Viruses

I have one of our executives who is receiving an email that they swear does not have a virus yet I keep getting the virus message from clamav.

Virus Info: Phishing.Heuristics.Email.SpoofedDomain

I told them maybe something wrong with the domain, so they then tried to send the word document attachment from their aol account and I got the same virus message.

So Im trying to find out what virus this is, as well as see if I can retrieve it or something to find out the exact problem.

Thanks
 
clamav has some heuristics to detect phishing messages. I don't have access to your mail, but maybe it's just a false positive.

I guess we should consider adding a flag to disable those test on the web interface.

- Dietmar
 
I have one of our executives who is receiving an email that they swear does not have a virus yet I keep getting the virus message from clamav.

Virus Info: Phishing.Heuristics.Email.SpoofedDomain

I told them maybe something wrong with the domain, so they then tried to send the word document attachment from their aol account and I got the same virus message.

So Im trying to find out what virus this is, as well as see if I can retrieve it or something to find out the exact problem.

Thanks

do you got the email in the proxmox virus quarantine?
 
We had the user resend it and received it. I dont think its set to goto quarantine, I get the message but I suppose I could go find that feature. The user did not get an email notice with that message (like the spam ones)

I just figured it got deleted automatically, good idea, maybe I will let them quarantine and manually check them before I just let mail pass through.