Re: [Clamav-users] Phishing.Heuristics.Email.SpoofedDomain Query

2009-04-29 Thread Greg McCarthy
Thanks for the info. I've run the scan on the body file and headers file and get: LibClamAV debug: Initializing phishcheck module LibClamAV debug: Phishcheck: Compiling regex: ^ *(http|https|ftp:(//)?)?[0-9]{1,3}(\.[0-9]{1,3}){3}[/?:]? *$ LibClamAV debug: Phishcheck module initialized LibClamAV de

Re: [Clamav-users] Phishing.Heuristics.Email.SpoofedDomain Query

2009-04-29 Thread Török Edwin
On 2009-04-29 11:43, Greg McCarthy wrote: > I've upgraded to 0.95.1 and have a few mails that are getting > quarantined as Phishing.Heuristics.Email.SpoofedDomain > > How do I go about checking for spoofed domains in the email headers? > Its quite possible that the domain has been spoofed but I wou

[Clamav-users] Phishing.Heuristics.Email.SpoofedDomain Query

2009-04-29 Thread Greg McCarthy
I've upgraded to 0.95.1 and have a few mails that are getting quarantined as Phishing.Heuristics.Email.SpoofedDomain How do I go about checking for spoofed domains in the email headers? Its quite possible that the domain has been spoofed but I would like to just double check? Cheers Greg