Re: [clamav-users] Locky Dridex plan

2016-03-26 Thread Joel Esler (jesler)
We even have a list for package maintainers to sign up on, where I notify the maintainers of upcoming releases. Very little traffic. -- Joel Esler iPhone On Mar 26, 2016, at 9:31 PM, Benny Pedersen mailto:m...@junc.eu>> wrote: one more reason to use gentoo where i created a github master trun

Re: [clamav-users] Locky Dridex plan

2016-03-26 Thread Benny Pedersen
one more reason to use gentoo where i created a github master trunk ?, now i just emerge @live-rebuild to get the latest stable clamav nothing happens if users dont notifify maintainers of precompiled problems ___ Help us build a comprehensive ClamAV g

Re: [clamav-users] Locky Dridex plan

2016-03-26 Thread C.D. Cochrane
Thank you all for sharing Linux distribution and clamav source build options. I probably should have kept my "whine" to myself :) There are always at least 5 ways to get the job done with Linux. Just have to find the one that works best for my server. ...Chris   >> And I am guessing my Linux

Re: [clamav-users] Locky Dridex plan

2016-03-26 Thread Scott Kitterman
On March 26, 2016 11:24:32 AM EDT, Freddie Cash wrote: >On Mar 26, 2016 6:26 AM, "C.D. Cochrane" wrote: >> >> And I am guessing my Linux distro will not just seamlessly move on to >0.99 by itself with an "apt-get update". > >Debian 6 includes ClamAV 0.98. Thus, anything newer than that will hav

Re: [clamav-users] Locky Dridex plan

2016-03-26 Thread Stefan Hornburg (Racke)
o your sources.list. Regards Racke > > > Sent: Friday, March 25, 2016 at 11:00 PM > From: "Joel Esler (jesler)" > To: "ClamAV users ML" > Subject: Re: [clamav-users] Locky Dridex plan > Generally this means that we just won't regression test

Re: [clamav-users] Locky Dridex plan

2016-03-26 Thread Freddie Cash
On Mar 26, 2016 6:26 AM, "C.D. Cochrane" wrote: > > And I am guessing my Linux distro will not just seamlessly move on to 0.99 by itself with an "apt-get update". Debian 6 includes ClamAV 0.98. Thus, anything newer than that will have a newer version of ClamAV. And if you are running anything old

Re: [clamav-users] Locky Dridex plan

2016-03-26 Thread ellanios82
On 03/26/2016 03:26 PM, C.D. Cochrane wrote: And I am guessing my Linux distro will not just seamlessly move on to 0.99 by itself with an "apt-get update". . - openSUSE have a Rolling Release named "Tumbleweed" https://www.opensuse.org/ .. - believe Tumbleweed u

Re: [clamav-users] Locky Dridex plan

2016-03-26 Thread Dennis Peterson
I am guessing my Linux distro will not just seamlessly move on to 0.99 by itself with an "apt-get update". Sent: Friday, March 25, 2016 at 11:00 PM From: "Joel Esler (jesler)" To: "ClamAV users ML" Subject: Re: [clamav-users] Locky Dridex plan Generally this means

Re: [clamav-users] Locky Dridex plan

2016-03-26 Thread Joel Esler (jesler)
I am guessing my Linux distro will not just seamlessly move on to 0.99 by itself with an "apt-get update". Sent: Friday, March 25, 2016 at 11:00 PM From: "Joel Esler (jesler)" mailto:jes...@cisco.com>> To: "ClamAV users ML" mailto:clamav-users@lists.clamav

Re: [clamav-users] Locky Dridex plan

2016-03-26 Thread C.D. Cochrane
And I am guessing my Linux distro will not just seamlessly move on to 0.99 by itself with an "apt-get update".     Sent: Friday, March 25, 2016 at 11:00 PM From: "Joel Esler (jesler)" To: "ClamAV users ML" Subject: Re: [clamav-users] Locky Dridex plan Generally

Re: [clamav-users] Locky Dridex plan

2016-03-25 Thread Joel Esler (jesler)
Generally this means that we just won't regression test signatures against that version anymore. -- Joel Esler Manager, Talos Group Sent from my iPad On Mar 25, 2016, at 10:12 PM, Al Varnell mailto:alvarn...@mac.com>> wrote: Can you be a little more specific about the manner in which this will

Re: [clamav-users] Locky Dridex plan

2016-03-25 Thread Al Varnell
Can you be a little more specific about the manner in which this will take place? Does it just mean no support or do you plan to poison pill the database so the engine will no longer function, as has happened in the past. Sent from Janet's iPad -Al- On Mar 25, 2016, at 6:24 PM, "Joel Esler (je

Re: [clamav-users] Locky Dridex plan

2016-03-25 Thread Joel Esler (jesler)
We've completely rewritten the submission process as a result of feedback from the list. It should be functioning fine now. As far as a "plan" for addressing Dridex. We have a lot of things in the works now that we have a completely new signature system, giving us capabilities that we did no

Re: [clamav-users] Locky Dridex plan

2016-03-25 Thread Gene Heskett
On Friday 25 March 2016 17:12:06 Groach wrote: > ClamAV signatures have never caught a dridex variant for me (and they > have been around a long time). You need to head to over to Sane > Security and start using their definitions - they have perfect > Zero-hour detections for Dridex (and other Ma

Re: [clamav-users] Locky Dridex plan

2016-03-25 Thread Groach
ClamAV signatures have never caught a dridex variant for me (and they have been around a long time). You need to head to over to Sane Security and start using their definitions - they have perfect Zero-hour detections for Dridex (and other Macroware viruses). You wont be disappointed any more.

[clamav-users] Locky Dridex plan

2016-03-25 Thread C.D. Cochrane
Hi, I receive a Locky-ransomware variant almost every day as an email attachment. So far ClamAV has failed to detect it. Each file has had a unique signature. Does ClamAV have a detection plan and/or work in progress that will start to detect future variants of this? thanks, Chris ___