spam_marketing.ndb from SecuriteInfo.com are good enough to protect mailboxes,
because Win32 malwares are not spreaded by mail nowadays.
In any other case (system protection, HTTP scanning, file hosting, etc...) you
have to get Clamav official + 3rd party signatures for a maximum detection.
--
Best r
rimental way. ClamAV
> Performance better than earlier now.
To be clear : The signature databases provided by SecuriteInfo.com have to be
used *with* the official ones from Clamav.
The aim of our signature databases is *not* to replace official ones from
Clamav.
--
Best regards,
Arnaud Jacques
S
rrors, including typo errors.
Please try this :
$ sigtool --md5 * > /home/test/Documents/CustomDB.hdb
Then
/Downloads/exe$ clamscan -r -d /home/test/Documents/CustomDB.hdb
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom
23346 has been published today morning.
It seems you have a few updates late.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
___
clamav-users m
Received this message :
-- Message transmis --
Objet : False Positive of IObit product by ClamAV
Date : vendredi 31 mars 2017, 14:52:42
De : beta feedback
Hi ClamAV,
This is Coco from IObit (www.iobit.com).
Please forward this email to the person who may concern. This
Hello Alex,
> Hi, I reported an encrypted word macro virus this morning, and this
> evening it is still not detected by sanesecurity or clamav proper.
Could you please send it to webmas...@securiteinfo.com too ?
Thank you.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook :
d
> /var/lib/clamav/clamav-a0e1b3646bf0af582c18764ec2fd4
This night I has upload failure for securiteinfo.hdb resulting a corrupted
file. This is resolved now.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/1328725234922
Steve,
> Time: 86.344 sec (1 m 26 s)
That's why we should use clamdscan instead of clamscan. Clamscan reload all
databases each time, this takes too much time.
Btw, what was the CPU for this test ?
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.c
s :)
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
___
clamav-users mailing list
clamav-users@lists.clamav.net
http://lists.clamav.net/cgi-bin/mailman/l
Selçuk,
> in redhat El 6 version thereis no clamdscan command .
It is in the "clamd" package.
http://rpm.pbone.net/index.php3/stat/4/idpl/34508318/dir/redhat_el_6/com/clamd-0.99.2-1.el6.x86_64.rpm.html
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www
Hello Selçuk,
> when i try to run clamscan for single file on tmp folder it takes 12
> minutes !!!
Please use clamdscan.
How many time it takes to scan the same file ?
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523
s when javascript.ndb has more than 50k lines.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
___
clamav-users mailing list
clamav-users@lists.clamav.ne
acques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
___
clamav-users mailing list
clamav-users@lists.clamav.net
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users
Help us b
s problem resolved.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
___
clamav-users mailing list
clamav-users@lists.clamav.net
http://lists.clamav.ne
Hello,
> Does anybody even provide signatures for android malware?
We (SecuriteInfo.com) provide 85000+ signatures for Android malwares.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfo
Yes, maybe javascript.ndb too big for your VM. Can you remove it and retry
please ?
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
___
clamav-u
Hello,
Does Swizzor detection still maintened ?
I cannot see option to enable swizzor detection in clamscan --help or
https://github.com/vrtadmin/clamav-devel/blob/master/etc/clamd.conf.sample
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages
rus/improve-detection-rate-of-zero-day-malwares-for-clamav.shtml?lg=en
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
___
Help us build a comprehen
Community-sigs mailing list down or is it just me ?
I tried to send an email with no result.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
Hello,
A mail file is not recognized as mail, but ascii by clamscan.
Clamdscan recognize it as mail. This is good !
This looks like a bug.
A sample has been submitted. MD5 of submitted sample is
ca13562c8f8d1ce581c627d9a007f6a0
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook
up
>
> To note, the document opens fine in Microsoft Word, and oletools has no
> issues dumping out the macros.
Maybe related to
https://github.com/vrtadmin/clamav-devel/commit/dbd2653d835b5446aed780112d376f5b2596519f
See this in the next version of Clamav.
--
Best regards,
Arnaud Jacq
Hello Alain,
> If you could
> be so kind to point them out, we'll let you know what their status is.
I have sent a few email @community-sigs to point them out.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492
> * Joel Esler (jesler) :
> > http://blog.clamav.net/2016/07/crdf-joins-clamav-signature-partner.html
>
> Are these signatures already active?
Yes, since a few days
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/
that too ;)
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
___
Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq
http://www.clamav.net/contact.html#ml
t; There are lots of places
> out there that make detection other than us, but not distributed in an
> large fashion, regression tested, etc.
How do you know ? Do you think SaneSecurity or Securiteinfo.com does not verify
their signatures before
publishing ? Do you know our technical infrast
h with your OS version ?
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
___
Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/
Hello,
> Can you tell me … Can I install ClamAV to a server so that it is accessible
> via HTTP? Id like to do scans from http.
Mod_clamav for Apache.
http://software.othello.ch/mod_clamav/
But I don't know if it compiles on HP-UX.
--
Best regards,
Arnaud Jacques
SecuriteInfo.co
em is this ascii malware cannot be normalised, but it should be.
The sample has been sent to http://www.clamav.net/reports/malware
md5sum of malware sent is : 023bff926f5852ba0e58a72c10e77f2a
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/Secur
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
___
Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq
http://www.clamav.net/contact.html#ml
ING: Local version: 0.99 Recommended version: 0.99.2
This has been discussed on debian-user mailin list :
https://lists.debian.org/debian-user/2016/05/msg00953.html
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter
Hello,
> clamav is not in the standard debian jessie repository?
Yes it is :
https://packages.debian.org/jessie/clamav
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfo
Hello Al,
> Because the signatures may not be identical and could be looking for two
> different things so that a variant of the original malware that could be
> caught by one sig will be overlooked by the other.
This can not happened with Securiteinfo.com sigs. We remove signatures whe
d use less RAM should be a priority. Am I wrong
?
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
___
Help us build a comprehensive ClamAV guid
ion.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @SecuriteInfoCom
___
Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq
http://www.clamav.
eck this too :
https://www.securiteinfo.com/services/anti-spam-anti-virus/improve-detection-rate-of-zero-day-malwares-for-clamav.shtml?lg=en
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : @Sec
ctory /var/lib/clamav/daily.cld
ERROR: listdb: Error listing database /var/lib/clamav/daily.cld
Tested on 3 different servers. /tmp is not full.
sigtool -V
ClamAV 0.99/21492/Thu Apr 14 04:35:17 2016
Any clue ?
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/
Hello Alain,
> Did you normalize your file? I.e. Clamscan--leave-temps?
You didn't understand :)
If I normalize the file, the HTML comments are deleted. I need them to create
a signature.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.c
8.7
Scanned directories: 0
Scanned files: 1
Infected files: 0
Data scanned: 0.00 MB
Data read: 0.00 MB (ratio 0.00:1)
Time: 0.004 sec (0 m 0 s)
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
ascii, etc) but keeps the html comments.
On my side, a signature is ready to detect hundreds of thousands of
JS.Includer. I'm ready to publish it in the official Clamav database when this
new engine feature is ready. This could greatly improve Clamav detection
ratio.
--
Best regards,
Arnaud J
Hello Kurt,
> is detecting as PHP.Shell-83,
For me PHP.Shell-83 is wrong. It contains 0d0a. It means it has been created
with a non-normalized ascii file.
I guess it should be corrected.
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfo
Hello Marco,
> [3rd Party] javascript.ndb: 70417 sigs
You didn't update SecuriteInfo.com signatures. ATM, javascript.ndb has 48734
signatures for the free edition, and 25530 signatures for the paid edition.
That's why it takes so long to reload your database.
Please update.
--
db, which
> symlinks to /usr/local/maldetect/tmp/.runtime.user.19086.hdb, which does
> not exist.
>
> Any clues on this?
Juste delete the missing symlinks and restart Clamav.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/1328725234
Port 80 is http. So I believe the problem is not certificate related.
Btw, if you use a real browser, like firefox for PC, you will see my
certificate have green bar, with no warning.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/
t www.securiteinfo.com (IP: 62.210.244.190)
There is actually no issue at securiteinfo.com. Bandwith and response time are
OK
http://tools.pingdom.com/fpt/#!/ceNl1v/http://www.securiteinfo.com
Did you try to download manually with a browser ?
Can you see the web page at http://www.securiteinfo.com ?
cial Clamav databases.
Furthermore, I think this is a bad idea to lower detection ratio due to a
hadware limitation.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Facebook : https://www.facebook.com/pages/SecuriteInfocom/132872523492286
Twitter : https://twitter.com/SecuriteInfoCom
_
ll be run. So it will load 8 instance of
signature databases into RAM.
The best settings I use in my script is :
ls -d bin/* |parallel clamdscan -m --no-summary {} >yourlogfile.txt
As far as I know, it is faster than clamdscan -m bin/*
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
Face
Hello Clamav users,
Now, SecuriteInfo.com provides a new kind of signatures for Clamav. Here are
the features :
* 0-day malware signatures, based on real malwares on the wild.
* More than 500.000 signatures !
* Detection rate increase up to 80% on 0-day malwares.
* We detect any kind of
xt
>
> In this case, should I rely on the first line of output?
Short answer : Yes !
Long answer :
PDF are containers like zip, rar, tar, etc... Different kind of files are
emmbedded wintin.
So the first ligne is the real file format (=file extension)
--
Best regards,
Arnaud Jacques
Secur
2>&1|grep
"Recognized"
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
https://www.facebook.com/pages/SecuriteInfocom/132872523492286
___
Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq
http://www.clamav.net/contact.html#ml
P file with password : infected
I will include them for my alternative signatures
https://www.securiteinfo.com/services/clamav_unofficial_malwares_signatures.shtml
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
https://www.facebook.com/pages/SecuriteInfocom/132872523
My idea is not replacing HTTP with HTTPS. It is just adding support for HTTPS
to freshclam.
Many website have switched from HTTP to SSL in the last years. I guess this is
the natural evolution of the web. This is my opinion.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
_
r web servers. It could be a good idea if
freshclam support this protocol. What do you think ?
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
___
Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq
http://www.clama
URLs. May be a good start.
--
Best regards,
Arnaud Jacques
SecuriteInfo.com
___
Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq
http://www.clamav.net/contact.html#ml
> Can anyone tell me how many signatures does Clam virus database have? Or
> how many malwares can it detect?
3rd Party (distributed by SecuriteInfo.com
https://securiteinfo.com/services/clamav_unofficial_malwares_signatures.shtml) :
328587 securiteinfo.hdb
2600 securiteinfobat.hd
Arnaud Jacques
Consultant Sécurité
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securiteinfo.com
La Sécurité Informatique - La Sécurité des Informations.
266, rue de Villers
60123 Bonneuil en Valois
___
___
sultant Sécurité
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securiteinfo.com
La Sécurité Informatique - La Sécurité des Informations.
266, rue de Villers
60123 Bonneuil en Valois
___
___
http://lurker.clamav.net/list/clamav-users.html
thing to do. Other
> than that, what could I possibly be doing wrong?
>
> Thanks!
Your sample has been submitted to the Clamav team.
Thank you for reporting.
Best regards,
--
Arnaud Jacques
Consultant Sécurité
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
Hello Markus,
Le vendredi 2 Septembre 2005 01:00, Markus Beck a écrit :
> Hello Arnaud,
>
> On Thu, 1 Sep 2005 23:33:26 +0200
>
> "Securiteinfo.com" <[EMAIL PROTECTED]> wrote:
> > Well, to create a Clamav signature, you can read this first :
> > http
Hello Markus,
Le jeudi 1 Septembre 2005 23:11, Markus Beck a écrit :
> Hello Arnaud,
>
> thank You for Your fast answer!
>
> On Thu, 1 Sep 2005 18:18:04 +0200
>
> "Securiteinfo.com" <[EMAIL PROTECTED]> wrote:
> > There is different techniques to
variant (e.g. different IRC-Channels used in this case) could be
caught.
--
Cordialement,
Arnaud Jacques
Consultant Sécurité
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securiteinfo.com
La Sécurité Informatique - La Sécurité des Information
scanning.
See --exclude option for details.
Best regards,
--
Cordialement,
Arnaud Jacques
Consultant Sécurité
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securiteinfo.com
La Sécurité Informatique - La Sécurité des Informations.
266, rue de Vill
net/doc/0.86rc1/clamdoc.pdf
--
Cordialement,
Arnaud Jacques
Consultant Sécurité
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securiteinfo.com
La Sécurité Informatique - La Sécurité des Informations.
266, rue de Villers
60123 Bon
/ Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securiteinfo.com
La Sécurité Informatique - La Sécurité des Informations.
266, rue de Villers
60123 Bonneuil en Valois
___
___
http://lurker.clamav.
ies?
FYI, this is an example. Don't use it in production environment.
Best regards,
Cordialement,
Arnaud Jacques
Consultant Sécurité
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securiteinfo.com
La Sécurité Informatique - La Sécurité des
any error message, it is a vscan-clamav bug (time out ?). Please
contact the developpers of vscan-clamav.
Best regards,
--
Cordialement,
Arnaud Jacques
Consultant Sécurité
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securiteinfo.com
La
il.
> Can anyone help me?
Reinstall from source code.
Regards,
--
Cordialement,
Arnaud Jacques
Consultant Sécurité
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securiteinfo.com
La Sécurité Informatique - La Sécurité des Informations
Le dimanche 5 Juin 2005 23:20, Joanna Roman a écrit :
> --- "Securiteinfo.com" <[EMAIL PROTECTED]>
>
> wrote:
> > Le dimanche 5 Juin 2005 22:15, Joanna Roman a
> >
> > écrit :
> > > --- Niek <[EMAIL PROTECTED]> wrote:
> > > &
t; Networks does HW acceleration then.
> I have real doubt
> about the result. I wonder how much gain they can
> achieve.
Dedicated hardware acceleration is always fastest than the fastest CPU.
Have you got a 3D acceleration video card in your PC ?
If yes, why ? :)
--
Cordialement,
Arn
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securiteinfo.com
La Sécurité Informatique - La Sécurité des Informations.
266, rue de Villers
60123 Bonneuil en Valois
___
___
http://lurker.clamav.net/list/clamav-users.html
e docs. If it still doesn't work, remove all clamav files
(binaries+conf) and do a fresh install from sources.
Regards,
--
Cordialement,
Arnaud Jacques
Consultant Sécurité
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securiteinfo.com
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securiteinfo.com
La Sécurité Informatique - La Sécurité des Informations.
266, rue de Villers
60123 Bonneuil en Valois
___
>
>
Le mardi 31 Mai 2005 17:29, Odhiambo Washington a écrit :
> * Securiteinfo.com <[EMAIL PROTECTED]> [20050531 16:27]: wrote:
> > Le mardi 31 Mai 2005 14:58, Odhiambo Washington a écrit :
> > > * Christopher X. Candreva <[EMAIL PROTECTED]> [20050531 15:31]: wrot
3:50:19 2005
Please, set the "Debug" flag in your clamd.conf, rescan the sample, and send
us the logs.
Thank you by advance.
--
Cordialement,
Arnaud Jacques
Consultant Sécurité
Téléphone / Fax : +33-(0)3.44.39.76.46
Portable : +33-(0)6.24.40.95.03
E-mail : [EMAIL PROTECTED]
Securitein
Hello,
Le vendredi 1 Avril 2005 00:50, Joanna Roman a écrit :
> I noticed that a lot of virus sigs are not available
> in the virus database. For example, I tried to search
> in the virus database
> (http://clamav-du.securesites.net/cgi-bin/clamgrok)
> for HTML.Phishing.Bank-156, which is in the l
y, you can own a few % of speed for each scanned files.
Regards,
___
Arnaud Jacques
Consultant Sécurité
Securiteinfo.com
___
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users
75 matches
Mail list logo