header RM_vbs_UndelivHi Subject =~ /Undeliverable: HI$/i describe RM_vbs_UndelivHi Apparent virus bounce sign score RM_vbs_UndelivHi 3.000 # type=spamg - 8s/0h of 100795 corpus (82099s/18696h) 02/16/04 header RM_vbs_UndelivTest Subject =~ /Undeliverable: Test/i describe RM_vbs_UndelivTest Apparent virus bounce sign score RM_vbs_UndelivTest 3.000 # type=spamg - 6s/0h of 100795 corpus (82099s/18696h) 02/16/04 header RM_vbs_UndelivVirus Subject =~ /Undeliverable:.{1,15}Virus/i describe RM_vbs_UndelivVirus Apparent virus bounce sign score RM_vbs_UndelivVirus 3.000 # type=spamg - 3s/0h of 100795 corpus (82099s/18696h) 02/16/04 meta VBOUNCE_SOBIG1 (RCVD_IN_RFCI && VBOUNCE_SUBJECT0) describe VBOUNCE_SOBIG1 We do not want reports about forged SoBig.F messages. score VBOUNCE_SOBIG1 100 body VBOUNCE_ATTACHMENT0 /(Attachment.{0,40}was Deleted|Virus.{1,40}was found|the infected attachment)/i describe VBOUNCE_ATTACHMENT0 Virus Bounce - Please keep these to yourself, we don't like forgery. score VBOUNCE_ATTACHMENT0 7.0 body VBOUNCE_AVREPORT0 /(antivirus system report|the antivirus module has|illegal attachment|Unrepairable Virus Detected|virus.{1,18}quarantined)/i describe VBOUNCE_AVREPORT0 Virus Bounce - Please keep these to yourself, we don't like forgery. score VBOUNCE_AVREPORT0 7.0 rawbody VBOUNCE_SUBJECT0 /^\s*Subject:\s*(Re: )*(Thank you!?|That movie|Wicked screensaver|Approved)/i describe VBOUNCE_SUBJECT0 Copy of virus "Thank you!" etc.. subject in body score VBOUNCE_SUBJECT0 2.5 # HOAXES #body __HOAX_JDBGMGR_TEDDY /teddy bear/i #body __HOAX_JDBGMGR_NOOPEN /do not open it/i #body __HOAX_JDBGMGR_EXENAME /jdbgmgr\.exe/i #meta JDBGMGR_HOAX ((__HOAX_JDBGMGR_TEDDY + __HOAX_JDBGMGR_NOOPEN + __HOAX_JDBGMGR_EXENAME) > 1) #describe JDBGMGR_HOAX JDBGMGR.EXE IS NOT A VIRUS, THIS IS A HOAX! #score JDBGMGR_HOAX 5.0 body FVGT_b_VIRUS1 /is infected with virus/i describe FVGT_b_VIRUS1 FVGT - virus reports are often forged score FVGT_b_VIRUS1 1.4