X-Git-Url: https://git.donarmstrong.com/?a=blobdiff_plain;f=common%2Fvirus_spam;h=5e88e97d09c27c5b7b0c6441b6a9232365ec2bb3;hb=204d2174dd6d37026ce104d22fe571dcd4c822a4;hp=151b21d6a94880504d3f06c376d30834ad0ca647;hpb=728db2e653d88568b0d59a91fa59843a17c4b01f;p=spamassassin_config.git diff --git a/common/virus_spam b/common/virus_spam index 151b21d..5e88e97 100644 --- a/common/virus_spam +++ b/common/virus_spam @@ -95,10 +95,23 @@ describe XEROX Scanner malware score XEROX 4 # don 2016-11-04 -header FEDEXPACKAGE subject=~/FedEx International|unable to deliver.*(item|parcel)/i +header FEDEXPACKAGE subject=~/(FedEx International|USPS courier)|((unable to|could not) deliver|problems? with).*(item|parcel)|shipment delivery problem|delivery notification|USPS delivery/i describe FEDEXPACKAGE Fedex Package Virus spam score FEDEXPACKAGE 4 -meta FEDEX_ZIP FEDEXPACKAGE && ZIPCOMPRESSED +#don 2016-11-04 +header SHIPPING_ID subject =~ /(ID:?|ID|\#|n\.|UPS(| parcel))\s*\d{7,}\s*\)?\s*($|shipment|delivery)/ +describe SHIPPING_ID Contains a long ID number at the end or folled by shipment +score SHIPPING_ID 3 + +header SHIP_ID_INT subject =~ /(ID:?|ID|\#|n\.|UPS(| parcel))\s*\d{7,}\s*/ +describe SHIP_ID_INT Contains a long ID number inside +score SHIP_ID_INT 1 + +rawbody MSWORD /application\/msword/ +describe MSWORD Has a word attachment +score MSWORD 2 + +meta FEDEX_ZIP (FEDEXPACKAGE || SHIPPING_ID || SHIP_ID_INT ) && ( ZIPCOMPRESSED || ZIPFILE || MSWORD ) describe FEDEX_ZIP Fedex package with zip file -score FEDEX_ZIP 3 +score FEDEX_ZIP 7