) Could you advise me how to make sure the presence/absence of a
redirect to "iyfbodn.com"?

sorry, looks like a real virus targetting browsers.
Can you try searching from other computer?
--
Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
REALITY.SYS corrupted. Press any key to reboot Universe.
_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat

Reply via email to