[clamav-users] SpoofedDomain FOUND
Al Varnell
alvarnell at mac.com
Thu Feb 16 00:59:00 UTC 2017
Ellan,
I'm afraid it's going to be more trouble than it's worth. You will need to turn debugging on when you scan that mailbox which will produce a huge amount of output, but includes details about exactly what was found. You would then need to search that mailbox in Thunderbird for the offending URL and decide whether you need the message or it can be deleted. A SpoofedDomain finding is not necessarily an attempt to misdirect you. It's a technique sometimes used to give a message clarity.
-Al-
On Wed, Feb 15, 2017 at 12:17 PM, ellanios82 wrote:
>
> scanning my Thunderbird directory , am getting :
>
> /home/user/.thunderbird/9i9wirek.default/Mail/pop.gmail.com/bus: Heuristics.Phishing.Email.SpoofedDomain FOUND
> /home/user/.thunderbird/9i9wirek.default/Mail/pop.gmail.com/bus: copied to '/var/log/clams.infected/bus'
>
>
> How please do i locate the offending message to delete, as i do not want to delete the entire directory ?
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3573 bytes
Desc: not available
URL: <https://lists.clamav.net/pipermail/clamav-users/attachments/20170215/5c8cf80a/attachment.bin>
More information about the clamav-users
mailing list