Sourcefire/Snort has developed a system that focuses on network traffic instead of the traditional anti-virus interest in the malicious files themselves. The system has been happily churning through malicious executables from ClamAV for several months now. A huge portion of the traffic in these PCAPs went to legitimate domains, including thousands of obscure ad servers across the world. Separating these domains from truly malicious sites has been one of the more interesting ongoing challenges in running this system.”]
Source: https://blog.talosintelligence.com/2011/02/blacklistrules-clamav-and-data-mining.html