Re: [clamav-users] signature for cve2017-11882

2021-04-04 Thread G.W. Haywood via clamav-users
Hi there, On Sun, 4 Apr 2021, Jigar via clamav-users wrote: I agree with you and also aware about it as old vulnerability and to use of latest/patched software. However, my intention was to detect it before it get deliver to user. As I said a week ago, if you can place somewhere on the Web a

Re: [clamav-users] signature for cve2017-11882

2021-04-03 Thread Jigar via clamav-users
Hello, Thank you.. I agree with you and also aware about it as old vulnerability and to use of latest/patched software. However, my intention was to detect it before it get deliver to user. Especially when other AV could detect it and block it. I will wait for response from clamav team. With R

Re: [clamav-users] signature for cve2017-11882

2021-04-03 Thread G.W. Haywood via clamav-users
Hi there, On Sat, 3 Apr 2021, Jigar via clamav-users wrote: Any update w.r.t. submitted infected file and signature?. This vulnerability was patched by Microsoft more than three years ago. For example, see https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2017-11882 There sho

Re: [clamav-users] signature for cve2017-11882

2021-04-03 Thread Jigar via clamav-users
Hello, Any update w.r.t. submitted infected file and signature?. With Regards Jigar On Thu, Apr 1, 2021, 09:26 Jigar wrote: > Hello, > > With reference to uploaded infected file and generated signature on > 30/March/2021, we hope the clamav team is further checking. > > Meanwhile, for ready re

Re: [clamav-users] signature for cve2017-11882

2021-03-31 Thread Jigar via clamav-users
Hello, With reference to uploaded infected file and generated signature on 30/March/2021, we hope the clamav team is further checking. Meanwhile, for ready reference, we have enabled the signature on the mail server and have not found any false positive till today. With Regards Jigar Raval

Re: [clamav-users] signature for cve2017-11882

2021-03-29 Thread Jigar via clamav-users
Hello, I have uploaded the infected file in clamav malware report submission. Kindly look into it. I have also herewith attached signature generated using it. With Regards Jigar Raval On Sun, Mar 28, 2021 at 1:26 PM G.W. Haywood via clamav-users wrote: > > Hello again, > > On Sun, 28 Mar 20

Re: [clamav-users] signature for cve2017-11882

2021-03-28 Thread Jigar via clamav-users
Hello, I just tried using the following command but it is not detecting it. clamscan -d javascript.ndb Receipt.xlsx I feel it is different varient in cve 2017-11882. On Sun, Mar 28, 2021, 15:19 Arnaud Jacques wrote: > Hello Jigar, > > > > > clam clam 312952834 Mar 9 10:48 securiteinfoold.

Re: [clamav-users] signature for cve2017-11882

2021-03-28 Thread Arnaud Jacques
Hello Jigar, clam clam 312952834 Mar 9 10:48 securiteinfoold.hdb clam clam 16405860 Mar 26 09:36 securiteinfo.hdb clam clam 7203325 Mar 26 09:36 securiteinfohtml.hdb clam clam 8421132 Mar 26 13:32 securiteinfoascii.hdb Why you do not have javascript.ndb ??? It can detect some cve2017

Re: [clamav-users] signature for cve2017-11882

2021-03-28 Thread G.W. Haywood via clamav-users
Hello again, On Sun, 28 Mar 2021, Jigar via clamav-users wrote: On Sat, Mar 27, 2021 at 11:28 PM G.W. Haywood via clamav-users wrote: This is a rather old CVE, what databases do you use for your ClamAV installation? Perhaps what you have seen recently is a new threat which has been engineered

Re: [clamav-users] signature for cve2017-11882

2021-03-27 Thread Jigar via clamav-users
Hello, Thank you for valuable inputs. We have herewith attached a screenshot of eset detection as cve2017-11882. This may further help. We have also scannws using the latest clamav signature, porcupine, etc. but could not detect it. So, we tried to prepare it using the malicious file. Brief Ana

Re: [clamav-users] signature for cve2017-11882

2021-03-27 Thread G.W. Haywood via clamav-users
Hi there, On Sat, 27 Mar 2021, Jigar via clamav-users wrote: In the first week of March 2021, multiple users had received email with xlsx attachment having exploit for CVE-2017-11882. The clamav could not detect it but other antivirus like eScan and ESET could detect it as malware threat. Sig