@shuro IIRC (Please, correct me if I am wrong) There are databases for viruses that anti-virus software use to check on and see if there is anything new added. People themselves contribute to databases also. I use Malwarebytes and now it has been 3 times already that it reacted onto Mastodon instances. @stux did say that there was a false positive in his instance case. I didn't exactly ask what databases he checked
Some of these detections are false, some can be warranted - sometimes malware can really be present, e.g. some file attached to the post or even web server infected.