[clamav-users] What was detected?

joe a joea-lists at j4computers.com
Mon Feb 27 22:12:34 UTC 2023


On 2/27/2023 4:49 PM, Andrew C Aitchison via clamav-users wrote:
> On Mon, 27 Feb 2023, joe a wrote:
> 66
>> On 2/27/2023 4:24 PM, Paul Netpresto wrote:
>>
>> I attempted that just now.  Ran clamscan --debug -f some-email.eml
>>
>> After it cranks up and apparently beings actually scanning the email, 
>> starts cranking out errors/warnings like:
>>
>> Return-path: <some at body.com>: No such file or directory
>> WARNING: Return-path: <some at body.com>: Can't access file
>> Seems to be t
>> This particular email was previously scanned and found to be possibly 
>> infected with "Heuristics.Phishing.Email.SpoofedDomain" and am 
>> attempting to determine the actual objectionable domain.
>>
>> Clearly I am doing something wrong.
> 
> Drop the '-f' - it says read the filenames from some-file.eml
> Try clamscan  some-email.eml 

Thanks folks, that did it for me. I guess it helps to slow down and read 
what -f actually means

Found the link and added it to my ignore file. And it actually does 
ignore the"iffy-spoofy" domain.

Maybe I will also save notes this time.




More information about the clamav-users mailing list