[clamav-users] Malware/ransomware and Yara signatures with clamav

Alex mysqlstudent at gmail.com
Sat May 13 17:16:21 UTC 2017


Hi,

So you've probably heard of the latest ransomware dubbed WannaCry. I'm
wondering if anyone has figured out a way to integrate the yara
signatures for these types of exploits with spamassassin?

https://www.us-cert.gov/ncas/alerts/TA17-132A

What is the status of development of integration of yara rules into clamav?

I submitted two more password encrypted word macro viruses as
false-positives to the clamav team several days ago, and they still
aren't being marked properly. I need another way to more quickly
identify vulnerabilities and exploits.

Thanks,
Alex



More information about the clamav-users mailing list