[BlueOnyx:14162] Re: Solarspeed AV-SPAM V5

Michael Stauber mstauber at blueonyx.it
Tue Dec 24 15:42:18 -05 2013


Hi Colin,

> Why does Clam not pick these viruses up?

Clam AV is signature based. If the attackers vary the codebase a bit,
then the existing signatures won't catch it. There are constant updates
to the signature database to catch all known strands, but sometimes the
newest batch sails right through until someone creates signatures for
those as well.

-- 
With best regards

Michael Stauber



More information about the Blueonyx mailing list