Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Phishing Heuristics Item Found by ClamXav

ClamXav reports the following:

/Users/Ryan/Library/Mail/IMAP-ryanthemusician@imap.aol.com/Deleted Messages.imapmbox/Messages/4527.partial.emlx: Phishing.Heuristics.Email.SpoofedDomain FOUND
****
The above file looks like it may be part of an email mailbox, please think carefully about what to do with this file. If it has been quarantined, you may end up losing some email. I suggest you leave this file where it is (or move it back if it's been quarantined) and delete suspicious messages from within your email client.
****
ERROR: Can't unlink '/Users/Ryan/Library/Mail/IMAP-ryanthemusician@imap.aol.com/Deleted Messages.imapmbox/Messages/4527.partial.emlx': No such file or directory


Could someone please comment on this? I didn't know that ClamXav could detect phishing in emails? How does it know?

I have the quarantined file which is an email from Sears. Could this be an error?

iMac 2.4 GHz Intel Core 2 Duo, 4 GB RAM, Mac OS X (10.5.6), Bootcamp 50 GB Windows 7

Posted on Apr 22, 2009 8:44 AM

Reply
5 replies

Apr 22, 2009 9:29 AM in response to nerowolfe

Clam is very much out-of-date (over a year old)

Is it?
http://www.clamxav.com/index.php?page=dl
Latest version is ClamXav 1.1.1 with ClamAV 0.95 backend - 4th April 2009

http://www.clamav.net/
Latest ClamAV® stable release is: 0.95.1
Total number of signatures: 545287
ClamAV Virus Databases:
main.cvd ver. 50 released on 15 Feb 2009 16:47 :0500
daily.cvd ver. 9273 released on 22 Apr 2009 10:16 :0400

Apr 22, 2009 9:50 AM in response to pianoman1976

ClamAV's phishing heuristics are based primarily on a search for HTML links where the visible and real targets of the link are different. It's a nice idea but with some URLs, for instance those based on TinyURL, it is likely to produce false positives. Most likely you can just ignore the report, though be cautious about clicking on any web link in the reported email, particularly if it's asking for any sort of personal information (never provide any sort of personal information via a web link in any email).

Hope this helps.

Phishing Heuristics Item Found by ClamXav

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.