Re: [clamav-users] FP Heuristics.Phishing.Email.SpoofedDomain with amazon

2018-08-27 Thread Reindl Harald
Am 23.08.2018 um 20:08 schrieb Marcus Schopen: > Hi, > > Am Dienstag, den 14.11.2017, 11:20 +0100 schrieb Hajo Locke: >> Hello, >> >> based on my working whitelist regex i would say the 2nd part should >> not >> look only for amazon\.com >> >> >> If i understood it the correct way it should

Re: [clamav-users] FP Heuristics.Phishing.Email.SpoofedDomain with amazon

2018-08-23 Thread Marcus Schopen
Hi, Am Dienstag, den 14.11.2017, 11:20 +0100 schrieb Hajo Locke: > Hello, > > based on my working whitelist regex i would say the 2nd part should > not > look only for amazon\.com > > > If i understood it the correct way it should be something like: > >

Re: [clamav-users] FP Heuristics.Phishing.Email.SpoofedDomain with amazon

2017-11-14 Thread Hajo Locke
Hello, based on my working whitelist regex i would say the 2nd part should not look only for amazon\.com If i understood it the correct way it should be something like: X:.+\.amazon\.(at|ca|co\.uk|co\.jp|com|de|fr)([/?].*)?:.+\.amazon\.(com|de)([/?].*)? Using this regex shows a clean mail.

Re: [clamav-users] FP Heuristics.Phishing.Email.SpoofedDomain with amazon

2017-11-14 Thread Al Varnell
On Tue, Nov 14, 2017 at 01:48 AM, Hajo Locke wrote: > Hello, > > > Am 14.11.2017 um 10:44 schrieb Al Varnell: >> I'm not very good at regex, but I'm surprised that this current X record >> doesn't already take care of this: >> >>

Re: [clamav-users] FP Heuristics.Phishing.Email.SpoofedDomain with amazon

2017-11-14 Thread Hajo Locke
Hello, Am 14.11.2017 um 10:44 schrieb Al Varnell: I'm not very good at regex, but I'm surprised that this current X record doesn't already take care of this: X:.+\.amazon\.(at|ca|co\.uk|co\.jp|com|de|fr)([/?].*)?:.+\.amazon\.com([/?].*)? me too. in which file is this regex located? -Al-

Re: [clamav-users] FP Heuristics.Phishing.Email.SpoofedDomain with amazon

2017-11-14 Thread Al Varnell
I'm not very good at regex, but I'm surprised that this current X record doesn't already take care of this: X:.+\.amazon\.(at|ca|co\.uk|co\.jp|com|de|fr)([/?].*)?:.+\.amazon\.com([/?].*)? -Al- On Tue, Nov 14, 2017 at 01:19 AM, Hajo Locke wrote: > Hello List, > > i think i found an fp in

[clamav-users] FP Heuristics.Phishing.Email.SpoofedDomain with amazon

2017-11-14 Thread Hajo Locke
Hello List, i think i found an fp in incoming mail.  I cant submit mail as FP on website, because it contains private data. I can provide debug output which leads to match: LibClamAV debug: Phishcheck:URL after cleanup: https://sellercentral-europe.amazon.com->http://www.amazon.de LibClamAV