I am seeing lots of different version of ransomware .js downloaders 
(telescript, locky, and many others and variants) for which I have been feeding 
 the CalmAV team and creating sigs pushed out as winnow sigs in Steve’s feed.  
I can tell you that all that I have and am feeding have not been detected by 
ClamAV when I detected them.

> On Mar 15, 2016, at 2:15 PM, Al Varnell <> wrote:
> That’s the KeRanger ransomeware which we dealt with last weekend.  Not 
> related to Teslacrypt AFAIK.
> -Al-
> On Tue, Mar 15, 2016 at 10:45 AM, Dennis Peterson wrote:
>> Already in the wild.
> _______________________________________________
> Help us build a comprehensive ClamAV guide:

Attachment: signature.asc
Description: Message signed with OpenPGP using GPGMail

Help us build a comprehensive ClamAV guide:

Reply via email to