Re: [Assp-test] ClamAV regexp

2009-06-03 Thread GrayHat
If I'm not wrong, starting from the following regexp INetMsg\.=>1.0 Heuristics=>1.25 Safebrowsing=>1.25 Sanesecurity\.Jurlbl\.Auto\.x=>1.6 INetMsg\.SpamDomain-2w\.=>2.0 (MSRBL-Images\.)=>2.1 winnow\.spam\.x=>2.1 Sanesecurity\.Jurlbl\.x=>2.6 Email.Spam\d{1,4}-SecuriteInfo=>4.1 (Email|HTML|Sanesecur

Re: [Assp-test] ClamAV regexp

2009-06-01 Thread Tom Shaw
At 6:02 PM +0200 6/1/09, Grayhat wrote: > > Its not working? What is wrong? Mine is similar but I don't use the >> anchor (^) and I have a couple more: > >afaik scores over 6 are treated as "weight" not as a "multiplier" so >those 6.1 aren't probably ok in our case > >> eicar=>0 >> Safebrowsing

Re: [Assp-test] ClamAV regexp

2009-06-01 Thread Grayhat
> Its not working? What is wrong? Mine is similar but I don't use the > anchor (^) and I have a couple more: afaik scores over 6 are treated as "weight" not as a "multiplier" so those 6.1 aren't probably ok in our case > eicar=>0 > Safebrowsing=>1.25 > Heuristics=>1.25 Hmmm... yes, those shoul

Re: [Assp-test] ClamAV regexp

2009-06-01 Thread Fritz Borgstedt
ASSP development mailing list schreibt: >Mine is similar Please show them -- Register Now for Creativity and Technology (CaT), June 3rd, NYC. CaT is a gathering of tech-side developers & brand creativity professional

Re: [Assp-test] ClamAV regexp

2009-06-01 Thread Tom Shaw
At 3:37 PM +0200 6/1/09, Grayhat wrote: >Anyone volunteering to turn the following into ASSP usable regexp ? > >^Phishing\.=>4.6 >^Email.Spam\d{1,4}-SecuriteInfo=>4.1 >^(Email|HTML|Sanesecurity)\.(Phishing|Spear|(Spam|Scam)[a-z0-9]?)\.i=>4.6 >^Sanesecurity\.(Hdr|Img|ImgO|Junk|Doc|Casino)\.x=>6.1 >^

[Assp-test] ClamAV regexp

2009-06-01 Thread Grayhat
Anyone volunteering to turn the following into ASSP usable regexp ? ^Phishing\.=>4.6 ^Email.Spam\d{1,4}-SecuriteInfo=>4.1 ^(Email|HTML|Sanesecurity)\.(Phishing|Spear|(Spam|Scam)[a-z0-9]?)\.i=>4.6 ^Sanesecurity\.(Hdr|Img|ImgO|Junk|Doc|Casino)\.x=>6.1 ^Sanesecurity\.(Lott|Fake|SpamImg|Job|Stk)\.x=>6