Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Of course it might be useful to detect UPX packed files (even though it doesn't necessarily mean they're malicious), but the problem is that this rule might hide a better detection underneath. I ran a test with 592 UPX packed malware samples and the rule hit on 338 of them, which hid plenty of ClamAV's own signatures.
- Loading branch information
85581e9
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
#84