Re: [clamav-users] PUA.Win.Trojan.EmbeddedPDF-1 false-positives

2017-11-17 Thread Eric Tykwinski
-users [mailto:clamav-users-boun...@lists.clamav.net] On > Behalf Of Alex > Sent: Friday, November 17, 2017 12:44 PM > To: ClamAV users ML > Subject: [clamav-users] PUA.Win.Trojan.EmbeddedPDF-1 false-positives > > Hi, > > We're seeing a large number of false

[clamav-users] PUA.Win.Trojan.EmbeddedPDF-1 false-positives

2017-11-17 Thread Alex
Hi, We're seeing a large number of false-positives with the above rule. Is it particularly prone to false-positives? Would someone explain how it works? What's perhaps even more strange is that scanning the email again (or the files within the email) don't produce the same false-positives. Was