VIRUS NAME: Java.Trojan.Agent-36975
TARGET TYPE: ANY FILE
OFFSET: *
DECODED SIGNATURE:
java*lang*String{WILDCARD_ANY_STRING}writeEmbeddedFile{WILDCARD_ANY_STRING}LPORT{WILDCARD_ANY_STRING}LHOST
I substituted "*" for "/" in the signature in order to prevent this message from being detected in route.
-Al-
On Tue, Oct 29, 2019 at 01:06 AM, Steffen Sledz wrote:
We've a really unexplainable behaviour related to clamdscan and tar.There's a tree of subdirs and files.If I tar the complete tree and scan it with 'clamdscan -v --fdpass all.tar' an infected file is reported: 'Java.Trojan.Agent-36975 FOUND'.If I tar all subdirs of the first level in separate tars and scan them, all of them are reported OK. Same if I scan all files one by one.So where's the infected file report is coming from? Any ideas?Environment:# lsb_release -aLSB Version: n/aDistributor ID: openSUSEDescription: openSUSE Leap 15.1Release: 15.1Codename: n/a# rpm -q -i clamavName : clamavVersion : 0.101.4Release : lp151.205.1Architecture: x86_64Install Date: Mo 28 Okt 2019 16:03:42 CETGroup : Productivity/SecuritySize : 2383988License : GPL-2.0-onlySignature : RSA/SHA256, Fr 25 Okt 2019 16:59:46 CEST, Key ID 69d1b2aaee3d166aSource RPM : clamav-0.101.4-lp151.205.1.src.rpmBuild Date : Fr 25 Okt 2019 16:59:23 CESTBuild Host : lamb53Relocations : (not relocatable)Vendor : obs://build.opensuse.org/securityURL : http://www.clamav.netSummary : Antivirus Toolkit_______________________________________________clamav-users mailing listclamav-users@lists.clamav.nethttps://lists.clamav.net/mailman/listinfo/clamav-usersHelp us build a comprehensive ClamAV guide:https://github.com/vrtadmin/clamav-faqhttp://www.clamav.net/contact.html#ml