Re: [clamav-users] Win.Trojan.URLspoof-2 trigger source?

2016-12-08 Thread Al Varnell
On Thu, Dec 08, 2016 at 10:17 AM, Jay Gattuso wrote: > > (1)What's the signature trigger for Win.Trojan.URLspoof-2? You can find any current signature using or $ sigtool --find Win.Trojan.URLspoof-2 | sigtool --decode-sigs VIRUS NAME: Wi

[clamav-users] Win.Trojan.URLspoof-2 trigger source?

2016-12-08 Thread Jay Gattuso
I have a long running recurring issue that I'd appreciate any help. We have an automated ingest routine that runs any-old-binary through ClamAV. The sources of files is all over, and I've observed files that come in via a web harvesting tool result in a particular malware warning. The file type