[sanesecurity] Re: False positive: Sanesecurity.Jurlbl.Auto.76c31d5233879882ed5115885a7a00cf

  • From: "Steve Basford" <steveb_clamav@xxxxxxxxxxxxxxxx>
  • To: sanesecurity@xxxxxxxxxxxxx
  • Date: Mon, 4 Oct 2010 11:12:08 +0100

> This signature contains very populer bulk mail sender domain euromsg.net.
> I think this should be whitelisted.
>
>  FileName jurlbla.ndb
>  MalwareName Sanesecurity.Jurlbl.Auto.76c31d5233879882ed5115885a7a00cf
>  TargetType Mail File (4)
>  OffSet *
>  Content (.|/|@| |<|_)euromsg.net('|"| |/|=|_|>| | |?|<)
>

Hi,

Thanks for the report.

I've whitelisted on my sigs... but if you are using InetMsg sigs, it's on
the list too and I'm sure Bill will take a look:

INetMsg.SpamDomain-2m.euromsg_net

Cheers,

Steve
Sanesecurity


Other related posts: