Bug 11123 - 550 Message contained unsafe content (Heuristics.Safebrowsing.Suspected-phishing_safebrowsing.clamav.net)
550 Message contained unsafe content (Heuristics.Safebrowsing.Suspected-phish...
Status: NEW
Product: ClamAV
Classification: ClamAV
Component: libclamav
ALL
x86_64 GNU/Linux
: P3 enhancement
: feature_request
Assigned To: ClamAV team
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-09-29 10:45 EDT by jorge
Modified: 2018-04-27 15:43 EDT (History)
3 users (show)

See Also:
QA Contact:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description jorge 2014-09-29 10:45:16 EDT
Why is this happening to my e-mail: mail@jorgesarmento.com

I never used this mail to spam, or virus.

This is my woek mail, i do not understand what is happening.
Please this mail should no be blacklisted it is my most important mail.

Please help me.
Comment 1 jorge 2014-09-29 10:46:04 EDT
550 Message contained unsafe content (Heuristics.Safebrowsing.Suspected-phishing_safebrowsing.clamav.net)
Comment 2 Steven Morgan 2014-09-29 18:34:16 EDT
Alain, see also bug 11122.
Comment 3 tlhackque 2014-10-06 06:45:14 EDT
Bug 11122 is restricted; referencing it isn't helpful :-)

Allow me to expand on this issue.

I have dozens of e-mails that are quarantined due to Suspect-phishing_safebrowsing.  These mostly come from a mailing list, which sends digest mode e-mails.  Because of the list membership, I doubt that any of the quarantined e-mails are phishing.

Diagnosing which URL(s) are triggering the report is next to impossible.

The problem is that a digest can contain dozens of emails - each of which often quotes/encapsulates a long reply thread.  Thus, there are hundreds of URLs.  For example (chosen at random):

   grep -c http: /var/spool/mqueue/dfs8O40ioF014234
   151

The log files are not helpful:
sendmail[14234]: s8O40ioF014234: Milter insert (1): header: X-Virus-Status: Infected (Heuristics.Safebrowsing.Suspected-phishing_safebrowsing.clamav.net)
sendmail[14234]: s8O40ioF014234: milter=clamav-milter, quarantine=quarantined by clamav-milter

Request:

Please log the URL(s) that trigger this rule.  That would allow the administrator to easily use the google diagnostic tool (http://www.google.com/safebrowsing/diagnostic?site=<url>) to determine the cause and get the site/sender to correct the issue (or whitelist the site).

Thanks.
Comment 4 Alain Zidouemba 2017-12-13 14:23:42 EST
Re-assigning
Comment 5 David Raynor 2017-12-19 15:50:33 EST
Phishing alerts are "Heuristics.Safebrowsing.Suspected-phishing_safebrowsing.clamav.net" and are a kind of Potentially Unwanted Application alert from phishcheck.c.

This may be driven by certain data in safebrowsing.cvd, but any actual FP complaints about Safebrowsing content needs to go to Google's Safebrowsing team who curate that data.

The follow-up request in comment #3 "please write usable information to the logs so the user can identify the affected domain which flagged the alert" is a valid request, but is a code change not a CVD issue. Moving it over.