Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: ClamAV: users

Virus submission timing

 

 

ClamAV users RSS feed   Index | Next | Previous | View Threaded


dantearmok at gmail

May 18, 2009, 7:30 AM

Post #1 of 4 (660 views)
Permalink
Virus submission timing

At 10:40 AM -0400 5/12/2009, Tom Shaw wrote
in the thread "Re: [Clamav-users] VIRUS? PHISH?"
>
>You can check by sending to scan [at] virustotal with the word SCAN
>as the subject and attach the suspected malware. virustotal will
>forward to AV vendors including ClamAV.

Hi,

After submitting something to VirusTotal, and getting the response
back that shows only one or two products detected it as a virus...

VirusTotal then automatically forwards the item to all the vendors?
Or is there further action required by me to initiate this?

Once the ClamAV team receives the virus, on average currently how
long before its sig is added to the database?

Thanks,
- Dan.
--
- Psychoceramic Emeritus; South Jersey, USA, Earth
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


acabng at digitalfuture

May 18, 2009, 8:03 AM

Post #2 of 4 (623 views)
Permalink
Re: Virus submission timing [In reply to]

Dan wrote:
> Hi,
>
> After submitting something to VirusTotal, and getting the response
> back that shows only one or two products detected it as a virus...
>
> VirusTotal then automatically forwards the item to all the vendors?

Yes, if the vendor asks for the stuff. Yes we do receive samples we miss
at VT.

> Or is there further action required by me to initiate this?

Since VT feeds are pretty massive and contains very random files
(including false positives from other vendors, lots of tests - the bad
guys know about VT as well) we generally classify those samples as low
priority.
On the other hand, user sumbissions have a much higher priority and are
generally processed first.

> Once the ClamAV team receives the virus, on average currently how
> long before its sig is added to the database?

Due to the huge number of submissions we have to process it is really
hard to tell. It mostly depends on the severity of the threat, that is,
how many of such samples we've already received. Big outbreaks generally
take less than one hour. Unique samples may need several days to be
processed.

-aCaB
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


dantearmok at gmail

May 18, 2009, 8:41 AM

Post #3 of 4 (626 views)
Permalink
Re: Virus submission timing [In reply to]

At 5:03 PM +0200 5/18/2009, aCaB wrote:
>Since VT feeds are pretty massive and contains very random files
>(including false positives from other vendors, lots of tests - the bad
>guys know about VT as well) we generally classify those samples as low
>priority.
>On the other hand, user sumbissions have a much higher priority and are
>generally processed first.

So you would prefer we submit directly to ClamAV at
<http://cgi.clamav.net/sendvirus.cgi>

> > Once the ClamAV team receives the virus, on average currently how
>> long before its sig is added to the database?
>
>Due to the huge number of submissions we have to process it is really
>hard to tell. It mostly depends on the severity of the threat, that is,
>how many of such samples we've already received. Big outbreaks generally
>take less than one hour. Unique samples may need several days to be
>processed.

Ok. Thx.

- Dan.
--
- Psychoceramic Emeritus; South Jersey, USA, Earth
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


acabng at digitalfuture

May 18, 2009, 9:05 AM

Post #4 of 4 (626 views)
Permalink
Re: Virus submission timing [In reply to]

Dan wrote:
> So you would prefer we submit directly to ClamAV at
> <http://cgi.clamav.net/sendvirus.cgi>

Yes, we do.

-acab
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml

ClamAV users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.