Re: [clamav-users] Heuristics.Phishing.Email.SpoofedDomain false-positive

2014-02-02 Thread Al Varnell
On Sun, Feb 02, 2014 at 10:41 AM, Benny Pedersen wrote: > > On 2014-02-02 18:43, Alex wrote: >>> The heuristics engine is only used for selected financial institution >>> domains (currently 263) >>> listed in daily.pdb as H: >> It looks like I only have daily.cld. Can you explain what you mean h

Re: [clamav-users] Heuristics.Phishing.Email.SpoofedDomain false-positive

2014-02-02 Thread Benny Pedersen
On 2014-02-02 18:43, Alex wrote: The heuristics engine is only used for selected financial institution domains (currently 263) listed in daily.pdb as H: It looks like I only have daily.cld. Can you explain what you mean here? cd /tmp && sigtool --unpack-current=daily there you find what you

Re: [clamav-users] request for feature

2014-02-02 Thread Joel Esler (jesler)
On Feb 2, 2014, at 9:39 AM, Gene Heskett mailto:ghesk...@wdtv.com>> wrote: On Sunday 02 February 2014 09:37:59 Joel Esler (jesler) did opine: Because these are two separate systems. In two different parts of the network. We haven't consolidated everything that we took over when the original cla

Re: [clamav-users] Heuristics.Phishing.Email.SpoofedDomain false-positive

2014-02-02 Thread Alex
Hi, >>> running clamscan --debug against the file. >>> http://www.tdcanadatrust.com/tdvisa/agreements appears >>> several times in the body of the message but links to >>> http://ems1.aeroplan.com/a/l.x?t=icholbpbeophbeocnlmimpbc&; >>> M=1&L=2&v=4. >> >> Ah, thanks. I should have known that. >>

Re: [clamav-users] request for feature

2014-02-02 Thread Gene Heskett
On Sunday 02 February 2014 09:48:26 Joel Esler (jesler) did opine: > Because these are two separate systems. In two different parts of the > network. We haven't consolidated everything that we took over when the > original clam team left yet. > > > -- > Joel Esler I should add, that when I st

Re: [clamav-users] request for feature

2014-02-02 Thread Gene Heskett
On Sunday 02 February 2014 09:37:59 Joel Esler (jesler) did opine: > Because these are two separate systems. In two different parts of the > network. We haven't consolidated everything that we took over when the > original clam team left yet. > > > -- > Joel Esler > Sent from my iPhone I see

Re: [clamav-users] request for feature

2014-02-02 Thread Joel Esler (jesler)
Because these are two separate systems. In two different parts of the network. We haven't consolidated everything that we took over when the original clam team left yet. -- Joel Esler Sent from my iPhone > On Jan 31, 2014, at 14:59, "Gene Heskett" wrote: > > On Friday 31 January 2014 14:5

Re: [clamav-users] request for feature

2014-02-02 Thread Gene Heskett
On Sunday 02 February 2014 09:12:36 G.W. Haywood did opine: > Hi there, > > On Sun, 2 Feb 2014, Gene Heskett wrote: > > I have trolled thru the man pages at length, and can find no option to > > make it just a little more verbose by outputting something that would > > serve to identify the origin

Re: [clamav-users] request for feature

2014-02-02 Thread G.W. Haywood
Hi there, On Sun, 2 Feb 2014, Gene Heskett wrote: I have trolled thru the man pages at length, and can find no option to make it just a little more verbose by outputting something that would serve to identify the originator of a compromised email. What we do get, is hard to impossible to act