Cisco-Talos / clamav

ClamAV - Documentation is here: https://docs.clamav.net
https://www.clamav.net/
GNU General Public License v2.0
4.43k stars 706 forks source link

Password Protected Doc File PUA.Doc.Packed.EncryptedDoc-6563700-0 #1219

Closed anandcloudcall closed 7 months ago

anandcloudcall commented 7 months ago

How to prevent .docx file to mark as unsafe

micahsnyder commented 7 months ago

If you wish to report an FP, you can submit it here: https://www.clamav.net/reports/fp If you wish to report undetected malware, you can submit it here: https://www.clamav.net/reports/malware

It's not clear to me what you're asking. Regardless, this ticket queue is to report bugs in clamav and not detection issues.

I would also note that you appear have PUA (Potentially Unwanted Application) signature enabled. PUA signatures detect stuff that is suspicious or undesirable but is often times not actually malware. With PUA signatures in particular, you may simply need to ignore the alert.

If you want ClamAV to trust the specific file, or ignore a specific signature, you can create a signature and add it to your ClamAV database directory. For details: https://docs.clamav.net/manual/Signatures/AllowLists.html