Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: ClamAV: users

Janicab Definitions

 

 

ClamAV users RSS feed   Index | Next | Previous | View Threaded


alvarnell at mac

Jul 24, 2013, 11:50 PM

Post #1 of 3 (101 views)
Permalink
Janicab Definitions

A definition was added today (Wednesday) for Win.Trojan.Janicab which I assume is based on the malware described by F-Secure on Tuesday <http://www.f-secure.com/weblog/archives/00002581.html>.

The OS X version of Janicab was announced by F-Secure over a week before on July 15
<http://www.f-secure.com/weblog/archives/00002576.html> based on a posting found on VirusTotal first submitted on 2013-07-12 05:03:36 UTC
<https://www.virustotal.com/en/file/3bc13adad9b7b60354d83bc27a507864a2639b43ec835c45d8b7c565e81f1a8f/analysis/>.

Where is the definition for OSX.Trojan.Janicab which was made available on VT almost two weeks ago. 22 of 47 A-V scanners are currently able to detect it.

I realize that Apple eventually took action to disable this Malware for the current version of OS X, but still….


-Al-
--
Al Varnell
Mountain View, CA

_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


azidouemba at sourcefire

Jul 25, 2013, 7:25 AM

Post #2 of 3 (92 views)
Permalink
Re: Janicab Definitions [In reply to]

Updated signatures with the coverage you are looking for will be released
shortly.

Thanks,

- Alain


On Thu, Jul 25, 2013 at 2:50 AM, A K Varnell <alvarnell [at] mac> wrote:

> A definition was added today (Wednesday) for Win.Trojan.Janicab which I
> assume is based on the malware described by F-Secure on Tuesday <
> http://www.f-secure.com/weblog/archives/00002581.html>.
>
> The OS X version of Janicab was announced by F-Secure over a week before
> on July 15
> <http://www.f-secure.com/weblog/archives/00002576.html> based on a
> posting found on VirusTotal first submitted on 2013-07-12 05:03:36 UTC
> <
> https://www.virustotal.com/en/file/3bc13adad9b7b60354d83bc27a507864a2639b43ec835c45d8b7c565e81f1a8f/analysis/
> >.
>
> Where is the definition for OSX.Trojan.Janicab which was made available on
> VT almost two weeks ago. 22 of 47 A-V scanners are currently able to
> detect it.
>
> I realize that Apple eventually took action to disable this Malware for
> the current version of OS X, but still….
>
>
> -Al-
> --
> Al Varnell
> Mountain View, CA
>
> _______________________________________________
> Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
> http://www.clamav.net/support/ml
>
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


alvarnell at mac

Jul 26, 2013, 6:30 PM

Post #3 of 3 (85 views)
Permalink
Re: Janicab Definitions [In reply to]

Thanks, I'm seeing them at this time.

-Al-

On Jul 25, 2013, at 7:25 AM, Alain Zidouemba <azidouemba [at] sourcefire> wrote:
> Updated signatures with the coverage you are looking for will be released
> shortly.
>
> Thanks,
>
> - Alain
>
>
> On Thu, Jul 25, 2013 at 2:50 AM, A K Varnell <alvarnell [at] mac> wrote:
>
>> A definition was added today (Wednesday) for Win.Trojan.Janicab which I
>> assume is based on the malware described by F-Secure on Tuesday <
>> http://www.f-secure.com/weblog/archives/00002581.html>.
>>
>> The OS X version of Janicab was announced by F-Secure over a week before
>> on July 15
>> <http://www.f-secure.com/weblog/archives/00002576.html> based on a
>> posting found on VirusTotal first submitted on 2013-07-12 05:03:36 UTC
>> <
>> https://www.virustotal.com/en/file/3bc13adad9b7b60354d83bc27a507864a2639b43ec835c45d8b7c565e81f1a8f/analysis/
>>> .
>>
>> Where is the definition for OSX.Trojan.Janicab which was made available on
>> VT almost two weeks ago. 22 of 47 A-V scanners are currently able to
>> detect it.
>>
>> I realize that Apple eventually took action to disable this Malware for
>> the current version of OS X, but still….
>>
>>
>> -Al-
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml

ClamAV users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.