[clamav-users] How to find string for a signature?

kristen R kristen at atmyhome.org
Sat Oct 21 03:30:18 UTC 2017


List,

I just received an email from ncas.us-cert.gov that was caught by clamd
reporting PUA.Win.Trojan.Xored-1 signature. This email is from the US
Department of Homeland Security.

I suppose this is a case of a false positive. How does one find the
string triggering this event that I might know and report this as a
false positive?

Kristen

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 235 bytes
Desc: OpenPGP digital signature
URL: <https://lists.clamav.net/pipermail/clamav-users/attachments/20171020/b45bc505/attachment.sig>


More information about the clamav-users mailing list