Re: [clamav-users] False positives phishing sites

2014-09-24 Thread Thorvald Hallvardsson
Hi, Don't know really. I also have some email newsletter samples of shops selling mobile phones - marked as suspicious. Also message from mobile network announcing iPhone 6 - also marked as suspicious. Not sure about the exact reason as I haven't review them yet. I will let you all know about m

Re: [clamav-users] False positives phishing sites

2014-09-24 Thread Al Varnell
On Wed, Sep 24, 2014 at 12:41 AM, Thorvald Hallvardsson wrote: > > at the moment I'm reviewing > customers emails because the impact we are facing with the false positive > is so massive that we would need to have a team of 4-5 people full time > working only on false positives. It's not the matt

Re: [clamav-users] False positives phishing sites

2014-09-24 Thread Thorvald Hallvardsson
Hi, Thank you Shaun for your reply. Al Varnell. Yes I will pass that over but at the moment I'm reviewing customers emails because the impact we are facing with the false positive is so massive that we would need to have a team of 4-5 people full time working only on false positives. It's not the

Re: [clamav-users] False positives phishing sites

2014-09-23 Thread Al Varnell
> On Sep 23, 2014, at 5:29 AM, Thorvald Hallvardsson > wrote: > > If I would like to build my own database (I have > read PDF but I don't understand really how it works) what would be the > syntax for it ? > > H:youraccount.mbna.co.uk:mbna.co.uk ?? You can obviously do whatever you want for a

Re: [clamav-users] False positives phishing sites

2014-09-23 Thread Shaun Hurley
Yes, that would trigger it. Shaun On Tue, Sep 23, 2014 at 11:16 AM, Thorvald Hallvardsson < thorvald.hallvards...@gmail.com> wrote: > Hi Shaun, > > Thank you for your reply. Just for a bit of clarification would actually > clamav catch this bit as a phishing: > > http://www.bankofamerica.co.uk/a

Re: [clamav-users] False positives phishing sites

2014-09-23 Thread Thorvald Hallvardsson
Hi Shaun, Thank you for your reply. Just for a bit of clarification would actually clamav catch this bit as a phishing: http://www.bankofamerica.co.uk/amazon";>http://youraccount.m=bna.co.uk/imgproxy/img/647707065/az_main_logo.png"; width=3D"280" height=3D"= 103" border=3D"0" style=3D"display:blo

Re: [clamav-users] False positives phishing sites

2014-09-23 Thread Shaun Hurley
Thorvald, ClamAV's Phishing heuristics checks the link URL versus the URL listed in the link text. Here is a simple example: text If the text is formatted like a URL and it is different from the href link, then it will be flagged as a phishing attempt. I don't know offhand how different the

Re: [clamav-users] False positives phishing sites

2014-09-23 Thread Thorvald Hallvardsson
Hi Steve, Thank you for your answer. If I would like to build my own database (I have read PDF but I don't understand really how it works) what would be the syntax for it ? H:youraccount.mbna.co.uk:mbna.co.uk ?? Regards. On 23 September 2014 13:08, Steve Basford wrote: > > On Tue, September 2

Re: [clamav-users] False positives phishing sites

2014-09-23 Thread Steve Basford
On Tue, September 23, 2014 12:44 pm, Thorvald Hallvardsson wrote: > Anyone would like to point me into the right direction and help me out > with the problems I'm having ? Report as an FPs here: http://cgi.clamav.net/sendvirus.cgi ClamAV team will need to add hosts to the daily.wdb database to

[clamav-users] False positives phishing sites

2014-09-23 Thread Thorvald Hallvardsson
Hi guys, I need a bit of help in understanding why ClamAV finds phishing URLs in the very very legitimate emails. I have got some customers complaining that some emails from normal retail shops (newsletters) are marked as phising. Also multiple customers having issues with receiving emails from A