[clamav-users] clamscan (NOT clamdscan) log file setup in *.conf file?

2016-11-16 Thread Fouts, Christopher
The docs show the following example when running clamscan (NOT clamdscan) $ clamscan –r –l scan.txt /some_path How can I configure the log file in the /etc/clamd.d/scan.conf file for clamscan, not for clamdscan? I see # Uncomment this option to enable logging. # LogFile must be writable for

Re: [clamav-users] ClamAV malware report: include info from Malwr?

2016-11-16 Thread Joel Esler (jesler)
To answer the automation question, 100% of what people submit is handled automatically. It is ran through our sandboxes if needs be, (the sandboxes used by our commercial customers) along with a ton of other factors, but yes, it's 100% automated. Humans have to deal with what cannot be

Re: [clamav-users] ClamAV malware report: include info from Malwr?

2016-11-16 Thread Matteo Dessalvi
Sure, I can use other sites too. My question was: would the folks at ClamAV benefit from these analysis? I don't know how much automated the submission process is: I guess it will anyhow run an analysis on the submitted file, so maybe including these links is not particularly useful to decide if

Re: [clamav-users] ClamAV malware report: include info from Malwr?

2016-11-16 Thread Steve Basford
On Wed, November 16, 2016 1:56 pm, Matteo Dessalvi wrote: > It ended up to be just the first step in order to download the > real malware: > > https://malwr.com/analysis/MzVkNzAzYjBiOTJhNDlmODhkZjRiY2EwY2EwOWZhZWE/ I Guess you could post links to other sites too... eg:

[clamav-users] ClamAV malware report: include info from Malwr?

2016-11-16 Thread Matteo Dessalvi
Hi all. As stated in the subject, I am wondering if it would be useful to include a link to the analysis of the submitted file into the "Description" field. For example, today our ClamAV missed the file described here: https://malwr.com/analysis/MjQ3MWExYzBhNTRjNGJhOTg1Yjc4NzMxMGNkNDAyMjQ/ It