WG: Rechnung offline Spam

Holger Gebhard holger at gebhardweb.de
Fri Jun 13 11:05:35 IST 2014

Hi Johan,

the copy/paste destroyed my rule... 
The right rule is attached in a text now ;-)

Best regards


-----Ursprüngliche Nachricht-----
Von: mailscanner-bounces at lists.mailscanner.info
[mailto:mailscanner-bounces at lists.mailscanner.info] Im Auftrag von Holger
Gesendet: Freitag, 13. Juni 2014 11:06
An: 'MailScanner discussion'
Betreff: AW: Rechnung offline Spam

Hi Johan,

this is my current anti-phishing rule for the telekom spams. If the spammers
change the messages from time to time you must tweak the regex a little bit.

header          __PHISHING_TXT_14060401 Subject =~ /RechnungOnline Monat/i
body            __PHISHING_TXT_14060402 /(?:als Anlage (?:ist|erhalten
Sie)|diese Nachricht finden Sie) die Rechnung \d+ als
body            __PHISHING_TXT_14060403
meta            TELEKOM_PHISHING_01        (__PHISHING_TXT_14060401 &&
__PHISHING_TXT_14060402 && __PHISHING_TXT_14060403)
score           TELEKOM_PHISHING_01       5.0
describe        TELEKOM_PHISHING_01        Typical phishing message parts

Best regards


-----Ursprüngliche Nachricht-----
Von: mailscanner-bounces at lists.mailscanner.info
[mailto:mailscanner-bounces at lists.mailscanner.info] Im Auftrag von Johan
Gesendet: Mittwoch, 11. Juni 2014 15:42
An: MailScanner List (mailscanner at lists.mailscanner.info)
Betreff: Rechnung offline Spam

Hello all.

I am trying to stop some spam but it seems MailScanner just lets them

It is about mail with the following Subject.
RechnungOnline Monat Juni 2014 (Buchungskonto: 4660367728)

So i made a custum.cf  file with the following

header TELECOM_SUBJECT      Subject =~ /RechnungOnline/i
score TELECOM_SUBJECT       5.1
describe TELECOM_SUBJECT    Telekom spam

Is my rule not ok, and is it looking for a subject ONLY with RechnungOnline

Secondly the mail contains a Trojan and that also is getting through?

Could someone please help me.


MailScanner mailing list
mailscanner at lists.mailscanner.info

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website! 

MailScanner mailing list
mailscanner at lists.mailscanner.info

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website! 
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: rule.txt
Url: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140613/77bcd4c6/attachment.txt 

More information about the MailScanner mailing list