Re: [clamav-users] Reference a normalized variable name without hardcoding a specific one?

2024-03-06 Thread Kris Deugau via clamav-users
Arnaud Jacques via clamav-users wrote: Hello Kris, [...] > /(n\d+).htmldomstuff;function(\1);/ > > Do any of Clam's signature types support something like this? I use : 6e3?3?3? that matches n000, n003, n024, n781 ... Right, and I've used that in cases where tracking a particular normal

[clamav-users] Reference a normalized variable name without hardcoding a specific one?

2024-03-05 Thread Kris Deugau via clamav-users
So, I've been creating local signatures for a variety of obfuscated Javascript for a while. But I've been missing a way to more precisely target malicious actions based on surrounding variables. With my latest sample, I want to match "[variable].[htmldomstuff]", "function([variable])", acros

Re: [clamav-users] [ext] ClamAV and Cohesity

2023-05-23 Thread Kris Deugau
steven aldenkamp via clamav-users wrote: Thanks. Apparently the info I gave earlier was older. We noticed also ClamAV 0.103.5 This is still three minor patch releases behind the current one in the 0.103 series, and IIRC there were some low-grade security fixes in that span. It should stil

Re: [clamav-users] Anyone else having trouble reaching the ClamAV website?

2023-01-05 Thread Kris Deugau
clamav.mbou...@spamgourmet.com wrote: Kris Deugau wrote: I went to load a semi-bookmarked page for signature writing (https://docs.clamav.net/manual/Signatures.html), but it failed and kept reloading Cloudflare's "security check" voodoo. ClamAV's site works for me, usi

[clamav-users] Anyone else having trouble reaching the ClamAV website?

2023-01-05 Thread Kris Deugau
I went to load a semi-bookmarked page for signature writing (https://docs.clamav.net/manual/Signatures.html), but it failed and kept reloading Cloudflare's "security check" voodoo. (Side question to pass up the chain at Cisco/Talos - is there a knob that can be twisted somewhere to force that

Re: [clamav-users] Fwd: exception rule - help needed

2023-01-04 Thread Kris Deugau
newcomer01 via clamav-users wrote: no one can help me? I think most of us have just about given up on this test, and are either doing without or call ClamAV in a way that allows us to handle FP-prone tests like this differently from other results (either by whitelisting mail ahead of ClamAV

Re: [clamav-users] LibClamAV Warning: PNG: Unexpected early end-of-file.

2022-12-12 Thread Kris Deugau
Andrew C Aitchison via clamav-users wrote: On Mon, 12 Dec 2022, newcomer01 wrote: Well on my PC I changed a lot because the naming was too messy for me. I have "program" clam*d*scan for which I have a clam*d*.conf and a "program" clamscan for which I have a clamscan.conf. And then the normal

Re: [clamav-users] Heuristics.Phishing.Email.SpoofedDomain false positive desjardins.com and rbc.com

2022-06-15 Thread Kris Deugau
joe a wrote: To semi-hijack, I was attempting to deal with my own occasional false positive by using this thread as a clue. Attempting to follow the docs, I hit a wall here: "To help you identify what triggered a heuristic phishing alert, clamscan or clamd will print a message indicating the

Re: [clamav-users] clamdscan versus clamscan detection

2022-03-31 Thread Kris Deugau
Matus UHLAR - fantomas wrote: On 31.03.22 11:02, Petr Jurášek via clamav-users wrote: https://www.mail-archive.com/clamav-users@lists.clamav.net/msg51769.html It's the same situation. Vir is detected, but file is "clean", you can see it in summary. looks like that. I completely missed it.

[clamav-users] Detection glitch on series of Excel files

2022-03-25 Thread Kris Deugau
I've been seeing a series of Excel files recently that seem to be triggering a bug of some kind. These are not matched by any stock signatures (yet), so I've been using clamscan --leave-temps to extract components for signatures. Most of the time I just create hashes of a component from one s

Re: [clamav-users] human friendly signatures

2022-03-21 Thread Kris Deugau
G.W. Haywood via clamav-users wrote: Hi there, On Mon, 21 Mar 2022, Kris Deugau wrote: TBH I'd prefer if Clam *did* continue, just skipping malformed rules (and also whinging loudly in the log). I could live with that if it didn't *also* crash. Either would be better than ju

Re: [clamav-users] human friendly signatures

2022-03-21 Thread Kris Deugau
G.W. Haywood via clamav-users wrote: Hi Micah, On Wed, 16 Mar 2022, Micah Snyder (micasnyd) wrote: I'm not sure what you mean here.  Can you elaborate?  If you simply want ClamAV ignore garbage rules on load and continue with the rest of the file (see point #4) - that's something we can easily

Re: [clamav-users] INSTREAM + eicar not well detected?

2022-03-03 Thread Kris Deugau
Jorge Elissalde via clamav-users wrote: Thank you for your answer. I'm using Windows clamd release 0.104.2 I have double checked with wireshark and the data sent is ok. suppose I just send: char *eicarTest = "X5O!P%@AP[4\\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*" Result is ok: i

Re: [clamav-users] Minor bug or working as intended?

2022-03-02 Thread Kris Deugau
Kris Deugau wrote: For some types of content, just allowing a plain ASCII string instead of the hex-coded version of the same would be a big help.  Or an enhancement in the current file formats allowing embedded comments - I've lost track of how many times I've created something co

Re: [clamav-users] Minor bug or working as intended?

2022-03-02 Thread Kris Deugau
Micah Snyder (micasnyd) via clamav-users wrote: G.W. Haywood wrote: Execution time will be important for scanning filesystems, less so for scanning mail (at least for scanning low-volume mail) and readability can be hugely important if you're writing a lot of rules.  Perhaps we should be aski

Re: [clamav-users] allowlist/fixing false positive

2022-03-01 Thread Kris Deugau
Alex via clamav-users wrote: Hi, I have a fedora34 system with clamd-0.103.5 and amavisd/SA/postfix. I have a newsletter from ncua.gov that keeps getting blocked because it apparently contains links.gd in the body somewhere, although I can't find it. How do I exclude this email from being tagge

Re: [clamav-users] Minor bug or working as intended?

2022-02-25 Thread Kris Deugau
Laurent S. via clamav-users wrote: Dear Kris, I've had the same issue. In the last two years, I was regularly writing YARA sigs in ClamAV and finding that it behaves in strange ways... Especially the regex integration. I specifically remember that counting regex wasn't possible and that I had

Re: [clamav-users] Minor bug or working as intended?

2022-02-25 Thread Kris Deugau
Maarten Broekman via clamav-users wrote: There's not a lot that you can do in Yara rules that you can't do in LDB sigs... for what it's worth, here's a logical sig that detects the same thing as the Yara rules... mbroekman@lothlorien:~$ grep MJB.JS.SendEmail clamdb/javascript_sigs.ldb| sigtoo

[clamav-users] Minor bug or working as intended?

2022-02-24 Thread Kris Deugau
After chasing docs back and forth and trying small variations, I think I've found what's arguably a bug in Clam's YARA implementation. These two YARA rules should both match exactly the same, but don't. The first will only match if the condition is changed to indicate a single match in some v

Re: [clamav-users] Current replacement for --max-ratio?

2022-01-17 Thread Kris Deugau
G.W. Haywood via clamav-users wrote: Hi there, On Fri, 14 Jan 2022, Kris Deugau wrote: I've just come across a presumed-malicious .zip file of about 500K that contains a ~315M ISO image, which in turn appears to contain a ~315M executable file. After a bit of searching and testing

[clamav-users] Current replacement for --max-ratio?

2022-01-14 Thread Kris Deugau
I've just come across a presumed-malicious .zip file of about 500K that contains a ~315M ISO image, which in turn appears to contain a ~315M executable file. After a bit of searching and testing I see the --max-ratio option has been removed from clamscan, and ArchiveMaxCompressionRatio in clam

Re: [clamav-users] what initiates freshclam? [OT]

2022-01-07 Thread Kris Deugau
G.W. Haywood via clamav-users wrote: IMHO this is a pretty unconvincing reason to change your init system, especially to one which is both as new as systemd, and as capable of stupidity on a scale never before seen in any init system.  A couple of examples here (the wanton renaming of Ethernet in

Re: [clamav-users] what initiates freshclam?

2022-01-06 Thread Kris Deugau
novpenguincne via clamav-users wrote: OEL = Oracle Enterprise Linux Under /usr/lib/systemd/system, there are the four clam*.service files. But since none of them are active or enabled, I don't think can be the source. I scanned the entire file system for cl*.service and they are the only one

Re: [clamav-users] what initiates freshclam?

2022-01-06 Thread Kris Deugau
novpenguincne via clamav-users wrote: I'm still experimenting with Clam and I've got 103.4 installed on an OEL 7.9 box. What is "OEL"? I'm guessing it's some Red Hat derivative.   I've got freshclam configured to download new updates every few hours.  I can manually run freshclam and success

Re: [clamav-users] main.cvd update schedule

2021-12-21 Thread Kris Deugau
Vu, Hong-Duc V. via clamav-users wrote: Hello, How often does the main.cvd file get updated? According to this old post they have seven changes in two years. https://lists.clamav.net/pipermail/clamav-users/2014-September/000916.html This will help me troubleshoot any issues with my freshclam

Re: [clamav-users] clamscan tar archive

2021-12-20 Thread Kris Deugau
Hart, Steven A. via clamav-users wrote: Hello all, ClamAV documentation states that tar archives are supported.   I've created a small sample tar archive that includes an eicar sample. Clamscan seems to only look at the tar archive as a single file and does not hit on the eicar sample withi

Re: [clamav-users] Possible to use clamdscan to scan a file on the clamd host?

2021-09-10 Thread Kris Deugau
Choate, Nathan via clamav-users wrote: Hello, I’ve recently been experimenting with using the recently built ClamAV Docker image in a Kubernetes deployment. We want to utilize the ClamAV container in our deployment alongside a basic server application running in a separate pod. We think th

Re: [clamav-users] clamscan: permission denied on many files being used by another process

2021-07-13 Thread Kris Deugau
Michael Wang wrote: I understand "more" is not clamscan, I was just showing that the file in question cannot be opened with clamscan nor with "more" as administrator. I also understand if clamscan cannot read a file, it cannot scan it. My question is how I can let clamscan to read a file, as I

[clamav-users] Sig writing advice - complex matching in a PDF

2021-06-18 Thread Kris Deugau
I have a phishy PDF. I want to match a string I've extracted from one of the files left by clamscan --leave-temps, but ONLY if the outermost file being scanned is a PDF. The string on its own is just generic enough I don't want to rely on it alone, so I want to limit matching to PDF files.

Re: [clamav-users] freshclam issues

2021-04-09 Thread Kris Deugau
Wayne Florence via clamav-users wrote: Hello,     I have recently updated my 4 ClamAV private mirrors to version 0.103.0 to fix issues downloading the cvd files.     However I am still having issues  I have the servers setup to use freshclam via a cron once per day.

Re: [clamav-users] Heuristics, only on or off?

2021-03-24 Thread Kris Deugau
Joe Acquisto-j4 wrote: In log find (snipped) ". . .infected by Heuristics.OLE2.ContainsMacros.VBA" This is enabled by the AlertOLE2Macros directive in clamd.conf ". . .infected by Heuristics.Phishing.Email.SpoofedDomain" This is enabled by the PhishingScanURLs directive in clamd.conf. I

Re: [clamav-users] Problem with private mirror and cld, inc files

2021-01-27 Thread Kris Deugau
Vangelis Katsikaros via clamav-users wrote: Hi Joel, thanks for the quick response. We already download once every hour (the default ubuntu 18.04 behavior). However, we are using auto scaling and we might be running a large number of EC2 instances (a few hundreds), that could try to download si

Re: [clamav-users] Is Doc.Packed available as PUA category?

2021-01-14 Thread Kris Deugau
G.W. Haywood via clamav-users wrote: One of the reasons that malicious senders send so many malicious password protected documents by email is that it is not always easy to detect malware in them without knowledge of the password, so by and large scanners like ClamAV don't attempt to do it (even

Re: [clamav-users] Question about Urlhaus.Malware.452652-9766253-0

2020-12-23 Thread Kris Deugau
Orion Poplawski wrote: Can anyone give me some details about the Urlhaus.Malware.452652-9766253-0 signature? We're seeing following URLs trigger it: https://curben.gitlab.io/malware-filter/urlhaus-filter-online.txt https://raw.githubusercontent.com/curbengh/urlhaus-filter/master/urlhaus-filter-

Re: [clamav-users] How can we consume .ldb files in ClamAV Ubuntu?

2020-12-14 Thread Kris Deugau
Sandeep Talla wrote: Hi Mark/Kris, Thank you for your responses. I have placed the *fireeye.ldb* file under the directory /var/lib/clamav/ and modified the permission to 644 and ownership to clamav. Then we have restarted the service Clamav-Deamon and then started clamscan. However, Clamscam

Re: [clamav-users] How can we consume .ldb files in ClamAV Ubuntu?

2020-12-14 Thread Kris Deugau
Sandeep Talla wrote: Hi All, We have ClamAV installed on Ubuntu. On Ubuntu, the rules can be specified or modified under the directory */var/lib/clamav/main.cvd*. However,  We are trying to consume ClamAV rules from the FireEye as shown below link which is*.ldb* file and we are trying to conv

Re: [clamav-users] Kindly help in create unofficial signature

2020-09-21 Thread Kris Deugau
Dismas Axel (Thomas) via clamav-users wrote: 3) I ran the command: cat Returned_Swift Copy,PDF.tar.xz | sigtool --hex-dump | head -c 2048 > Returned_Swift_Copy.ndb If you don't have multiple similar but not quite identical samples, and you're not familiar with the structure of Windows execut

Re: [clamav-users] create /var/run/clamav on reboot in Fedora, otherwise Pulseaudio errors occur

2020-08-05 Thread Kris Deugau
Robert Kudyba wrote: Using Fedora 31, this has been happening for quite a while. After reboot /var/run/clamav is removed, which is expected. However, wehn ClamAV was installed the user created in /etc/passwd looks like this: clamav:x:985:981::/var/run/clamav:/sbin/nologin So Pulseaudio tries t

Re: [clamav-users] Multiple Streams embedded as base64 inside xml

2020-04-24 Thread Kris Deugau
G.W. Haywood via clamav-users wrote: It's quite possible that a scan could catch some known problem in *any* file, no matter how compressed, containerized and obfuscated, if there's already a signature which matches something in the raw file (that is, before any extraction and/or decoding takes

Re: [clamav-users] Heuristics.Limits.Exceeded FOUND

2020-04-03 Thread Kris Deugau
Arjen de Korte via clamav-users wrote: Citeren Paul Kosinski via clamav-users : However, applying clamscan to this file (which was slightly renamed by my download script to be more readable) results in the following output: clamscan --alert-exceeds-max=yes --max-scantime=999 --max-scansize=4

Re: [clamav-users] Cannot install Clam AV on Ubuntu 16.04

2020-03-30 Thread Kris Deugau
Matus UHLAR - fantomas wrote: On 30.03.20 18:09, Cheney, James via clamav-users wrote: I did the sudo apt install clamav-daemon on a test 16.04 instance and it worked perfectly! This makes me think I've overcomplicated the centos & RHEL installs we've done. When I ran sudo yum install clama

Re: [clamav-users] Proofpoint and Heuristics.Phishing.Email.SpoofedDomain

2020-03-16 Thread Kris Deugau
micah anderson via clamav-users wrote: Hi, I keep having people complaining about False Positives due to Heuristics.Phishing.Email.SpoofedDomain because of Proofpoint. I really didn't want to do this, but I added a few entries to the local.wdb to whitelist it: X:.+safelinks\.protection\.out

Re: [clamav-users] ClamAV using high CPU and battery

2020-02-27 Thread Kris Deugau
Douglas Stinnette wrote: I have been getting reports of ClamAV using high CPU during full scans. Well yes it's busy scanning the whole filesystem like it's been told to do. Also I am getting a complaint from faculty that ClamAV is heavily using resources and causing loss of battery

Re: [clamav-users] clamav-milter and "whitelist"

2019-12-24 Thread Kris Deugau
Gerard E. Seibert via clamav-users wrote: On Mon, 23 Dec 2019 08:04:13 +0100, Alessandro Vesely via clamav-users stated: Perhaps you could try and match From:snopescom-.*@cmail20.com? Actually, it is the "@cmail20.com" part changes also. I've also got cmail1 and cmail2 in my ham collection

Re: [clamav-users] clamd onaccess scanning NFS

2019-11-11 Thread Kris Deugau
Mark Parker via clamav-users wrote: Hi all,     I'm investigating clamav as a solution for a couple hundred linux boxes. We need onaccess scanning but I'm running into an issue. For clamd to do onaccess scanning it needs to be run as root to use the inotify components, but since we export our

Re: [clamav-users] Disable official database

2019-08-26 Thread Kris Deugau
G.W. Haywood via clamav-users wrote: To find out what might work and what might not, here's what I did: == Using 'clamd': 8<-- 1. I moved the 'main.cld' and 'd

Re: [clamav-users] Disable official database

2019-08-26 Thread Kris Deugau
Joel Esler (jesler) via clamav-users wrote: I mean, it's possible not to download the official definitions and just point at a custom file right? *nod* This works fine. I have a secondary Clam instance set up to use only a selection of third-party signatures that I do not absolutely trust

Re: [clamav-users] How to enable llvm ?

2019-05-21 Thread Kris Deugau
Dorian ROSSE via clamav-users wrote: Yes that doesn,’t works as Following… *checking for llvm-config... /usr/bin/llvm-config* *configure: Using external LLVM* *checking for supported LLVM version... no (6.0.0)* *configure: error: LLVM < 3.7 required, but "6.0.0"(600) found* *configure: error

Re: [clamav-users] clamd using ~1GB memory on Debian Stretch

2019-05-13 Thread Kris Deugau
Avinash Sonawane via clamav-users wrote: On Mon, 13 May 2019 16:21:15 +0200 Matus UHLAR - fantomas wrote: loading takes time, much time. How much time are we talking about here? I suppose by 'time' we mean loading time (load binary and signatures) + processing time (comparing signatures).

Re: [clamav-users] clamscan/clamdscan with -z option

2019-02-14 Thread Kris Deugau
Paul wrote: Hi I have been looking at using the -z option on either clamdscan or clamscan and stumbled onto some odd behavior. This is with version 101.1. 101.0 also behaves the same. Take 2 paultest-010E110713-000 is constructed from test/clam.mail with the addition of a line of text to

Re: [clamav-users] Information regarding Win.Downloader.DDECmdExec-6715271-0

2018-11-13 Thread Kris Deugau
Dominique Sarrazin wrote: Hi everyone, On October 26^th , ClamAV’s signature database was updated with the addition of Win.Downloader.DDECmdExec-6715271-0, for which I cannot find any information despite my thorough research. sigtool --find-sigs [sig name] |sigtool --decode-sigs will at leas

Re: [clamav-users] Specify more servers for clamdscan to pass for scanning

2018-11-05 Thread Kris Deugau
Brent Clark wrote: Good day Guys I have setup two clamd servers. On my Webservers, I need to stream a file to the clamd for scanning. I would like to ask, how would I specify two TCPAddr. If I specify just one, server, everything works ok. Ive tried various options and google does not appears

Re: [clamav-users] About clamav's requirements for system resources

2018-11-02 Thread Kris Deugau
zhuangxiaohui wrote: Dear guys, Thanks to your team for providing us a such wonderful anti-virus soft. But, I got some problems there. I have some servers(Centos6/7). Most of them have 1GB memory, 600M available. But also servers with low memory. For example 512M memory, 200M available. When I

Re: [clamav-users] Whitelisting extensions for virus scan

2018-10-30 Thread Kris Deugau
Tilman Schmidt wrote: Am 29.10.18 um 17:33 schrieb Kris Deugau: Tilman Schmidt wrote: Am 26.10.18 um 15:34 schrieb Johnny Time: For exemple, we wanted to authorize only a white list which contains *.doc,*.xls,*.pdf and ban the others extensions. Surely you meant to write "*.docx,*

Re: [clamav-users] Whitelisting extensions for virus scan

2018-10-29 Thread Kris Deugau
Jerry wrote: We have a a steady flow of "*.doc", "*.docx" "*.xlsx" and *.pdf" files exchanged with other offices. I have not seen a virus in any of them since 2010. Seems like you might be doing business with the wrong type of people. I work for an ISP, managing our mail filtering services. Th

Re: [clamav-users] Whitelisting extensions for virus scan

2018-10-29 Thread Kris Deugau
Tilman Schmidt wrote: Am 26.10.18 um 15:34 schrieb Johnny Time: For exemple, we wanted to authorize only a white list which contains *.doc,*.xls,*.pdf and ban the others extensions. Surely you meant to write "*.docx,*.xlsx,*.pdf"? *.doc and *.xls are the old, malware-prone MS-Office filetypes.

Re: [clamav-users] Whitelisting extensions for virus scan

2018-10-26 Thread Kris Deugau
Johnny Time wrote: Hi Folks, We use Clamav and we wonder if we can whitelist some extensions on our virus scan ? For exemple, we wanted to authorize only a white list which contains *.doc,*.xls,*.pdf and ban the others extensions. If you're looking to block all files except a limited set

Re: [clamav-users] /bin/mkdir: cannot create directory ‘/run/clamav’: File exists

2018-10-17 Thread Kris Deugau
Dino Edwards wrote: Answering my own question on the /var/run and the /run directories. There is a link between the two, I just didn’t go up a level in the directory structure. The question about the error still remains though. The chown and mkdir look a bit suspect to me; I'm not seeing anyt

[clamav-users] FP on ProduKey 32-bit

2018-09-10 Thread Kris Deugau
Win.Trojan.Agent-6584188-0 is a hash matching the executable from the 32-bit build of ProduKey. One of our staff doing an assets audit triggered it by emailing the .zip to another staff member. I've confirmed that the .zip and the files in it match a fresh download from the developer's site,

Re: [clamav-users] Malwarepatrol false positive

2018-08-31 Thread Kris Deugau
Benny Pedersen wrote: why is https even blocked ? :( please whitelist https signatures There's no reason a hacked HTTPS website couldn't host malware. And there's no reason a spam domain couldn't get a certificate (from Let's Encrypt, or somewhere else) if they carefully time their actions.

Re: [clamav-users] FP with Heuristics.Phishing.Email.SpoofedDomain

2018-08-29 Thread Kris Deugau
Paul wrote: Hi I have 2 emails which have tripped Heuristics.Phishing.Email.SpoofedDomain (4 times in each email using clamscan -x option) Is the output from clamscan -x --debug shown below indicate the offending url pair triggering Heuristics.Phishing.Email.SpoofedDomain? LibClamAV debug

Re: [clamav-users] Limitation or bug in ClamAV's processing of Yara rules?

2018-03-19 Thread Kris Deugau
G.W. Haywood wrote: Hi Kris, On Thu, 15 Mar 2018, Kris Deugau wrote: I'm still chasing signatures for a certain class of (very) oversized spam with malformed HTML. ... Would you be able to send me a few samples?  Preferably with full headers. I've been able to create log

Re: [clamav-users] Limitation or bug in ClamAV's processing of Yara rules?

2018-03-16 Thread Kris Deugau
for two-byte fixed references in patterns in all other pattern-matching signature types, since I have another Yara rule for a series of obfuscated Javascript that uses a similar type of regex pattern. -kgd Regards     Mark. On 14/03/18 20:47, Kris Deugau wrote: I'm still chasing s

[clamav-users] Limitation or bug in ClamAV's processing of Yara rules?

2018-03-14 Thread Kris Deugau
I'm still chasing signatures for a certain class of (very) oversized spam with malformed HTML. I've found an issue that is either an implementation limit or a bug in ClamAV's handling of Yara rules. I've narrowed it down to an issue with the "#" condition variant. For a rule like so: rule ba

Re: [clamav-users] Question regarding freshclam log entry

2018-02-23 Thread Kris Deugau
J Doe wrote: I note though that man 5 freshclam.conf states that clamd is *NOT* set to update by default, however when I installed the package on Ubuntu 16.04.03 LTS, it has put in 3600 for an update frequency. Between freshclam and clamd there are three options here that operate indpendentl

[clamav-users] Possible FP on Doc.Dropper.Agent-6447876-0?

2018-02-15 Thread Kris Deugau
I've had a customer reporting problems sending a supposedly all-text (likely actually multipart text+html with no hand-added attachments) triggering this signature. Since it's a hash I'm baffled by what it might be misfiring on in a legitimate more-or-less text-only message. I don't yet have

Re: [clamav-users] Can't Install ClamAV

2018-02-02 Thread Kris Deugau
Paul B. wrote: Ok, I got the same errors from Synaptics upon trying to install a completely unrelated program: E: clamav-base: subprocess installed post-installation script returned error exit status 1 E: clamav-freshclam: dependency problems - leaving unconfigured E: clamav: dependency problems

Re: [clamav-users] ERROR: NotifyClamd: Can't connect to clamd on 127.0.0.1:3310: Connection refused

2018-02-01 Thread Kris Deugau
Chris wrote: Using nc -l 3310 in one terminal and nc 127.0.0.1 3310 I get: nc -l 3310 test this is a test  nc 127.0.0.1 3310 test this is a test So, IIUC I can talk to port 3310 with 127.0.0.1 or am I incorrect? nc -l should have returned an error if clamd was actually listening on that po

Re: [clamav-users] Matching variant patterns in logical or Yara signatures

2018-01-17 Thread Kris Deugau
G.W. Haywood wrote: Hi there, On Tue, 16 Jan 2018, Kris Deugau wrote: I'm trying to create signatures to match a particular series of large to very large spams whose main identifier is a

[clamav-users] Matching variant patterns in logical or Yara signatures

2018-01-15 Thread Kris Deugau
I'm trying to create signatures to match a particular series of large to very large spams whose main identifier is a

Re: [clamav-users] problem installing clamav

2017-11-28 Thread Kris Deugau
richard parker wrote: I am sure this is something obvious to the experienced but not to a bit of a newbie such as myself. I am struggling with installation with the following being reported E: dpkg was interrupted, you must manually run 'sudo dpkg --configure -a' to correct the problem. rich

Re: [clamav-users] Heuristics.Phishing.Email.SpoofedDomain

2017-11-15 Thread Kris Deugau
micah anderson wrote: I keep having people complaining about False Positives due to Heuristics.Phishing.Email.SpoofedDomain - my research has shown me that the reason this is happening is because of Outlook's "advanced threat protection" which wraps urls in a "safelink" url, I really didn't wa

Re: [clamav-users] Heuristics.Broken.Executable FOUND for core files/core dumps

2017-11-07 Thread Kris Deugau
Ravi wrote: Thanks Kris for your comments. Currently we scan the incoming files(zips/archives) placed on the local hard drive with the clamdscan(which uses clamd daemon), Can you share more info on what you meant on handling the result differently if we are using the clamdscan? Whatever calls c

Re: [clamav-users] Heuristics.Broken.Executable FOUND for core files/core dumps

2017-11-06 Thread Kris Deugau
Ravi wrote: Hi, Looking forward for comments and suggestions for the below reported issue from the community. Well, to answer your original question, it looks to me like the test is doing exactly what it's supposed to. Core dumps would quite reasonably contain executable chunks, but may not

Re: [clamav-users] Run script on file scanned but no virus found

2017-11-02 Thread Kris Deugau
Chris Johnson wrote: I have on access scanning configured and we successfully run a script when a virus is found. This script allows us to make a log that the file was scanned and a virus found. However we'd also like to run a script to make a log when the file has been scanned and no virus has

[clamav-users] OT: mailing list behaviours (Re: Part 2: Dynamic engine module for scanning media files (e.g., MP3, MP4, etc.)?)

2017-09-19 Thread Kris Deugau
Crystalslave wrote: Return-Path: harlequin...@gmail.com First off, my apologies for the confusion. This is my first time posting to a mailing list; I didn't really know how to handle the return path thing, so I had to start over. Is this better? The return path goes at the top of the message bod

Re: [clamav-users] How to know if yara rules are being run?

2017-07-06 Thread Kris Deugau
Mark Foley wrote: So, the question posted below remains: Will the expetr.yara rule, described in this thread, run as is, or not, on Linux? Any valid signature file will be loaded and used. Any *invalid* signature file will cause clamd to exit. If clamd is running, and you've been able to co

Re: [clamav-users] clamav-users Digest, Vol 150, Issue 19

2017-06-01 Thread Kris Deugau
outre...@epsilon.com wrote: Hi Al, Could you please confirm exactly what is the issue you see with the links? As far as I can see, they use standard link tracking. ^^ In my experience that, in and of itself, is often the problem. The c

[clamav-users] Signature specifics (was Re: Malware/ransomware and Yara signatures with clamav)

2017-05-15 Thread Kris Deugau
Cedric Knight wrote: Devs - is it possible to block PDFs based on containing '/JavaScript' and '/OpenAction' (or '/Launch')? I wish ClamAV has a hierarchy from definite signatures first to secondly checking heuristics... Not a ClamAV developer, but yes, you can create a signature for this. Y

Re: [clamav-users] ClamAV UnOfficial Database

2017-05-04 Thread Kris Deugau
Joel Esler (jesler) wrote: We already distribute some third party feeds into the official database, we have a program for that which can be found on our website. For my part I would far prefer an enhancement to freshclam to allow it to download arbitrary third-party signature sets, much as Sp

Re: [clamav-users] disabling a database

2017-05-01 Thread Kris Deugau
nobswolf wrote: Hello, I just added virus support by ClamAV to my email-server. I am almost satisfied. It already catched some "zero days". But I'd like to separate the detection of junk from the detection of malware. So I'd like to disable the junk detection in ClamAV. I commented out the Jur

Re: [clamav-users] Win.Trojan.Toa-5368540-0 - How many people need to complain before you listen?

2016-12-29 Thread Kris Deugau
Groach wrote: > If I could exclude the Clam default > signatures and just continue to use Sane then I would and then I could > turn back on quarantining to make our systems safe again. You can; turn off freshclam and delete the stock signature files. Also make sure that you don't use the --off

Re: [clamav-users] Probable false positive *.xlsm - Win.Trojan.Toa-5368540-0

2016-12-28 Thread Kris Deugau
Al Varnell wrote: > On Dec 27, 2016, at 1:53 PM, demonhunter wrote: >> Office Open XML file format (.doc(x|m), .xls(x|m), etc., >> https://en.wikipedia.org/wiki/Office_Open_XML) are ZIP files, and those with >> macros typically contain an OLE2 file named vbaProject.bin. This signature >> appear

Re: [clamav-users] Cannot skip OLE2 checking

2016-12-22 Thread Kris Deugau
Mark Foley wrote: > Kees - thanks for that info. So, basically I'd have to start a new clamd with > a > different socket and therefore pointing to a different config file. Not sure > then what the point of the --config-file parameter to clamdscan is ... It allows you to call a different clamd tha

Re: [clamav-users] Documentation for creating ndb signatures?

2016-10-26 Thread Kris Deugau
Joel Esler (jesler) wrote: > Dave, > > Check out: > https://github.com/vrtadmin/clamav-devel/blob/master/docs/signatures.pdf Unfortunately this document still leaves a number of questions, since it's quite easy to create a signature that looks to be valid but which ClamAV won't accept. And the

Re: [clamav-users] WSF viruses, and other issues

2016-10-24 Thread Kris Deugau
John T. Bryan wrote: > I’ve been running ClamAV now for some years as the virus-checking plug-in on > my main multi-client mail server. For a long time, I was very pleased with > it and how easily I was able to integrate it into the custom software back > when I first switched to it. > > Lately,

Re: [clamav-users] How to get each file status when scan a ditrtectory using clamdscan

2016-10-04 Thread Kris Deugau
crazy thinker wrote: > Hi, > > I would you like to get each file status call back in *Clamdscan output* > while perfrom scan over a dirtectory using *clamdscan*. but i able to get > a file status call back *(OR | ERROR| FOUND)* in *Clamdscan output* when > i perfrom scan over a *single file.

Re: [clamav-users] CryLocker and Cryptolocker

2016-09-15 Thread Kris Deugau
Matus UHLAR - fantomas wrote: > On 15.09.16 00:51, Reindl Harald wrote: >> frankly i have seen companies blocking every .doc and .xls attachment >> with a reject info that you should use .docx and .xslx becasue they >> can't contain macros (would be .docm for the new formats) > > .docm is docx wit

Re: [clamav-users] Match on raw .wsf file?

2016-09-02 Thread Kris Deugau
Steven Morgan wrote: > Please try clamscan --scan-html=no to turn off normalization. Mmmm. I suppose that's technically the functionality I'm asking for, but in its current form it's a pretty blunt instrument - it's all or nothing, especially if set for clamd with the "ScanHTML" option in clamd.c

Re: [clamav-users] Match on raw .wsf file?

2016-08-31 Thread Kris Deugau
Kris Deugau wrote: > Is there a way to force matching on the raw file, or at least control > the normalization to some degree so that formatting and details in the > original code aren't lost? As a complement to that question, is there a way to *force* other Javascript files to be

[clamav-users] Match on raw .wsf file?

2016-08-30 Thread Kris Deugau
Is there a way to force matching on the raw file, or at least control the normalization to some degree so that formatting and details in the original code aren't lost? I've been coming across .wsf files in .zip files, which are essentially Javascript wrapped in a very thin wrapper: [insert nasty

Re: [clamav-users] Understanding OLE2BlockMacros

2016-08-24 Thread Kris Deugau
Alex wrote: > Please don't send me to the amavis list - there must be someone who > uses both clamav and amavis that understands what's happening here. Much like SpamAssassin, Clamav in and of itself can only say "Matched signature " or "Triggered heuristic test ", or "Didn't match anything". It'

Re: [clamav-users] Heuristics.Phishing.Email.SpoofedDomain FP

2016-08-16 Thread Kris Deugau
Alex wrote: > Hi, > > I have a false-positive with Heuristics.Phishing.Email.SpoofedDomain > for capitaloneemail.com, but can't figure out how to use sigtool to > determine which actual domain it thinks was spoofed. > > # sigtool --find-sigs Heuristics.Phishing.Email.SpoofedDomain | > sigtool --d

Re: [clamav-users] ign2 whitelist don't work

2016-07-19 Thread Kris Deugau
Charles Swiger wrote: > On Jul 19, 2016, at 10:39 AM, Kris Deugau wrote: >> ClamAV hits on any of the Heuristics.* tests get flagged instead of >> treated the same as the signature-based hits, and that flag either >> causes an an adjustment in the SpamAssassin results

Re: [clamav-users] ign2 whitelist don't work

2016-07-19 Thread Kris Deugau
Charles Swiger wrote: > The milter approach is less flexible. With a scoring mechanism, you can rate > actual viruses sufficiently negative that the scoring algorithm will always > reject them. That depends on the milter you're using. My own favoured milter is MIMEDefang, which allows you do

Re: [clamav-users] ClamAV+exim: scanner finds not a single malware

2016-05-30 Thread Kris Deugau
Groach wrote: > As a side note: is anyone surprised a virus hasnt been released, > embedded in a 'password protected' Zip file (to fool AV scans) with the > body of the email sayuing something like "to fight against viruses and > to protect you, it is password protected. Your password is: ABC12

Re: [clamav-users] zip, rar, jar, ... how to delete all exe's and others files?

2016-04-14 Thread Kris Deugau
Steve Basford wrote: > 1) .rmd/.zmd databases are obsolete, they are replaced with .cdb > > More details: > https://github.com/vrtadmin/clamav-devel/blob/master/docs/signatures.pdf Does anyone have any examples of valid signatures for the .cdb sigfiles? I've tried a couple of times to port some

Re: [clamav-users] Clamd vs clamscan

2016-02-10 Thread Kris Deugau
Gene Heskett wrote: > But, I do wish that clamd would send me a substitute email advising that > it has stashed a suspect incoming email into the > mailfile /var/spool/mail/virii. I try to look that file over for FP's, > but quickly get lost in the visual garbage because its probably a zip'd >

Re: [clamav-users] Finding the spoofed domain

2015-12-15 Thread Kris Deugau
Alex wrote: > Steve Basford wrote: >> I've posted the email here: >> http://pastebin.com/n4WRjmzE > >> Got a match: f.email.americanexpress.com/ with /moc.sserpxenacirema >> Before inserting .: .f.email.americanexpress.com >> Lookup result: in regex list >> Phishcheck:host:.r.smartbrief.com >> Ph

Re: [clamav-users] Difficult malwarefiles - signature too short

2015-11-02 Thread Kris Deugau
G.W. Haywood wrote: > Hi there, > > On Mon, 2 Nov 2015, Hajo Locke wrote: > >> ... It seems to be so easy for a php-programmer to generate infinite >> number of malwarefiles ... > > That's correct. > > Any .php file sent here goes straight to /dev/null without inspection. I can't say I've seen

  1   2   >