Re: [clamav-users] Needed to whitelist Email.Phishing.RPMSG_Downloader-10004958-0

2023-07-17 Thread Christopher Marczewski
net/mailman/listinfo/clamav-users > > > Help us build a comprehensive ClamAV guide: > https://github.com/Cisco-Talos/clamav-documentation > > https://docs.clamav.net/#mailing-lists-and-chat > -- Christopher Marczewski Research Engineer, Talos Cisco Systems 443-832-2975

Re: [clamav-users] Email.Phishing.RPMSG_Downloader-10004958-0 false positive

2023-07-17 Thread Christopher Marczewski
; DECODED SUBSIGNATURE: > application/x-microsoft-rpmsg-message; > * SUBSIG ID 11 > +-> OFFSET: ANY > +-> SIGMOD: NONE > +-> DECODED SUBSIGNATURE: > name="message_v{WILDCARD_IGNORE}.rpmsg" > > > ___

Re: [clamav-users] Win.Virus.Memery-10002766-0 on version 26922

2023-05-30 Thread Christopher Marczewski
list subscription / unsubscribe: > https://lists.clamav.net/mailman/listinfo/clamav-users > > > Help us build a comprehensive ClamAV guide: > https://github.com/Cisco-Talos/clamav-documentation > > https://docs.clamav.net/#mailing-lists-and-chat > -- Christopher Marczews

Re: [clamav-users] Vbs.Trojan.AsyncRAT-9889434-1

2023-05-24 Thread Christopher Marczewski
/ unsubscribe: > https://lists.clamav.net/mailman/listinfo/clamav-users > > > Help us build a comprehensive ClamAV guide: > https://github.com/Cisco-Talos/clamav-documentation > > https://docs.clamav.net/#mailing-lists-and-chat > -- Christopher Marczewski Research Engineer, Tal

Re: [clamav-users] False positive, My program is recently Started to be flagged with Win.Dropper.Tinba-9943147-0

2022-07-11 Thread Christopher Marczewski
> https://docs.clamav.net/#mailing-lists-and-chat >> > ___ > > clamav-users mailing list > clamav-users@lists.clamav.net > https://lists.clamav.net/mailman/listinfo/clamav-users > > > Help us build a comprehensive ClamAV g

Re: [clamav-users] Clamav found in php files Archive.Test.Agent2-9953724-0

2022-06-24 Thread Christopher Marczewski
Build 26583 for daily.cvd is ready for use. We're also taking additional steps and safety measures to ensure experimental signatures are not eligible for additions to any published CVD. On Fri, Jun 24, 2022 at 10:36 AM Christopher Marczewski < cmarczew...@sourcefire.com> wrote: >

Re: [clamav-users] Clamav found in php files Archive.Test.Agent2-9953724-0

2022-06-24 Thread Christopher Marczewski
amav-users@lists.clamav.net >> https://lists.clamav.net/mailman/listinfo/clamav-users >> >> >> Help us build a comprehensive ClamAV guide: >> https://github.com/Cisco-Talos/clamav-documentation >> >> https://docs.clamav.net/#mailing-lists-and-chat >&g

Re: [clamav-users] Virus not detected

2022-03-21 Thread Christopher Marczewski
//github.com/vrtadmin/clamav-faq > > http://www.clamav.net/contact.html#ml > > > > ___ > > clamav-users mailing list > clamav-users@lists.clamav.net > https://lists.clamav.net/mailman/listinfo/clamav-users > > > Help us

Re: [clamav-users] Malware found on datadog folder in centos. Is it false-positive?

2022-01-31 Thread Christopher Marczewski
LqfdL >> >> ___ >> >> clamav-users mailing list >> clamav-users@lists.clamav.net >> https://lists.clamav.net/mailman/listinfo/clamav-users >> >> >> Help us build a comprehensive ClamAV guide: >> https:/

Re: [clamav-users] Lot of false positives detected from signature Java.Malware.CVE_2021_44228-9915814-0

2021-12-20 Thread Christopher Marczewski
d take appropriate action on this? >> >> > > -- > > <https://smart.salesforce.com/sig/pbhootra//us_mb/default/link.html> > > ___ > > clamav-users mailing list > clamav-users@lists.clamav.net > https://l

Re: [clamav-users] Nonsensical noreplies from ClamAV team

2021-12-09 Thread Christopher Marczewski
Win.Malware.Agent-9914239-0 will be published shortly and covers both DLL samples. On Thu, Nov 18, 2021 at 2:16 PM Christopher Marczewski < cmarczew...@sourcefire.com> wrote: > Hello Alessandro, > > Given the SHA256 hashes in those replies, we've confirmed it was the > o

Re: [clamav-users] WARNING: clamav quarantined libcurl.so.4.5.0 and broke a bunch of hosts

2021-11-19 Thread Christopher Marczewski
er-9910195-0 FOUND > > Jeff > > ___ > > clamav-users mailing list > clamav-users@lists.clamav.net > https://lists.clamav.net/mailman/listinfo/clamav-users > > > Help us build a comprehensive ClamAV guide: > https://github.com/vrtadmin/clamav-fa

Re: [clamav-users] Nonsensical noreplies from ClamAV team

2021-11-18 Thread Christopher Marczewski
> Best > Ale > -- > > > > > > > > > > > > > > > > ___ > > clamav-users mailing list > clamav-users@lists.clamav.net > https://lists.clamav.net/mailman/listinfo/clamav-users > >

Re: [clamav-users] Perplexing response to malware submission.

2021-08-06 Thread Christopher Marczewski
ment from the ClamAV team. The report was sent using > > the 'clamsubmit' utility, which does not offer an option to provide > > a description of the malware. > > > > What should I do now? > > > > ___ >

Re: [clamav-users] Virus definition Txt.Downloader.Generic-6810205-0

2020-09-24 Thread Christopher Marczewski
t; Help us build a comprehensive ClamAV guide: > https://github.com/vrtadmin/clamav-faq > > http://www.clamav.net/contact.html#ml > -- Christopher Marczewski Research Engineer, Talos Cisco Systems 443-832-2975 ___ clamav-users mailing list cla

Re: [clamav-users] FP with Osx.Trojan.EmPyre-6852410-0

2019-02-14 Thread Christopher Marczewski
_ > clamav-users mailing list > clamav-users@lists.clamav.net > http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users > > > Help us build a comprehensive ClamAV guide: > https://github.com/vrtadmin/clamav-faq > > http://www.clamav.net/contact.html#ml > --

Re: [clamav-users] False Positive Detected - Win.Malware.Triusor-6824994-0

2019-01-22 Thread Christopher Marczewski
___ > clamav-users mailing list > clamav-users@lists.clamav.net > http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users > > > Help us build a comprehensive ClamAV guide: > https://github.com/vrtadmin/clamav-faq > > http://www.clama

Re: [clamav-users] Pdf.Exploit.CVE_2017_3039-6300177-0 only with clamd

2017-05-02 Thread Christopher Marczewski
; $ sigtool --find Pdf.Exploit.CVE_2017_3039-6300177-0 > >>> $ > >> > >> I don't think it is related, but there was an issue with DNS that > stopped all updates after 23343 late Saturday until mid morning Monday > Pacific Time. > >> > >> -

Re: [clamav-users] Pdf.Exploit.CVE_2017_3039-6300177-0 only with clamd

2017-04-28 Thread Christopher Marczewski
> > clamav-users@lists.clamav.net > > http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users > > > > > > Help us build a comprehensive ClamAV guide: > > https://github.com/vrtadmin/clamav-faq > > > > http://www.clamav.net/contact.html#ml > > > > > _____

Re: [clamav-users] Html.Exploit.CVE_2017_0141-6003839-0 FP's

2017-03-16 Thread Christopher Marczewski
stinfo/clamav-users > > > Help us build a comprehensive ClamAV guide: > https://github.com/vrtadmin/clamav-faq > > http://www.clamav.net/contact.html#ml > -- Christopher Marczewski Research Engineer Talos Group cmarczew...@sourcefire.com Phone: 443.430.7118 __

Re: [clamav-users] Submitting False Negatives

2017-01-22 Thread Christopher Marczewski
If a virus is picked up as a generic > "Unix.Malware.Agent-1847425", does that mean that the sample was detected > as malicious through heuristics or something like that, but the actual > specific sample isn't known? > > Thanks for the info! > > On Wed, Jan 11, 201

Re: [clamav-users] Submitting False Negatives

2017-01-11 Thread Christopher Marczewski
info/clamav-users > > > Help us build a comprehensive ClamAV guide: > https://github.com/vrtadmin/clamav-faq > > http://www.clamav.net/contact.html#ml > -- Christopher Marczewski Research Engineer Talos Group cmarczew...@sourcefire.com Phone: 443.430.7118

[clamav-users] Win.Trojan.URLspoof-2 signtuare and WARC files

2016-12-20 Thread Christopher Marczewski
____ > clamav-users mailing list > clamav-users at lists.clamav.net > http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users > > > Help us build a comprehensive ClamAV guide: > https://github.com/vrtadmin/clamav-faq > > http://www.clamav.net/contact.html#ml -A