MailScanner 過濾雅虎病毒信特徵

MailScanner 過濾雅虎病毒信特徵

文章super » 2009年 2月 15日, 11:07

使用來源特徵方式過濾
命中率(100%)
有些廣告信也會打中
代碼: 選擇全部
header   YahooDomainKey DomainKey-Signature =~ /yahoo/i
describe YahooDomainKey YahooDomainKey
score    YahooDomainKey 0.01
header   FORM_YahooMail Received =~ /yahoo\.com/i
describe FORM_YahooMail FORM_YahooMail
score    FORM_YahooMail 0.01
meta     YahooMail      (FORM_YahooMail && YahooDomainKey)
describe YahooMail      FORM_YahooMail & YahooDomainKey
score    YahooMail      0.01

#59.60.*.*
header   China_IP_A     Received =~ /\[59\.60\./i
describe China_IP_A     China_IP_A
score    China_IP_A     0.01
meta     YahooVirus_A   (YahooMail && China_IP_A)
describe YahooVirus_A   YahooVirus China 59.60.*.*
score    YahooVirus_A   100

#59.58.*.*
header   China_IP_B     Received =~ /\[59\.58\./i
describe China_IP_B     China_IP_B
score    China_IP_B     0.01
meta     YahooVirus_B   (YahooMail && China_IP_B)
describe YahooVirus_B   YahooVirus China 59.58.*.*
score    YahooVirus_B   100

#222.78.*.*
header   China_IP_C     Received =~ /\[222\.78\./i
describe China_IP_C     China_IP_C
score    China_IP_C     0.01
meta     YahooVirus_C   (YahooMail && China_IP_C)
describe YahooVirus_C   YahooVirus China 222.78.*.*
score    YahooVirus_C   100

#121.206.*.*
header   China_IP_D     Received =~ /\[121\.206\./i
describe China_IP_D     China_IP_D
score    China_IP_D     0.01
meta     YahooVirus_D   (YahooMail && China_IP_D)
describe YahooVirus_D   YahooVirus China 121.206.*.*
score    YahooVirus_D   100

#220.162.*.*
header   China_IP_E     Received =~ /\[220\.162\./i
describe China_IP_E     China_IP_E
score    China_IP_E     0.01
meta     YahooVirus_E   (YahooMail && China_IP_E)
describe YahooVirus_E   YahooVirus China 220.162.*.*
score    YahooVirus_E   100

#58.22.*.*
header   China_IP_F     Received =~ /\[58\.22\./i
describe China_IP_F     China_IP_F
score    China_IP_F     0.01
meta     YahooVirus_F   (YahooMail && China_IP_F)
describe YahooVirus_F   YahooVirus China 58.22.*.*
score    YahooVirus_F   100


#120.34.*.*
header   China_IP_G     Received =~ /\[120\.34\./i
describe China_IP_G     China_IP_G
score    China_IP_G     0.01
meta     YahooVirus_G   (YahooMail && China_IP_G)
describe YahooVirus_G   YahooVirus China 120.34.*.*
score    YahooVirus_G   100

super
系統管理員
 
文章: 2226
註冊時間: 2008年 8月 15日, 07:39

Re: MailScanner 過濾雅虎病毒信特徵

文章super » 2009年 2月 15日, 13:01

代碼: 選擇全部
header   YahooDomainKey DomainKey-Signature =~ /yahoo/i
describe YahooDomainKey YahooDomainKey
score    YahooDomainKey 0.01
header   FORM_YahooMail Received =~ /yahoo\.com/i
describe FORM_YahooMail FORM_YahooMail
score    FORM_YahooMail 0.01
meta     YahooMail      (FORM_YahooMail && YahooDomainKey)
describe YahooMail      FORM_YahooMail & YahooDomainKey
score    YahooMail      0.01

#59.60.*.*
header   China_IP_A     Received =~ /\[59\.60\./i
describe China_IP_A     China_IP_A
score    China_IP_A     0.01
meta     YahooVirus_A   (YahooMail && China_IP_A)
describe YahooVirus_A   YahooVirus China 59.60.*.*
score    YahooVirus_A   100

#59.58.*.*
header   China_IP_B     Received =~ /\[59\.58\./i
describe China_IP_B     China_IP_B
score    China_IP_B     0.01
meta     YahooVirus_B   (YahooMail && China_IP_B)
describe YahooVirus_B   YahooVirus China 59.58.*.*
score    YahooVirus_B   100

#222.78.*.*
header   China_IP_C     Received =~ /\[222\.78\./i
describe China_IP_C     China_IP_C
score    China_IP_C     0.01
meta     YahooVirus_C   (YahooMail && China_IP_C)
describe YahooVirus_C   YahooVirus China 222.78.*.*
score    YahooVirus_C   100

#121.206.*.*
header   China_IP_D     Received =~ /\[121\.206\./i
describe China_IP_D     China_IP_D
score    China_IP_D     0.01
meta     YahooVirus_D   (YahooMail && China_IP_D)
describe YahooVirus_D   YahooVirus China 121.206.*.*
score    YahooVirus_D   100

#220.162.*.*
header   China_IP_E     Received =~ /\[220\.162\./i
describe China_IP_E     China_IP_E
score    China_IP_E     0.01
meta     YahooVirus_E   (YahooMail && China_IP_E)
describe YahooVirus_E   YahooVirus China 220.162.*.*
score    YahooVirus_E   100

#58.22.*.*
header   China_IP_F     Received =~ /\[58\.22\./i
describe China_IP_F     China_IP_F
score    China_IP_F     0.01
meta     YahooVirus_F   (YahooMail && China_IP_F)
describe YahooVirus_F   YahooVirus China 58.22.*.*
score    YahooVirus_F   100


#120.34.*.*
header   China_IP_G     Received =~ /\[120\.34\./i
describe China_IP_G     China_IP_G
score    China_IP_G     0.01
meta     YahooVirus_G   (YahooMail && China_IP_G)
describe YahooVirus_G   YahooVirus China 120.34.*.*
score    YahooVirus_G   100

super
系統管理員
 
文章: 2226
註冊時間: 2008年 8月 15日, 07:39


回到 Linux 筆記



cron