I have an email where clamdcan
complains
Sanesecurity.Jurlbl.0c9ed5.UNOFFICIAL FOUND
It is 100% a false positive.
The signature comes from
root@mx3:~# fgrep Sanesecurity.Jurlbl.0c9ed5 /var/lib/clamav-unofficial-sigs/dbs-ss/jurlbl.ndb
Sanesecurity.Jurlbl.0c9ed5:4:*:(2e|2f|40|20|3c|5f)6e65746d656469612e67726f7570(27|22|20|2f|3d|5f|3e|0a|0d|3f|3c|25|23)
root@mx3:~#
Any ideas how to disable that particular rule?
I know how to mark false positives, but only for attachments, not for entire mails like in my case. Also, I cannot just edit the pattern file, since it is cryptographically signed.
3