[Community-sigs] Win.Trojan.Downloader

Mariano Graziano magrazia at sourcefire.com
Mon Aug 1 06:34:33 EDT 2016


Hi Askar,
the updated signature has been submitted for the FP tests and
it should be published soon.

Thanks.

On Sun, Jul 31, 2016 at 6:00 PM, Askar Dyussekeyev <dyussekeyev at yandex.kz>
wrote:

>
> Win.Trojan.Downloader:1:28900:85C0744785D2743653565789C689D78B4FFC578B56FC4A7820668B0683C60229D17E16F266AF751189CB565789D1F366A75F5E740C89D9EBEA5A31C0EB0A31C0C35A89F829D0D1E85F5E5BC3
>
> signature looks for specific block of code
>
> detections(162):
> 00a95890f38dbdb2c2ddd8149ab898fc
> 0143762dc9502cb9550d6cb64f3ea138
> 014bd844fa16b35d4996b7a19e6cbaac
> 018dc8c7268357f96e247240c70b33c4
> 0210dfc82cfa2b1d44ec0465a039c49e
> 027bbed314fe1c29e48da664cce4b897
> ................................
> f64b3007811a43430c92f6971f8064f8
> fc0cfe36328e94bca6261dda4db75f7e
> fdd05962c71d86908cff524d8b125ee2
> fe840b3a14cd062b3a6e5b299a3f3e41
> ff30e33de34710174ab7b65b11644ec1
> _______________________________________________
> Community-sigs mailing list
> Community-sigs at lists.clamav.net
> http://lists.clamav.net/cgi-bin/mailman/listinfo/community-sigs
>
> http://www.clamav.net/contact.html#ml
>



More information about the Community-sigs mailing list