INFECTED:: Phishing.Heuristics.Email.SpoofedDomain:: ....

Gareth list-mailscanner at linguaphone.com
Wed Oct 31 09:23:20 GMT 2007


Its caused by a new feature in clamav with an incorrect default setting.
You need to either update MailScanner to include the new scanning option
or switch to clamd.

On Wed, 2007-10-31 at 08:22, Quentin Campbell wrote:
> I am running eight mail gateways with MailScanner-4.62.9-2 using 'clamavmodule' (Mail-ClamAV-0.20 & ClamAV 0.91.2).
> 
> However only seeing "INFECTED:: Phishing.Heuristics.Email.SpoofedDomain::" on two of them and many of these look like false positives. 
> 
> Cannot see why only two systems doing this as all eight gateways are equal preference MX hosts for our domains and share the same type of mail traffic. 
> 
> Any pointers to where else I might look would be appreciated.
> 
> Thanks
> 
> Quentin
> ---
> PHONE: +44 191 222 8209    Information Systems and Services (ISS),
>                            Newcastle University,
>                            Newcastle upon Tyne,
> FAX:   +44 191 222 8765    United Kingdom, NE1 7RU.
> ------------------------------------------------------------------------



More information about the MailScanner mailing list