Some ramsomware send an email with a link to download one zip with a excel or word docunent with a macro. This macro download another code and crypt files on pc. I need to scan all possible downloaded file for my custommers... The macro signature is present in clamav unofficial signatures, but i need clamav download and scan all url in email.... phishsigs is not for me, i need MailFollowURL.... Thanks
Il 31 Mar 2017 8:14 PM, Steven Morgan <smor...@sourcefire.com> ha scritto: Mauro, It is not clear what MailFollowURL did. Have a look at docs/phishsigs_howto.pdf for a description of how to scan for URLs. This may have subsumed MailFollowURL. Steve On Fri, Mar 31, 2017 at 12:34 PM, Mauro Celli <mauro.ce...@2000net.it> wrote: > Hi, > i need to scan link in email, in the past i use MailFollowUrl but now is > deprecated, > There are an alternative to make this test? > Thanks > _______________________________________________ > clamav-users mailing list > clamav-users@lists.clamav.net > http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users > > > Help us build a comprehensive ClamAV guide: > https://github.com/vrtadmin/clamav-faq > > http://www.clamav.net/contact.html#ml > _______________________________________________ clamav-users mailing list clamav-users@lists.clamav.net http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/vrtadmin/clamav-faq http://www.clamav.net/contact.html#ml _______________________________________________ clamav-users mailing list clamav-users@lists.clamav.net http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/vrtadmin/clamav-faq http://www.clamav.net/contact.html#ml