One rule (369660) will code to 53 (scams).

Another (369650) will code to 53 (scams).

Another (369634) also codes to 53 (scams).

The rules got the scam tag because it presents like a phishing scam.

I'll be watching for evidence of additional polymorphism and we will
adapt. Now that we know this has a virus attached, new rules may be
coded to malware.

_M


On Monday, June 6, 2005, 6:01:17 PM, Jim wrote:

JM> Thanks Pete,
JM> What Return code will this be under?

JM> Jim Matuska Jr.
JM> Computer Tech2, CCNA
JM> Nez Perce Tribe
JM> Information Systems
JM> [EMAIL PROTECTED]
JM> ----- Original Message ----- 
JM> From: "Pete McNeil" <[EMAIL PROTECTED]>
JM> To: "Dave Koontz" <[email protected]>
JM> Sent: Monday, June 06, 2005 3:00 PM
JM> Subject: Re[2]: [sniffer] New Spam/Virus?


>> On Monday, June 6, 2005, 5:50:38 PM, Dave wrote:
>>
>> DK> Same exact IP  here!
>>
>> We've got a couple of rules for this now -- making the rounds as new
>> compiles go out.
>>
>> _M
>>
>>
>>
>> This E-Mail came from the Message Sniffer mailing list. For information
>> and (un)subscription instructions go to 
>> http://www.sortmonster.com/MessageSniffer/Help/Help.html
>> 


JM> This E-Mail came from the Message Sniffer mailing list. For
JM> information and (un)subscription instructions go to
JM> http://www.sortmonster.com/MessageSniffer/Help/Help.html


This E-Mail came from the Message Sniffer mailing list. For information and 
(un)subscription instructions go to 
http://www.sortmonster.com/MessageSniffer/Help/Help.html

Reply via email to