ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
New HDB Signature From The Trickbot Malware Gang

Joined: 09 Jul 2006
Posts: 4935
Location: USA
Reply with quote
Below is a HDB signature for a remote access trojan (backdoor) that is being used in corporate contact forms to distribute ransomeware or other malware, primarily to corporations. The malware could be used on any computer, I guess. This current campaign distributes the malware in a .LNK file.

Copy the signature and post it to a new Notepad or similar text writer file, and save it in the ClamWin database folder as a file named Sigfile.hdb with a file type of “All Files”. Do not save it as text file. The file name should end in nothing but .hdb. The date and time are the last two items in the signature.

For multiple signatures, put each one on a separate line in the Notepad file. You can add multiple signatures to the top of an existing HDB signature file (just add one blank line and paste the signatures there—any lines needed will be added). Adding signatures to the bottom of an existing signature file will give you a scanning error. Delete any blank lines between signatures in the signature file after pasting.

After you save the signature file in the database folder, scan something with ClamWin to make sure it works. If you get a scan error, delete the signature file from the database folder or delete only the signatures that you just posted to an existing HDB file and resave it. Leave no blank lines in the signature file.

Delete signatures after they are 6 weeks old. The viruses will be updated by then.


View user's profileSend private message
New HDB Signature From The Trickbot Malware Gang
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

 Reply to topic