One rule (369660) will code to 53 (scams). Another (369650) will code to 53 (scams).
Another (369634) also codes to 53 (scams). The rules got the scam tag because it presents like a phishing scam. I'll be watching for evidence of additional polymorphism and we will adapt. Now that we know this has a virus attached, new rules may be coded to malware. _M On Monday, June 6, 2005, 6:01:17 PM, Jim wrote: JM> Thanks Pete, JM> What Return code will this be under? JM> Jim Matuska Jr. JM> Computer Tech2, CCNA JM> Nez Perce Tribe JM> Information Systems JM> [EMAIL PROTECTED] JM> ----- Original Message ----- JM> From: "Pete McNeil" <[EMAIL PROTECTED]> JM> To: "Dave Koontz" <[email protected]> JM> Sent: Monday, June 06, 2005 3:00 PM JM> Subject: Re[2]: [sniffer] New Spam/Virus? >> On Monday, June 6, 2005, 5:50:38 PM, Dave wrote: >> >> DK> Same exact IP here! >> >> We've got a couple of rules for this now -- making the rounds as new >> compiles go out. >> >> _M >> >> >> >> This E-Mail came from the Message Sniffer mailing list. For information >> and (un)subscription instructions go to >> http://www.sortmonster.com/MessageSniffer/Help/Help.html >> JM> This E-Mail came from the Message Sniffer mailing list. For JM> information and (un)subscription instructions go to JM> http://www.sortmonster.com/MessageSniffer/Help/Help.html This E-Mail came from the Message Sniffer mailing list. For information and (un)subscription instructions go to http://www.sortmonster.com/MessageSniffer/Help/Help.html
