Re: [clamav-users] False Positives - Heuristics.Phishing.Email.SpoofedDomain

2019-01-08 Thread Ken Campney
Thanks Joel, Testing confirmed the issue appears to be with the WDB/PDB databases, I'm assuming 101.0 was when they were introduced For now I've changed my scan settings from blackhole (in use since 99.4) to Quarantine. Hopefully as I submit samples, white listings can get added. Thanks

Re: [clamav-users] False Positives - Heuristics.Phishing.Email.SpoofedDomain

2019-01-08 Thread Joel Esler (jesler)
Check out http://www.clamav.net/documents/miscellaneous-faq > On Jan 8, 2019, at 2:43 PM, Ken Campney wrote: > > Emails from credit card companies I deal with have since 12/10/18 been > getting flagged by

[clamav-users] False Positives - Heuristics.Phishing.Email.SpoofedDomain

2019-01-08 Thread Ken Campney
Emails from credit card companies I deal with have since 12/10/18 been getting flagged by Heuristics.Phishing.Email.SpoofedDomain. These include Best Buy/Citi Bank (accountsonline.com) and American Express. Sending Domain and IP's have been verified Upgraded to ClamAV version: 101.0 on