[clamav-users] ClamAV - Emotet - Malware not detected

Joel Esler (jesler) jesler at cisco.com
Wed Sep 16 12:57:13 UTC 2020


Can you provide the SHA256 hash of a couple of the files?

-- 
Joel Esler
Manager, Communities Division
Cisco Talos Intelligence Group
http://www.talosintelligence.com | https://www.snort.org

> On Sep 16, 2020, at 4:43 AM, clamav-users at lists.clamav.net wrote:
> 
> Hello,
> 
> Today, we transmitted a significant amount of Emotet files that were undetected by ClamAV,
> (verification done under VirusTotal).
> 
> Is there a reason why the Emotet detection rate is very low for ClamAV?
> 
> Thank you in advance.
> 
> Best regards,
> ---
> Cyril AECK
> 
> Service du numérique - SNum
> UNI/DETN
> Messagerie & conférences à distance
> 
> Tel.  04 74 27 52 13
> Port. 06 63 16 23 32
> 
> 
> 
> _______________________________________________
> 
> clamav-users mailing list
> clamav-users at lists.clamav.net
> https://lists.clamav.net/mailman/listinfo/clamav-users
> 
> 
> Help us build a comprehensive ClamAV guide:
> https://github.com/vrtadmin/clamav-faq
> 
> http://www.clamav.net/contact.html#ml

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.clamav.net/pipermail/clamav-users/attachments/20200916/1500cb3c/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3010 bytes
Desc: not available
URL: <https://lists.clamav.net/pipermail/clamav-users/attachments/20200916/1500cb3c/attachment.bin>


More information about the clamav-users mailing list