[clamav-users] VIRUS ({HEX}EICAR.TEST.10.UNOFFICIAL) in mail FROM [198.148.79.53]

Ralph Seichter m16+clamav at monksofcool.net
Tue Oct 3 14:52:02 UTC 2017


On 03.10.17 16:40, Anssi Johansson wrote:

> if your virus scanner detected EICAR from my message, I dare to say
> that it is broken.

Check the headers in my message again, I was quoting a report generated
for one of Nymblewyke's messages, not for yours.

I know customer setups which will automatically block addresses, or even
domains, after a single virus alert was generated. That may include joe-
job triggered events. Best not to risk this by posting virus samples to
mailing lists, not knowing who has subscribed and what the repercussions
might be. Depending on regional laws, sending virus materials might even
be unlawful. Cans of worms, and such. ;-)

-Ralph



More information about the clamav-users mailing list