Re: false positive from a third party defination

Steve Basford via clamav-users <[email protected]>
Newsgroups gmane.comp.security.virus.clamav.user
Message-ID <193beca8278.2855.3eaa884a23ece66aada06ae82ee56aba@sanesecurity.com>
On 12 December 2024 23:46:26 Lyle Giese via clamav-users 
<[email protected]> wrote:

> Not sure where I need to report this.  I am having legit email being
> bounced using ClamAV by this:
>
> Heuristics.Phishing.Email.SpoofedDomain(cd2d755959754996812d9dc9405de4be:121605)

Hi.

It's not a 3rd party definition.

It is a configuration option within ClamAV.

You need to add the following to the Clam conf file:

PhishingScanURLs no

And  submit your email as an fp to ClamAV.



>
>
> This email is legit from Hilton Honors.
>
> Thanks,
>
> Lyle Giese
>
>
> _______________________________________________
>
> Manage your clamav-users mailing list subscription / unsubscribe:
> https://lists.clamav.net/mailman/listinfo/clamav-users
>
>
> Help us build a comprehensive ClamAV guide:
> https://github.com/Cisco-Talos/clamav-documentation
>
> https://docs.clamav.net/#mailing-lists-and-chat


Cheers,

Steve
Sanesecurity

_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.