Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: ClamAV: users

ZIP/Bredolab.A!Camelot

 

 

ClamAV users RSS feed   Index | Next | Previous | View Threaded


robert at schetterer

Jul 20, 2012, 8:22 AM

Post #1 of 7 (647 views)
Permalink
ZIP/Bredolab.A!Camelot

Hi, just was informed that some mails with
ZIP/Bredolab.A!Camelot

slipped through up2date clamav gateway , detected by
Microsoft Forefront

the sender is deutschepost.de
ever

someone an idea to that ?

--
Best Regards
MfG Robert Schetterer
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


steveb_clamav at sanesecurity

Jul 20, 2012, 8:41 AM

Post #2 of 7 (623 views)
Permalink
Re: ZIP/Bredolab.A!Camelot [In reply to]

> Hi, just was informed that some mails with
> ZIP/Bredolab.A!Camelot
>
> slipped through up2date clamav gateway , detected by
> Microsoft Forefront


Hi,

Did they slip past the Sanesecurity phish.ndb/rogue.hdb ones too?

Cheers,

Steve
Sanesecurity

_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


jesler at sourcefire

Jul 20, 2012, 9:02 AM

Post #3 of 7 (628 views)
Permalink
Re: ZIP/Bredolab.A!Camelot [In reply to]

On Jul 20, 2012, at 11:22 AM, Robert Schetterer <robert [at] schetterer> wrote:

> Hi, just was informed that some mails with
> ZIP/Bredolab.A!Camelot
>
> slipped through up2date clamav gateway , detected by
> Microsoft Forefront
>
> the sender is deutschepost.de
> ever
>
> someone an idea to that ?

If you have the files, can you upload them to ClamAV.net and then send the md5s back to the list so we can take a look?

--
Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
Sourcefire
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


robert at schetterer

Jul 20, 2012, 1:42 PM

Post #4 of 7 (623 views)
Permalink
Re: ZIP/Bredolab.A!Camelot [In reply to]

Am 20.07.2012 17:41, schrieb Steve Basford:
>
>> Hi, just was informed that some mails with
>> ZIP/Bredolab.A!Camelot
>>
>> slipped through up2date clamav gateway , detected by
>> Microsoft Forefront
>
>
> Hi,
>
> Did they slip past the Sanesecurity phish.ndb/rogue.hdb ones too?
>
> Cheers,
>
> Steve
> Sanesecurity
>
> _______________________________________________
> Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
> http://www.clamav.net/support/ml
>

Hi Steve ,yes they did, last update

2012-07-20 11:54 /var/lib/clamav/phish.ndb
2012-07-20 17:55 /var/lib/clamav/rogue.hdb

--
Best Regards
MfG Robert Schetterer
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


robert at schetterer

Jul 20, 2012, 1:44 PM

Post #5 of 7 (635 views)
Permalink
Re: ZIP/Bredolab.A!Camelot [In reply to]

Am 20.07.2012 18:02, schrieb Joel Esler:
> On Jul 20, 2012, at 11:22 AM, Robert Schetterer <robert [at] schetterer> wrote:
>
>> Hi, just was informed that some mails with
>> ZIP/Bredolab.A!Camelot
>>
>> slipped through up2date clamav gateway , detected by
>> Microsoft Forefront
>>
>> the sender is deutschepost.de
>> ever
>>
>> someone an idea to that ?
>
> If you have the files, can you upload them to ClamAV.net and then send the md5s back to the list so we can take a look?

sorry i dont quarantaine with milter, and have got no example
from Forefront

perhaps i will hold them until flood goes on

>
> --
> Joel Esler
> Senior Research Engineer, VRT
> OpenSource Community Manager
> Sourcefire
> _______________________________________________
> Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
> http://www.clamav.net/support/ml
>


--
Best Regards
MfG Robert Schetterer
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


robert at schetterer

Jul 20, 2012, 1:53 PM

Post #6 of 7 (624 views)
Permalink
Re: ZIP/Bredolab.A!Camelot [In reply to]

Am 20.07.2012 22:44, schrieb Robert Schetterer:
> Am 20.07.2012 18:02, schrieb Joel Esler:
>> On Jul 20, 2012, at 11:22 AM, Robert Schetterer <robert [at] schetterer> wrote:
>>
>>> Hi, just was informed that some mails with
>>> ZIP/Bredolab.A!Camelot
>>>
>>> slipped through up2date clamav gateway , detected by
>>> Microsoft Forefront
>>>
>>> the sender is deutschepost.de
>>> ever
>>>
>>> someone an idea to that ?
>>
>> If you have the files, can you upload them to ClamAV.net and then send the md5s back to the list so we can take a look?
>
> sorry i dont quarantaine with milter, and have got no example
> from Forefront
>
> perhaps i will hold them until flood goes on

no more further mails such kind were logged
latest all got rejected by rbls
but i contact the exchange admin to upload a sample here

http://cgi.clamav.net/sendvirus.cgi
>
>>
>> --
>> Joel Esler
>> Senior Research Engineer, VRT
>> OpenSource Community Manager
>> Sourcefire
>> _______________________________________________
>> Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
>> http://www.clamav.net/support/ml
>>
>
>


--
Best Regards
MfG Robert Schetterer
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


robert at schetterer

Jul 23, 2012, 6:15 AM

Post #7 of 7 (597 views)
Permalink
Re: ZIP/Bredolab.A!Camelot [In reply to]

Am 20.07.2012 22:53, schrieb Robert Schetterer:
> Am 20.07.2012 22:44, schrieb Robert Schetterer:
>> Am 20.07.2012 18:02, schrieb Joel Esler:
>>> On Jul 20, 2012, at 11:22 AM, Robert Schetterer <robert [at] schetterer> wrote:
>>>
>>>> Hi, just was informed that some mails with
>>>> ZIP/Bredolab.A!Camelot
>>>>
>>>> slipped through up2date clamav gateway , detected by
>>>> Microsoft Forefront
>>>>
>>>> the sender is deutschepost.de
>>>> ever
>>>>
>>>> someone an idea to that ?
>>>
>>> If you have the files, can you upload them to ClamAV.net and then send the md5s back to the list so we can take a look?
>>
>> sorry i dont quarantaine with milter, and have got no example
>> from Forefront
>>
>> perhaps i will hold them until flood goes on
>
> no more further mails such kind were logged
> latest all got rejected by rbls
> but i contact the exchange admin to upload a sample here
>
> http://cgi.clamav.net/sendvirus.cgi
>>
>>>
>>> --
>>> Joel Esler
>>> Senior Research Engineer, VRT
>>> OpenSource Community Manager
>>> Sourcefire
>>> _______________________________________________
>>> Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
>>> http://www.clamav.net/support/ml
>>>
>>
>>
>
>

Hi , it seems its got detected now
as Suspect.Trojan.Generic.FD-1

--
Best Regards
MfG Robert Schetterer
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml

ClamAV users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.