Re: [clamav-users] Heuristics.Filetype.ZipWithJS

2017-03-28 Thread Matteo Dessalvi
On 03/28/2017 02:23 PM, Reindl Harald wrote: Heuristics are *not* signatures Uh-oh, sorry. You are right, my mistake entirely. Regards, Matteo ___ clamav-users mailing list clamav-users@lists.clamav.net http://lists.clamav.net/cgi-bin/mailman/li

Re: [clamav-users] Heuristics.Filetype.ZipWithJS

2017-03-28 Thread Matteo Dessalvi
Hello. Regarding your fist question you can execute the following tools from the command line: sigtool --find-sigs=Heuristics.Filetype.ZipWithJS-6162396-0 | sigtool --decode-sigs 'ZipWithJS' is for sure not in the ClamAV source code: it is just a part of a string used to identify the signatur

Re: [clamav-users] ClamAV Virus Definition Update Problem

2017-01-13 Thread Matteo Dessalvi
Hello. On the logs you posted I can see the following line: [...] freshclam[5948]: Connecting via 10.93.220.10 It means this system is trying to reach the ClamAV mirrors through a proxy (which I guess is internal, since you are using an IP address belonging to the RFC1918 private network range)

Re: [clamav-users] No notice of OLE2.ContainsMacros [OT]

2016-12-19 Thread Matteo Dessalvi
confusing! I suppose if I hadn't changed the subject line back to my original subject my reply might have unsubscribed be as well. Thanks for the clarification. --Mark -Original Message----- To: From: Matteo Dessalvi Date: Mon, 19 Dec 2016 16:15:37 +0100 Subject: Re: [clamav-users] No

Re: [clamav-users] No notice of OLE2.ContainsMacros [OT]

2016-12-19 Thread Matteo Dessalvi
Mark, I believe it was not a suggestion. It often happens here that a user which want to unsubscribe {him,her}self from the ClamAV mailing list just reply to whatever message is crossing the list, asking to be 'unsubscribed'. Best regards, Matteo On 12/19/2016 04:05 PM, Mark Foley wrote: Ple

Re: [clamav-users] Goldeneye ransomware

2016-12-09 Thread Matteo Dessalvi
basford wrote: Hi... this is detected with Badmacro.ndb. On 8 December 2016 16:54:26 Matteo Dessalvi wrote I also ran a quick analysis on Malwr: https://malwr.com/analysis/Y2VhYWNjZTk3NWFhNGRhMDg5OWYwY2E5MzdjNDA2M2I/ Best regards, Matteo

[clamav-users] Goldeneye ransomware

2016-12-08 Thread Matteo Dessalvi
Hi all. In the last couple of days our Human Resources have received a bunch of email with this kind of ransomware attached (as Excel file) and ClamAV was unfortunately unable to stop it. Anybody stumbled upon it recently? If yes, did you create your own signature for it? I have just submitted

Re: [clamav-users] ClamAV malware report: include info from Malwr?

2016-11-16 Thread Matteo Dessalvi
de if the submitted sample has to be included in the signatures or not (assuming there's an actual human being which will make the final decision at the end). Regards, Matteo On 11/16/2016 03:35 PM, Steve Basford wrote: On Wed, November 16, 2016 1:56 pm, Matteo Dessalvi wrote: It ende

[clamav-users] ClamAV malware report: include info from Malwr?

2016-11-16 Thread Matteo Dessalvi
interface will get a better idea of why I am submitting the stuff. Best regards, Matteo -- Matteo Dessalvi Abteilung: HPC Ort: SB2.4.109 Tel.: 06159-712030 Fax.: +49 6159 71 2986 E-Mail: m.dessa...@gsi.de GSI Helmholtzzentrum für Schwerionenforschung GmbH Planckstraße 1, 64291 Darmstad

Re: [clamav-users] ClamAV/AIX6.1/gcc4.8.3 - openssl error -X509_VERIFY_PARAM_new missing

2016-04-13 Thread Matteo Dessalvi
guide: https://github.com/vrtadmin/clamav-faq http://www.clamav.net/contact.html#ml -- Matteo Dessalvi Abteilung: HPC Ort: SB2.4.109 Tel.: 06159-712030 Fax.: +49 6159 71 2986 E-Mail: m.dessa...@gsi.de GSI Helmholtzzentrum für Schwerionenforschung GmbH Planckstraße 1 64291 Darmstadt www.gsi.de

Re: [clamav-users] C++ Compiler for IBM AIX-6100

2016-03-24 Thread Matteo Dessalvi
here: ftp://www.oss4aix.org/compatible/aix61/ On the IBM blog there's also an howto (although for AIX 7.1): https://www.ibm.com/developerworks/community/blogs/mhhaque/entry/how_to_use_gcc_or_g_compiler_on_aix_7?lang=en Best regards, Matteo Dessalvi On 23.03.2016 05:10, Krishnakumar Nair wrote: H