Re: [clamav-users] Question on attachments

2016-12-12 Thread Joel Esler (jesler)
File types are based upon their contents. Not their extensions. -- Joel Esler | Talos: Manager | jes...@cisco.com On Dec 12, 2016, at 11:43 AM, TR Shaw > wrote: How does ClamAV decide to unpack an attachment? In particular

Re: [clamav-users] Question on attachments

2016-12-12 Thread Steve basford
Hi Tom, .ftm files contain magic headers of various formats. Cat daily.ftm Cat sanesecurity.ftm The engine then unpacks if it's a zip etc and the unpacked exists. That's why your example filename still unpacks. You can also use. ftm to skip file formats from scanning. I'm mobile at the

Re: [clamav-users] Question on attachments

2016-12-12 Thread Reindl Harald
Am 12.12.2016 um 17:43 schrieb TR Shaw: How does ClamAV decide to unpack an attachment? In particular this is in reference to the recent Locky attachments that are zips but have the attachment extension “dip” clamav don't care about extensions as any other unix software

[clamav-users] Question on attachments

2016-12-12 Thread TR Shaw
How does ClamAV decide to unpack an attachment? In particular this is in reference to the recent Locky attachments that are zips but have the attachment extension “dip” ___ clamav-users mailing list clamav-users@lists.clamav.net