Cisco-Talos / clamav

ClamAV - Documentation is here: https://docs.clamav.net
https://www.clamav.net/
GNU General Public License v2.0
4.43k stars 706 forks source link

Annoy.PDF is not being detected by Clam Av #1247

Closed mohit8786 closed 7 months ago

mohit8786 commented 7 months ago

Hey Team,

Clam Av(version- 1.2.0/27247/Tue Apr 16) is not detecting the attached File. Annoy.pdf which is a test file for the viruses. Please look into this. annoy copy.pdf

Best regards,

HydraDragonAntivirus commented 7 months ago

I working on Xylent which is a ClamAV based and it should detect this due to his behaviour but normal ClamAV also should detect this due to shutdown 10 or less command. You can create YARA rule for detect this thing.

micahsnyder commented 7 months ago

@mohit8786 Thank you for reporting the undetected malware. Unfortunately, this ticket queue is just for software defects in ClamAV. Please report undetected malware using this form: https://clamav.net/reports/malware Reports using that web form will be handled by the Cisco Talos Threat Research team.

You can find additional contact and community information here:

@HydraDragonAntivirus Please do not take advantage of user complaints and bug reports on Github or on our Discord server to advertise your project. It is fine to share your project with our community, such as posting new release updates to our mailer or #showcase chat channel, but it is inappropriate to solicit users that are seeking help with a specific ClamAV issue, or are seeking to contribute to ClamAV.

If you have signatures you wish to contribute to the ClamAV community, you may submit them to one or both of these locations: