INFECTED:: Phishing.Heuristics.Email.SpoofedDomain:: ....

Quentin Campbell Q.G.Campbell at newcastle.ac.uk
Wed Oct 31 08:22:06 GMT 2007


I am running eight mail gateways with MailScanner-4.62.9-2 using 'clamavmodule' (Mail-ClamAV-0.20 & ClamAV 0.91.2).

However only seeing "INFECTED:: Phishing.Heuristics.Email.SpoofedDomain::" on two of them and many of these look like false positives. 

Cannot see why only two systems doing this as all eight gateways are equal preference MX hosts for our domains and share the same type of mail traffic. 

Any pointers to where else I might look would be appreciated.

Thanks

Quentin
---
PHONE: +44 191 222 8209    Information Systems and Services (ISS),
                           Newcastle University,
                           Newcastle upon Tyne,
FAX:   +44 191 222 8765    United Kingdom, NE1 7RU.
------------------------------------------------------------------------





More information about the MailScanner mailing list