[clamav-users] Current replacement for --max-ratio?

Kris Deugau kdeugau at vianet.ca
Fri Jan 14 18:43:16 UTC 2022


I've just come across a presumed-malicious .zip file of about 500K that 
contains a ~315M ISO image, which in turn appears to contain a ~315M 
executable file.

After a bit of searching and testing I see the --max-ratio option has 
been removed from clamscan, and ArchiveMaxCompressionRatio in clamd.conf 
has been deprecated.

Are there any remaining (or new?) options that might help flag 
hypercompressed files like this?

-kgd


More information about the clamav-users mailing list