Re: Why are recent Firefox (for Windows) downloads ALL being found to contain ransomware?
"Valerie Snyder \(valsnyde\) via clamav-users" <[email protected]> Fri, 27 Mar 2026 16:00:48 +0000
| Newsgroups | gmane.comp.security.virus.clamav.user |
|---|---|
| Message-ID | <SA1PR11MB5777B579EA02D98205EA4B00DE57A@SA1PR11MB5777.namprd11.prod.outlook.com> |
--===============2465187646269291226== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_SA1PR11MB5777B579EA02D98205EA4B00DE57ASA1PR11MB5777namp_" --_000_SA1PR11MB5777B579EA02D98205EA4B00DE57ASA1PR11MB5777namp_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Your clamd likely has the scan limits higher than defaults, so you can scan= larger files. In my own testing with the exe file from https://releases.mo= zilla.org/pub/firefox/releases/115.34.0esr/win64/en-US/ on my laptop, I had= to increase several limits including max-recursion, max-scantime, and max-= scansize from the default settings in order to get the detection. VirusTotal uses the latest clamav, which means it will be using 1.5.2. Howe= ver, it uses slightly lower scan limits than default, due to resource const= raints. So, it is not going to alert on this file. I'll forward the FP concern with our malware team so they're aware. Regarding supported versions: * We load-test new signatures on multiple releases including at least the lat= est patch version of the latest release as well as the latest patch version= of supported LTS releases. At this time, that is the 1.5.2 version of 1.5 = release and the 1.4.4 version of the 1.4 LTS release at a minimum. * We only FP-test with a single version. It takes more resources to do FP-tes= ting. We cannot afford to FP-test with multiple releases. It is highly unli= kely for an old version to have more detections than a new version, since n= ew features appear in new versions, and FPs are generally the result of bad= signatures, not bad file analyzer modules. So, we typically FP-test with t= he latest version, though we don't necessarily bump the version in our FP-t= est system right away. I have been wanting to add the ability for freshclam to check if the curren= t release and version are supported. It is going to require adding new DNS = text records and then more frequent updates to the DNS records. Sadly, this= work keeps getting pushed out. But I 100% agree that we really should give= these notifications in freshclam. Respectfully, Val Valerie Snyder (she/they) ClamAV Development Talos Cisco Systems, Inc. ________________________________ From: clamav-users <[email protected]> on behalf of Pau= l Kosinski via clamav-users <[email protected]> Sent: Thursday, March 26, 2026 7:09 PM To: [email protected] <[email protected]>; Andrew C= Aitchison via clamav-users <[email protected]> Cc: Paul Kosinski <[email protected]> Subject: Re: [clamav-users] Why are recent Firefox (for Windows) downloads = ALL being found to contain ransomware? I only have 1.0.9 installed, so I don't currently have a way to test it wit= h either 1.5.x or 1.4.x. So I submitted the "Firefox Setup 115.34.0esr.exe" file to VirusTotal, and = none of their scanners found a virus. I then asked VirusTotal (now owned by Google) what version of ClamAV they r= un, but they haven't replied as of a few minutes ago. I realize that ClamAV 1.0.9 is "EOL", but one can still obtain "official" s= ignature files for another year beyond that. Disturbingly, the Version Support Matrix says that, for 1.0 LTS, signatures= are NOT tested for false positives (FP) after 1.1 was released. In this ca= se that's about 2.5 years BEFORE 1.0.9 EOL. So WHAT EXACTLY DOES LTS MEAN?? For 1.0 LTS, it seems that no 1.0.x can be = FULLY trusted after 1.1 was released. This is not what I would characterize= as LTS. Furthermore, since the DB files can still be downloaded one year after nomi= nal EOL (much less End Of Trust), why doesn't freshclam at least issue a wa= rning among its large number of messages that EOL is past? Finally, I intend to (try to) install 1.4 LTS in the near future. But will = this help? According to the Version Support Matrix, FP testing will not be = done for 1.4 LTS after 1.5 is released. Oops: that was last October (2025)! --------------------- On Thu, 26 Mar 2026 18:17:38 +0000 (GMT) Andrew C Aitchison via clamav-users <[email protected]> wrote: > On Thu, 26 Mar 2026, Paul Kosinski via clamav-users wrote: > > > For example: > > > > Firefox Setup 140.9.0esr.exe --> Win.Trojan.Spora-7724442-0 FOUND > > Firefox Setup 115.34.0esr.exe --> Win.Trojan.Spora-7724442-0 FOUND > > Firefox Setup 115.34.0esr.msi --> Win.Trojan.Spora-7724442-0 FOUND > > > > > > These are from ClamAV 1.0.9 clamd on Linux receiving file to be scanned= over TCP. > > https://docs.clamav.net/faq/faq-eol.html#version-support-matrix > suggests that 1.0.9 went end-of-life Nov-28 2025 > Version 1.3 is also EOL. > > Can you verify the problem with version 1.4.3 or 1.5.1 ? > _______________________________________________ Manage your clamav-users mailing list subscription / unsubscribe: https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/Cisco-Talos/clamav-documentation https://docs.clamav.net/#mailing-lists-and-chat --_000_SA1PR11MB5777B579EA02D98205EA4B00DE57ASA1PR11MB5777namp_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"= > <style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo= ttom:0;} </style> </head> <body dir=3D"ltr"> <div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E= mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te= xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class= =3D"elementToProof"> Your clamd likely has the scan limits higher than defaults, so you can scan= larger files. In my own testing with the exe file from <a href=3D"https://releases.mozilla.org/pub/firefox/releases/115.34.0esr/wi= n64/en-US/"> https://releases.mozilla.org/pub/firefox/releases/115.34.0esr/win64/en-US/<= /a> on my laptop, I had to increase several limits including max-recur= sion, max-scantime, and max-scansize from the default settings in order to = get the detection. </div> <div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E= mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te= xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class= =3D"elementToProof"> <br> </div> <div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E= mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te= xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class= =3D"elementToProof"> VirusTotal uses the latest clamav, which means it will be using 1.5.2. Howe= ver, it uses slightly lower scan limits than default, due to resource const= raints. So, it is not going to alert on this file.</div> <div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E= mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te= xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class= =3D"elementToProof"> <br> </div> <div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E= mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te= xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class= =3D"elementToProof"> I'll forward the FP concern with our malware team so they're aware.</div> <div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E= mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te= xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class= =3D"elementToProof"> <br> </div> <div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E= mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te= xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class= =3D"elementToProof"> Regarding supported versions:</div> <div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E= mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te= xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class= =3D"elementToProof"> <br> </div> <ul style=3D"margin-top: 0px; margin-bottom: 0px;" data-editing-info=3D"{&q= uot;applyListStyleFromLevel":false,"unorderedStyleType":2}"> <li data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_Em= beddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size:= 12pt; color: rgb(0, 0, 0); list-style-type: "- "; --darkreader-i= nline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreade= r-text-000000, #e8e6e3));"> <div role=3D"presentation" class=3D"elementToProof">We load-test new signat= ures on multiple releases including at least the latest patch version of th= e latest release as well as the latest patch version of supported LTS relea= ses. At this time, that is the 1.5.2 version of 1.5 release and the 1.4.4 version of the 1.4 LTS release at a m= inimum.</div> </li></ul> <div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E= mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te= xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));"> <br> </div> <ul style=3D"margin-top: 0px; margin-bottom: 0px;" data-editing-info=3D"{&q= uot;applyListStyleFromLevel":false,"unorderedStyleType":2}"> <li data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_Em= beddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size:= 12pt; color: rgb(0, 0, 0); list-style-type: "- "; --darkreader-i= nline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreade= r-text-000000, #e8e6e3));"> <div role=3D"presentation" class=3D"elementToProof">We only FP-test with a = single version. It takes more resources to do FP-testing. We cannot afford = to FP-test with multiple releases. It is highly unlikely for an old version= to have more detections than a new version, since new features appear in new versions, and FPs are generally = the result of bad signatures, not bad file analyzer modules. So, we typical= ly FP-test with the latest version, though we don't necessarily bump the ve= rsion in our FP-test system right away. </div> </li></ul> <div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E= mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te= xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));"> <br> </div> <div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E= mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te= xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class= =3D"elementToProof"> I have been wanting to add the ability for freshclam to check if the curren= t release and version are supported. It is going to require adding new DNS = text records and then more frequent updates to the DNS records. Sadly, this= work keeps getting pushed out. But I 100% agree that we really should give these notifications in freshcl= am. </div> <div class=3D"elementToProof" id=3D"Signature"> <div data-darkreader-inline-color=3D"" style=3D"font-family: Aptos, Aptos_E= mbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size= : 12pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-te= xt--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" class= =3D"elementToProof"> <br> </div> <div data-darkreader-inline-color=3D"" style=3D"font-family: Calibri, Arial= , Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader= -inline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkrea= der-text-000000, #e8e6e3));" class=3D"elementToProof"> Respectfully,</div> <div data-darkreader-inline-color=3D"" style=3D"font-family: Calibri, Arial= , Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader= -inline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkrea= der-text-000000, #e8e6e3));" class=3D"elementToProof"> Val</div> <div data-darkreader-inline-color=3D"" style=3D"font-family: Calibri, Arial= , Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader= -inline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkrea= der-text-000000, #e8e6e3));" class=3D"elementToProof"> <br> <span style=3D"font-family: Helvetica; font-size: 12px;">Valerie Snyder (sh= e/they)</span><br> <span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Development= </span><br> <span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span><br> <span style=3D"font-family: Helvetica; font-size: 12px;">Cisco Systems, Inc= .</span><br> </div> </div> <div id=3D"appendonsend"></div> <hr style=3D"display:inline-block;width:98%" tabindex=3D"-1"> <div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" st= yle=3D"font-size:11pt" color=3D"#000000"><b>From:</b> clamav-users <clam= [email protected]> on behalf of Paul Kosinski via clamav= -users <[email protected]><br> <b>Sent:</b> Thursday, March 26, 2026 7:09 PM<br> <b>To:</b> [email protected] <[email protected]&= gt;; Andrew C Aitchison via clamav-users <[email protected]&= gt;<br> <b>Cc:</b> Paul Kosinski <[email protected]><br> <b>Subject:</b> Re: [clamav-users] Why are recent Firefox (for Windows) dow= nloads ALL being found to contain ransomware?</font> <div> </div> </div> <div class=3D"BodyFragment"><font size=3D"2"><span style=3D"font-size:11pt;= "> <div class=3D"PlainText">I only have 1.0.9 installed, so I don't currently = have a way to test it with either 1.5.x or 1.4.x. <br> <br> So I submitted the "Firefox Setup 115.34.0esr.exe" file to VirusT= otal, and none of their scanners found a virus.<br> I then asked VirusTotal (now owned by Google) what version of ClamAV they r= un, but they haven't replied as of a few minutes ago.<br> <br> I realize that ClamAV 1.0.9 is "EOL", but one can still obtain &q= uot;official" signature files for another year beyond that.<br> <br> Disturbingly, the Version Support Matrix says that, for 1.0 LTS, signatures= are NOT tested for false positives (FP) after 1.1 was released. In this ca= se that's about 2.5 years BEFORE 1.0.9 EOL.<br> <br> So WHAT EXACTLY DOES LTS MEAN?? For 1.0 LTS, it seems that no 1.0.x can be = FULLY trusted after 1.1 was released. This is not what I would characterize= as LTS.<br> <br> Furthermore, since the DB files can still be downloaded one year after nomi= nal EOL (much less End Of Trust), why doesn't freshclam at least issue a wa= rning among its large number of messages that EOL is past?<br> <br> Finally, I intend to (try to) install 1.4 LTS in the near future. But will = this help? According to the Version Support Matrix, FP testing will not be = done for 1.4 LTS after 1.5 is released. Oops: that was last October (2025)!= <br> <br> ---------------------<br> <br> On Thu, 26 Mar 2026 18:17:38 +0000 (GMT)<br> Andrew C Aitchison via clamav-users <[email protected]> w= rote:<br> <br> > On Thu, 26 Mar 2026, Paul Kosinski via clamav-users wrote:<br> > <br> > > For example:<br> > ><br> > > Firefox Setup 140.9.0esr.exe --> Win.Trojan.Spora-772444= 2-0 FOUND<br> > > Firefox Setup 115.34.0esr.exe --> Win.Trojan.Spora-7724442-0 F= OUND<br> > > Firefox Setup 115.34.0esr.msi --> Win.Trojan.Spora-7724442-0 F= OUND<br> > ><br> > ><br> > > These are from ClamAV 1.0.9 clamd on Linux receiving file to be s= canned over TCP. <br> > <br> > <a href=3D"https://docs.clamav.net/faq/faq-eol.html#version-support-ma= trix">https://docs.clamav.net/faq/faq-eol.html#version-support-matrix</a><b= r> > suggests that 1.0.9 went end-of-life Nov-28 2025<br> > Version 1.3 is also EOL.<br> > <br> > Can you verify the problem with version 1.4.3 or 1.5.1 ?<br> > <br> _______________________________________________<br> <br> Manage your clamav-users mailing list subscription / unsubscribe:<br> <a href=3D"https://lists.clamav.net/mailman/listinfo/clamav-users">https://= lists.clamav.net/mailman/listinfo/clamav-users</a><br> <br> <br> Help us build a comprehensive ClamAV guide:<br> <a href=3D"https://github.com/Cisco-Talos/clamav-documentation">https://git= hub.com/Cisco-Talos/clamav-documentation</a><br> <br> <a href=3D"https://docs.clamav.net/#mailing-lists-and-chat">https://docs.cl= amav.net/#mailing-lists-and-chat</a><br> </div> </span></font></div> </body> </html> --_000_SA1PR11MB5777B579EA02D98205EA4B00DE57ASA1PR11MB5777namp_-- --===============2465187646269291226== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Manage your clamav-users mailing list subscription / unsubscribe: https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/Cisco-Talos/clamav-documentation https://docs.clamav.net/#mailing-lists-and-chat --===============2465187646269291226==--