Re: Why are recent Firefox (for Windows) downloads ALL being found to contain ransomware?

"Valerie Snyder \(valsnyde\) via clamav-users" <[email protected]> Fri, 27 Mar 2026 16:00:48 +0000
Newsgroups gmane.comp.security.virus.clamav.user
Message-ID <SA1PR11MB5777B579EA02D98205EA4B00DE57A@SA1PR11MB5777.namprd11.prod.outlook.com>
--===============2465187646269291226==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_SA1PR11MB5777B579EA02D98205EA4B00DE57ASA1PR11MB5777namp_"

--_000_SA1PR11MB5777B579EA02D98205EA4B00DE57ASA1PR11MB5777namp_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Your clamd likely has the scan limits higher than defaults, so you can scan=
 larger files. In my own testing with the exe file from https://releases.mo=
zilla.org/pub/firefox/releases/115.34.0esr/win64/en-US/ on my laptop, I had=
 to increase several limits including max-recursion, max-scantime, and max-=
scansize from the default settings in order to get the detection.

VirusTotal uses the latest clamav, which means it will be using 1.5.2. Howe=
ver, it uses slightly lower scan limits than default, due to resource const=
raints. So, it is not going to alert on this file.

I'll forward the FP concern with our malware team so they're aware.

Regarding supported versions:


  *
We load-test new signatures on multiple releases including at least the lat=
est patch version of the latest release as well as the latest patch version=
 of supported LTS releases. At this time, that is the 1.5.2 version of 1.5 =
release and the 1.4.4 version of the 1.4 LTS release at a minimum.


  *
We only FP-test with a single version. It takes more resources to do FP-tes=
ting. We cannot afford to FP-test with multiple releases. It is highly unli=
kely for an old version to have more detections than a new version, since n=
ew features appear in new versions, and FPs are generally the result of bad=
 signatures, not bad file analyzer modules. So, we typically FP-test with t=
he latest version, though we don't necessarily bump the version in our FP-t=
est system right away.

I have been wanting to add the ability for freshclam to check if the curren=
t release and version are supported. It is going to require adding new DNS =
text records and then more frequent updates to the DNS records. Sadly, this=
 work keeps getting pushed out. But I 100% agree that we really should give=
 these notifications in freshclam.

Respectfully,
Val

Valerie Snyder (she/they)
ClamAV Development
Talos
Cisco Systems, Inc.
________________________________
From: clamav-users <[email protected]> on behalf of Pau=
l Kosinski via clamav-users <[email protected]>
Sent: Thursday, March 26, 2026 7:09 PM
To: [email protected] <[email protected]>; Andrew C=
 Aitchison via clamav-users <[email protected]>
Cc: Paul Kosinski <[email protected]>
Subject: Re: [clamav-users] Why are recent Firefox (for Windows) downloads =
ALL being found to contain ransomware?

I only have 1.0.9 installed, so I don't currently have a way to test it wit=
h either 1.5.x or 1.4.x.

So I submitted the "Firefox Setup 115.34.0esr.exe" file to VirusTotal, and =
none of their scanners found a virus.
I then asked VirusTotal (now owned by Google) what version of ClamAV they r=
un, but they haven't replied as of a few minutes ago.

I realize that ClamAV 1.0.9 is "EOL", but one can still obtain "official" s=
ignature files for another year beyond that.

Disturbingly, the Version Support Matrix says that, for 1.0 LTS, signatures=
 are NOT tested for false positives (FP) after 1.1 was released. In this ca=
se that's about 2.5 years BEFORE 1.0.9 EOL.

So WHAT EXACTLY DOES LTS MEAN?? For 1.0 LTS, it seems that no 1.0.x can be =
FULLY trusted after 1.1 was released. This is not what I would characterize=
 as LTS.

Furthermore, since the DB files can still be downloaded one year after nomi=
nal EOL (much less End Of Trust), why doesn't freshclam at least issue a wa=
rning among its large number of messages that EOL is past?

Finally, I intend to (try to) install 1.4 LTS in the near future. But will =
this help? According to the Version Support Matrix, FP testing will not be =
done for 1.4 LTS after 1.5 is released. Oops: that was last October (2025)!

---------------------

On Thu, 26 Mar 2026 18:17:38 +0000 (GMT)
Andrew C Aitchison via clamav-users <[email protected]> wrote:

> On Thu, 26 Mar 2026, Paul Kosinski via clamav-users wrote:
>
> > For example:
> >
> > Firefox Setup 140.9.0esr.exe  --> Win.Trojan.Spora-7724442-0 FOUND
> > Firefox Setup 115.34.0esr.exe --> Win.Trojan.Spora-7724442-0 FOUND
> > Firefox Setup 115.34.0esr.msi --> Win.Trojan.Spora-7724442-0 FOUND
> >
> >
> > These are from ClamAV 1.0.9 clamd on Linux receiving file to be scanned=
 over TCP.
>
> https://docs.clamav.net/faq/faq-eol.html#version-support-matrix
> suggests that 1.0.9 went end-of-life Nov-28 2025
> Version 1.3 is also EOL.
>
> Can you verify the problem with version 1.4.3 or 1.5.1 ?
>
_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat

--_000_SA1PR11MB5777B579EA02D98205EA4B00DE57ASA1PR11MB5777namp_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te=
xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class=
=3D"elementToProof">
Your clamd likely has the scan limits higher than defaults, so you can scan=
 larger files. In my own testing with the exe file from
<a href=3D"https://releases.mozilla.org/pub/firefox/releases/115.34.0esr/wi=
n64/en-US/">
https://releases.mozilla.org/pub/firefox/releases/115.34.0esr/win64/en-US/<=
/a>&nbsp;on my laptop, I had to increase several limits including max-recur=
sion, max-scantime, and max-scansize from the default settings in order to =
get the detection.&nbsp;</div>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te=
xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class=
=3D"elementToProof">
<br>
</div>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te=
xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class=
=3D"elementToProof">
VirusTotal uses the latest clamav, which means it will be using 1.5.2. Howe=
ver, it uses slightly lower scan limits than default, due to resource const=
raints. So, it is not going to alert&nbsp;on this file.</div>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te=
xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class=
=3D"elementToProof">
<br>
</div>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te=
xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class=
=3D"elementToProof">
I'll forward the FP concern with our malware team so they're aware.</div>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te=
xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class=
=3D"elementToProof">
<br>
</div>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te=
xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class=
=3D"elementToProof">
Regarding supported versions:</div>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te=
xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class=
=3D"elementToProof">
<br>
</div>
<ul style=3D"margin-top: 0px; margin-bottom: 0px;" data-editing-info=3D"{&q=
uot;applyListStyleFromLevel&quot;:false,&quot;unorderedStyleType&quot;:2}">
<li data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_Em=
beddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size:=
 12pt; color: rgb(0, 0, 0); list-style-type: &quot;- &quot;; --darkreader-i=
nline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreade=
r-text-000000, #e8e6e3));">
<div role=3D"presentation" class=3D"elementToProof">We load-test new signat=
ures on multiple releases including at least the latest patch version of th=
e latest release as well as the latest patch version of supported LTS relea=
ses. At this time, that is the 1.5.2
 version of 1.5 release and the 1.4.4 version of the 1.4 LTS release at a m=
inimum.</div>
</li></ul>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te=
xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));">
<br>
</div>
<ul style=3D"margin-top: 0px; margin-bottom: 0px;" data-editing-info=3D"{&q=
uot;applyListStyleFromLevel&quot;:false,&quot;unorderedStyleType&quot;:2}">
<li data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_Em=
beddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size:=
 12pt; color: rgb(0, 0, 0); list-style-type: &quot;- &quot;; --darkreader-i=
nline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreade=
r-text-000000, #e8e6e3));">
<div role=3D"presentation" class=3D"elementToProof">We only FP-test with a =
single version. It takes more resources to do FP-testing. We cannot afford =
to FP-test with multiple releases. It is highly unlikely for an old version=
 to have more detections than a new
 version, since new features appear in new versions, and FPs are generally =
the result of bad signatures, not bad file analyzer modules. So, we typical=
ly FP-test with the latest version, though we don't necessarily bump the ve=
rsion in our FP-test system right
 away.&nbsp;</div>
</li></ul>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te=
xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));">
<br>
</div>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te=
xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class=
=3D"elementToProof">
I have been wanting to add the ability for freshclam to check if the curren=
t release and version are supported. It is going to require adding new DNS =
text records and then more frequent updates to the DNS records. Sadly, this=
 work keeps getting pushed out.
 But I 100% agree that we really should give these notifications in freshcl=
am.&nbsp;</div>
<div class=3D"elementToProof" id=3D"Signature">
<div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E=
mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te=
xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class=
=3D"elementToProof">
<br>
</div>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Calibri, Arial=
, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader=
-inline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkrea=
der-text-000000, #e8e6e3));" class=3D"elementToProof">
Respectfully,</div>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Calibri, Arial=
, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader=
-inline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkrea=
der-text-000000, #e8e6e3));" class=3D"elementToProof">
Val</div>
<div data-darkreader-inline-color=3D"" style=3D"font-family: Calibri, Arial=
, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader=
-inline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkrea=
der-text-000000, #e8e6e3));" class=3D"elementToProof">
<br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Valerie Snyder (sh=
e/they)</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Development=
</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Cisco Systems, Inc=
.</span><br>
</div>
</div>
<div id=3D"appendonsend"></div>
<hr style=3D"display:inline-block;width:98%" tabindex=3D"-1">
<div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" st=
yle=3D"font-size:11pt" color=3D"#000000"><b>From:</b> clamav-users &lt;clam=
[email protected]&gt; on behalf of Paul Kosinski via clamav=
-users &lt;[email protected]&gt;<br>
<b>Sent:</b> Thursday, March 26, 2026 7:09 PM<br>
<b>To:</b> [email protected] &lt;[email protected]&=
gt;; Andrew C Aitchison via clamav-users &lt;[email protected]&=
gt;<br>
<b>Cc:</b> Paul Kosinski &lt;[email protected]&gt;<br>
<b>Subject:</b> Re: [clamav-users] Why are recent Firefox (for Windows) dow=
nloads ALL being found to contain ransomware?</font>
<div>&nbsp;</div>
</div>
<div class=3D"BodyFragment"><font size=3D"2"><span style=3D"font-size:11pt;=
">
<div class=3D"PlainText">I only have 1.0.9 installed, so I don't currently =
have a way to test it with either 1.5.x or 1.4.x.
<br>
<br>
So I submitted the &quot;Firefox Setup 115.34.0esr.exe&quot; file to VirusT=
otal, and none of their scanners found a virus.<br>
I then asked VirusTotal (now owned by Google) what version of ClamAV they r=
un, but they haven't replied as of a few minutes ago.<br>
<br>
I realize that ClamAV 1.0.9 is &quot;EOL&quot;, but one can still obtain &q=
uot;official&quot; signature files for another year beyond that.<br>
<br>
Disturbingly, the Version Support Matrix says that, for 1.0 LTS, signatures=
 are NOT tested for false positives (FP) after 1.1 was released. In this ca=
se that's about 2.5 years BEFORE 1.0.9 EOL.<br>
<br>
So WHAT EXACTLY DOES LTS MEAN?? For 1.0 LTS, it seems that no 1.0.x can be =
FULLY trusted after 1.1 was released. This is not what I would characterize=
 as LTS.<br>
<br>
Furthermore, since the DB files can still be downloaded one year after nomi=
nal EOL (much less End Of Trust), why doesn't freshclam at least issue a wa=
rning among its large number of messages that EOL is past?<br>
<br>
Finally, I intend to (try to) install 1.4 LTS in the near future. But will =
this help? According to the Version Support Matrix, FP testing will not be =
done for 1.4 LTS after 1.5 is released. Oops: that was last October (2025)!=
<br>
<br>
---------------------<br>
<br>
On Thu, 26 Mar 2026 18:17:38 +0000 (GMT)<br>
Andrew C Aitchison via clamav-users &lt;[email protected]&gt; w=
rote:<br>
<br>
&gt; On Thu, 26 Mar 2026, Paul Kosinski via clamav-users wrote:<br>
&gt; <br>
&gt; &gt; For example:<br>
&gt; &gt;<br>
&gt; &gt; Firefox Setup 140.9.0esr.exe&nbsp; --&gt; Win.Trojan.Spora-772444=
2-0 FOUND<br>
&gt; &gt; Firefox Setup 115.34.0esr.exe --&gt; Win.Trojan.Spora-7724442-0 F=
OUND<br>
&gt; &gt; Firefox Setup 115.34.0esr.msi --&gt; Win.Trojan.Spora-7724442-0 F=
OUND<br>
&gt; &gt;<br>
&gt; &gt;<br>
&gt; &gt; These are from ClamAV 1.0.9 clamd on Linux receiving file to be s=
canned over TCP.&nbsp;
<br>
&gt; <br>
&gt; <a href=3D"https://docs.clamav.net/faq/faq-eol.html#version-support-ma=
trix">https://docs.clamav.net/faq/faq-eol.html#version-support-matrix</a><b=
r>
&gt; suggests that 1.0.9 went end-of-life Nov-28 2025<br>
&gt; Version 1.3 is also EOL.<br>
&gt; <br>
&gt; Can you verify the problem with version 1.4.3 or 1.5.1 ?<br>
&gt; <br>
_______________________________________________<br>
<br>
Manage your clamav-users mailing list subscription / unsubscribe:<br>
<a href=3D"https://lists.clamav.net/mailman/listinfo/clamav-users">https://=
lists.clamav.net/mailman/listinfo/clamav-users</a><br>
<br>
<br>
Help us build a comprehensive ClamAV guide:<br>
<a href=3D"https://github.com/Cisco-Talos/clamav-documentation">https://git=
hub.com/Cisco-Talos/clamav-documentation</a><br>
<br>
<a href=3D"https://docs.clamav.net/#mailing-lists-and-chat">https://docs.cl=
amav.net/#mailing-lists-and-chat</a><br>
</div>
</span></font></div>
</body>
</html>

--_000_SA1PR11MB5777B579EA02D98205EA4B00DE57ASA1PR11MB5777namp_--

--===============2465187646269291226==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat

--===============2465187646269291226==--