вторник, 26 апреля 2011 г.

Clam AV - ложное срабатывание или нет [False Positive or not]??

Народ, кто знает, не пойму. В логах вирусной активности:


Sun Apr 24 22:46:26 2011 -> /var/spool/exim/scan/1QE4K9-000GQ1-P9/1QE4K9-000GQ1-P9.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 09:49:48 2011 -> /var/spool/exim/scan/1QEEg6-000MjL-Ic/1QEEg6-000MjL-Ic.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 09:52:01 2011 -> /var/spool/exim/scan/1QEEiG-000Mlz-Ej/1QEEiG-000Mlz-Ej.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 09:52:08 2011 -> /var/spool/exim/scan/1QEEiN-000Mm4-4z/1QEEiN-000Mm4-4z.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 09:52:15 2011 -> /var/spool/exim/scan/1QEEiU-000MmA-N6/1QEEiU-000MmA-N6.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 09:52:22 2011 -> /var/spool/exim/scan/1QEEib-000MmI-9f/1QEEib-000MmI-9f.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 09:52:36 2011 -> /var/spool/exim/scan/1QEEip-000Mma-Hd/1QEEip-000Mma-Hd.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 09:52:42 2011 -> /var/spool/exim/scan/1QEEiv-000Mmm-52/1QEEiv-000Mmm-52.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 09:52:47 2011 -> /var/spool/exim/scan/1QEEj0-000Mmv-NL/1QEEj0-000Mmv-NL.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 09:54:46 2011 -> /var/spool/exim/scan/1QEEku-000MoS-RQ/1QEEku-000MoS-RQ.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 09:56:50 2011 -> /var/spool/exim/scan/1QEEmv-000MsJ-89/1QEEmv-000MsJ-89.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 10:12:10 2011 -> /var/spool/exim/scan/1QEF1l-000NBR-Dp/1QEF1l-000NBR-Dp.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 10:21:59 2011 -> /var/spool/exim/scan/1QEFBH-000NSq-Ec/1QEFBH-000NSq-Ec.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 10:22:36 2011 -> /var/spool/exim/scan/1QEFBr-000NUY-W1/1QEFBr-000NUY-W1.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 10:45:15 2011 -> /var/spool/exim/scan/1QEFXl-000O6Z-Sd/1QEFXl-000O6Z-Sd.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 10:48:19 2011 -> /var/spool/exim/scan/1QEFal-000OBv-0u/1QEFal-000OBv-0u.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 12:02:23 2011 -> /var/spool/exim/scan/1QEGkO-0000Ds-5s/1QEGkO-0000Ds-5s.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 12:03:36 2011 -> /var/spool/exim/scan/1QEGlZ-0000Fb-5b/1QEGlZ-0000Fb-5b.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 12:04:38 2011 -> /var/spool/exim/scan/1QEGmZ-0000H8-9z/1QEGmZ-0000H8-9z.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 12:05:25 2011 -> /var/spool/exim/scan/1QEGnJ-0000Ii-Eg/1QEGnJ-0000Ii-Eg.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 12:55:16 2011 -> /var/spool/exim/scan/1QEHZY-0001mE-1B/1QEHZY-0001mE-1B.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 15:30:29 2011 -> /var/spool/exim/scan/1QEJzh-0005qW-UI/1QEJzh-0005qW-UI.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 15:43:43 2011 -> /var/spool/exim/scan/1QEKCV-0006CV-5A/1QEKCV-0006CV-5A.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 18:11:28 2011 -> /var/spool/exim/scan/1QEMVV-000967-UE/1QEMVV-000967-UE.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 18:14:23 2011 -> /var/spool/exim/scan/1QEMYK-00098d-VU/1QEMYK-00098d-VU.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 18:15:32 2011 -> /var/spool/exim/scan/1QEMZR-00099L-BH/1QEMZR-00099L-BH.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 18:17:07 2011 -> /var/spool/exim/scan/1QEMaz-0009AY-Av/1QEMaz-0009AY-Av.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 18:18:14 2011 -> /var/spool/exim/scan/1QEMc3-0009BY-PZ/1QEMc3-0009BY-PZ.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 22:44:11 2011 -> /var/spool/exim/scan/1QEQlH-000BSN-Rv/1QEQlH-000BSN-Rv.eml: PUA.PDF.EmbeddedJS FOUND
Mon Apr 25 22:54:33 2011 -> /var/spool/exim/scan/1QEQvY-000BX2-7N/1QEQvY-000BX2-7N.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 22:54:41 2011 -> /var/spool/exim/scan/1QEQvg-000BXE-Qw/1QEQvg-000BXE-Qw.eml: PUA.PDF.OpenActionObject FOUND
Mon Apr 25 22:54:46 2011 -> /var/spool/exim/scan/1QEQvl-000BXN-MT/1QEQvl-000BXN-MT.eml: PUA.PDF.OpenActionObject FOUND
Tue Apr 26 11:07:11 2011 -> /var/spool/exim/scan/1QEcMZ-000ING-D5/1QEcMZ-000ING-D5.eml: Worm.Mydoom.I FOUND
Tue Apr 26 11:07:14 2011 -> /var/spool/exim/scan/1QEcMb-000ING-9L/1QEcMb-000ING-9L.eml: Worm.Mydoom.I FOUND
Tue Apr 26 11:07:31 2011 -> /var/spool/exim/scan/1QEcMs-000INz-Pr/1QEcMs-000INz-Pr.eml: Suspect.DoubleExtension-zippwd-9 FOUND
Tue Apr 26 16:13:30 2011 -> /var/spool/exim/scan/1QEh90-0000cI-A8/1QEh90-0000cI-A8.eml: Worm.Mydoom.I FOUND
Видно, что основную массу срабатываний составляют некие 
PUA.PDF.EmbeddedJS, PUA.PDF.OpenActionObject.
 
Народ активно жалуется, что не отправлялись pdf-файлы, которые раньше уходили нормально. Собственно, вопрос, это ложное срабатывание или нет??? Потому что сегодня уже ничего подобного не наблюдается... Случайно сигнатуры в базу попали?? Кто в курсе, подскажите плиз, у меня к сожалениб нет на руках образца файла. 

Комментариев нет:

Отправить комментарий