[clamav-users] Finding the spoofed domain

2015-12-15 Thread Alex
Hi, I have an email that was marked as having a spoofed domain, but I believe it's a false-positive. It's one of those smartbrief.com newsletters. How do I find out which domain specifically it thinks was spoofed? I've posted the email here: http://pastebin.com/n4WRjmzE # clamscan -v spoofed-do

Re: [clamav-users] Finding the spoofed domain

2015-12-15 Thread Steve Basford
On Tue, December 15, 2015 1:43 pm, Alex wrote: > Hi, > > > I have an email that was marked as having a spoofed domain, but I > believe it's a false-positive. It's one of those smartbrief.com > newsletters. > > How do I find out which domain specifically it thinks was spoofed? --debug will help...

Re: [clamav-users] Finding the spoofed domain

2015-12-15 Thread Alex
Hi, > I've posted the email here: > http://pastebin.com/n4WRjmzE > Got a match: f.email.americanexpress.com/ with /moc.sserpxenacirema > Before inserting .: .f.email.americanexpress.com > Lookup result: in regex list > Phishcheck:host:.r.smartbrief.com > Phishing: looking up in whitelist: > .r.s

Re: [clamav-users] Finding the spoofed domain

2015-12-15 Thread Kris Deugau
Alex wrote: > Steve Basford wrote: >> I've posted the email here: >> http://pastebin.com/n4WRjmzE > >> Got a match: f.email.americanexpress.com/ with /moc.sserpxenacirema >> Before inserting .: .f.email.americanexpress.com >> Lookup result: in regex list >> Phishcheck:host:.r.smartbrief.com >> Ph

Re: [clamav-users] Finding the spoofed domain

2015-12-15 Thread Alex
Hi, >> Steve Basford wrote: >>> I've posted the email here: >>> http://pastebin.com/n4WRjmzE >> >>> Got a match: f.email.americanexpress.com/ with /moc.sserpxenacirema >>> Before inserting .: .f.email.americanexpress.com >>> Lookup result: in regex list >>> Phishcheck:host:.r.smartbrief.com >>> Ph

Re: [clamav-users] Finding the spoofed domain

2015-12-15 Thread Al Varnell
On Tue, Dec 15, 2015 at 06:21 PM, Alex wrote: > >>> Steve Basford wrote: I've posted the email here: http://pastebin.com/n4WRjmzE >>> Got a match: f.email.americanexpress.com/ with /moc.sserpxenacirema Before inserting .: .f.email.americanexpress.com Lookup result: in reg

Re: [clamav-users] Finding the spoofed domain

2015-12-21 Thread bijan gilani
Please stop sending me emails > On Dec 15, 2015, at 6:21 PM, Alex wrote: > > Hi, > >>> Steve Basford wrote: I've posted the email here: http://pastebin.com/n4WRjmzE >>> Got a match: f.email.americanexpress.com/ with /moc.sserpxenacirema Before inserting .: .f.email.america