Re: [clamav-users] Phishing.Heuristics.Email.SpoofedDomain

2011-08-02 Thread Török Edwin
On 2011-08-02 02:56, Al Varnell wrote: > On Jul 26, 2011, at 2:06 PM, Török Edwin wrote: > >> On 07/26/2011 11:59 PM, Al Varnell wrote: >>> Is there something going on with subject infections? I see that it's listed >>> on the clamav home page as a "Current Threat". We got several users asking

Re: [clamav-users] Phishing.Heuristics.Email.SpoofedDomain

2011-08-01 Thread Al Varnell
On Jul 26, 2011, at 2:06 PM, Török Edwin wrote: > On 07/26/2011 11:59 PM, Al Varnell wrote: >> Is there something going on with subject infections? I see that it's listed >> on the clamav home page as a "Current Threat". We got several users asking >> about this in the ClamXav Forum (including

Re: [clamav-users] Phishing.Heuristics.Email.SpoofedDomain

2011-07-26 Thread Török Edwin
On 07/26/2011 11:59 PM, Al Varnell wrote: > Is there something going on with subject infections? I see that it's listed > on the clamav home page as a "Current Threat". We got several users asking > about this in the ClamXav Forum (including a Linux user?) and I can't seem > to find it in the sig

[clamav-users] Phishing.Heuristics.Email.SpoofedDomain

2011-07-26 Thread Al Varnell
Is there something going on with subject infections? I see that it's listed on the clamav home page as a "Current Threat". We got several users asking about this in the ClamXav Forum (including a Linux user?) and I can't seem to find it in the signature database any more. -Al- -- Al Varnell

Re: [Clamav-users] Phishing.Heuristics.Email.SpoofedDomain Query

2009-04-29 Thread Greg McCarthy
Thanks for the info. I've run the scan on the body file and headers file and get: LibClamAV debug: Initializing phishcheck module LibClamAV debug: Phishcheck: Compiling regex: ^ *(http|https|ftp:(//)?)?[0-9]{1,3}(\.[0-9]{1,3}){3}[/?:]? *$ LibClamAV debug: Phishcheck module initialized LibClamAV de

Re: [Clamav-users] Phishing.Heuristics.Email.SpoofedDomain Query

2009-04-29 Thread Török Edwin
On 2009-04-29 11:43, Greg McCarthy wrote: > I've upgraded to 0.95.1 and have a few mails that are getting > quarantined as Phishing.Heuristics.Email.SpoofedDomain > > How do I go about checking for spoofed domains in the email headers? > Its quite possible that the domain has been spoofed but I wou

[Clamav-users] Phishing.Heuristics.Email.SpoofedDomain Query

2009-04-29 Thread Greg McCarthy
I've upgraded to 0.95.1 and have a few mails that are getting quarantined as Phishing.Heuristics.Email.SpoofedDomain How do I go about checking for spoofed domains in the email headers? Its quite possible that the domain has been spoofed but I would like to just double check? Cheers Greg

Re: [Clamav-users] Phishing.Heuristics.Email.SpoofedDomain - possible false positive please advise

2008-07-24 Thread Török Edwin
On 2008-07-24 13:41, Garry wrote: > Hi, > > Yestarday I made a Paypal payment and didn't get the email saying the > payment was made through my VPS, when I check the exim_mainlog I saw: > > 2008-07-23 12:24:42 H=mx0.phx.paypal.com (phx01imail02.phx.paypal.com) > [66.211.168.230] Warning: Sender

Re: [Clamav-users] Phishing.Heuristics.Email.SpoofedDomain - possible false positive please advise

2008-07-24 Thread Garry
On 2008-07-24 13:23, Török Edwin wrote: > On 2008-07-24 13:41, Garry wrote: > > Hi, > > > > Yestarday I made a Paypal payment and didn't get the email saying the > > payment was made through my VPS, when I check the exim_mainlog I saw: > > > > 2008-07-23 12:24:42 H=mx0.phx.paypal.com (phx01ima

Re: [Clamav-users] Phishing.Heuristics.Email.SpoofedDomain - possible false positive please advise

2008-07-24 Thread Török Edwin
On 2008-07-24 17:47, Garry wrote: > On 2008-07-24 13:23, Török Edwin wrote: > >> On 2008-07-24 13:41, Garry wrote: >> >>> Hi, >>> >>> Yestarday I made a Paypal payment and didn't get the email saying the >>> payment was made through my VPS, when I check the exim_mainlog I saw: >>> >>> 2

Re: [Clamav-users] Phishing.Heuristics.Email.SpoofedDomain -

2008-07-24 Thread Garry
Hi, The problem is I never got this email, so how should I report it ? Regards, Garry On 2008-07-24 13:23, Török Edwin wrote: > On 2008-07-24 13:41, Garry wrote: > > Hi, > > > > Yestarday I made a Paypal payment and didn't get the email saying the > > payment was made through my VPS, when

[Clamav-users] Phishing.Heuristics.Email.SpoofedDomain - possible false positive please advise

2008-07-24 Thread Garry
Hi, Yestarday I made a Paypal payment and didn't get the email saying the payment was made through my VPS, when I check the exim_mainlog I saw: 2008-07-23 12:24:42 H=mx0.phx.paypal.com (phx01imail02.phx.paypal.com) [66.211.168.230] Warning: Sender rate 0.0 / 1h 2008-07-23 12:24:42 1KLh8s-0006

Re: [Clamav-users] Phishing.Heuristics.Email.SpoofedDomain

2007-07-13 Thread Robert Schetterer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Török Edvin schrieb: > On 7/13/07, Robert Schetterer <[EMAIL PROTECTED]> wrote: >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA1 >> >> Hi @ll >> >> can someone explain this virus type >> >> Phishing.Heuristics.Email.SpoofedDomain > > PhishingScanU

Re: [Clamav-users] Phishing.Heuristics.Email.SpoofedDomain

2007-07-13 Thread Robert Schetterer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Török Edvin schrieb: > On 7/13/07, Robert Schetterer <[EMAIL PROTECTED]> wrote: >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA1 >> >> Hi @ll >> >> can someone explain this virus type >> >> Phishing.Heuristics.Email.SpoofedDomain > > PhishingScanU

Re: [Clamav-users] Phishing.Heuristics.Email.SpoofedDomain

2007-07-13 Thread Török Edvin
On 7/13/07, Robert Schetterer <[EMAIL PROTECTED]> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Hi @ll > > can someone explain this virus type > > Phishing.Heuristics.Email.SpoofedDomain PhishingScanURLs BOOL Scan URLs found in mails for phishing attempts using he

[Clamav-users] Phishing.Heuristics.Email.SpoofedDomain

2007-07-13 Thread Robert Schetterer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi @ll can someone explain this virus type Phishing.Heuristics.Email.SpoofedDomain this mail looks good , on a first look, seems to be amazon promotion, also spf record are fine - -- Mit freundlichen Gruessen Best Regards Robert Schetterer http