Re: [clamav-users] Generating signatures for malware

2012-08-30 Thread Dennis Peterson
On 8/30/12 4:21 AM, G.W. Haywood wrote: Please would someone explain to me the use of "{7-8}"? I do not recognize it as valid regular expression syntax. Here is an example used in a Sane Security signature: http://sane.mxuptime.com/s.aspx?id=Sanesecurity.Phishing.Auction.1749 It is an offs

Re: [clamav-users] Generating signatures for malware

2012-08-30 Thread Maarten Broekman
> -Original Message- > > Some of the phishing content that I'm finding is resulting in hex > > dumps in the 10k+ character range and I think it's more dangerous to > > replace sections with '*' than to replace certain substrings with > > specific length wildcards. > > Please would someone

Re: [clamav-users] Generating signatures for malware

2012-08-30 Thread G.W. Haywood
Hello again, On Thu, 30 Aug 2012, Maarten Broekman wrote: Some of the phishing content that I'm finding is resulting in hex dumps in the 10k+ character range and I think it's more dangerous to replace sections with '*' than to replace certain substrings with specific length wildcards. This br