[clamav-users] Mail from Paypal wrongly identified as phishing by ClamAv

Joel Esler (jesler) jesler at cisco.com
Fri May 19 20:12:54 UTC 2017


I assume G.W. means “using a URL that looks like something this”:

src="https://102.112.2O7.net/b/ss/paypalglobal/1/G.4--NS/123456?pageName=system_email_PP1814”


--
Joel Esler | Talos: Manager | jesler at cisco.com<mailto:jesler at cisco.com>






On May 18, 2017, at 1:15 PM, Reindl Harald <h.reindl at thelounge.net<mailto:h.reindl at thelounge.net>> wrote:



Am 18.05.2017 um 18:51 schrieb G.W. Haywood:
Admittedly this was quite a while ago; we've been rejecting all mail
from PayPal since 2013.  All the same, you aren't helping anybody by
doing things like that.

like what?
like reject mails from paypal to your users?

hopefully they know how you maintain your mailservices

yes, and hence it's a problem that you can't disable the nonsense without disable other things and need to run multiple of clamd which hits another problem: the morbid memory usage of clamd
_______________________________________________
clamav-users mailing list
clamav-users at lists.clamav.net<mailto:clamav-users at lists.clamav.net>
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/vrtadmin/clamav-faq

http://www.clamav.net/contact.html#ml



More information about the clamav-users mailing list