> Hi all,
> I am new to the list and want thank you in advance if you help me on this.
>
> I am creating the following rule:
>
> header   VIRUS_DHL1        FROM =~ /dhl-usa.com/i
> header   VIRUS_DHL2        ALL =~ /text inside the email to check for/i
> meta     VIRUS_DHLTOTAL    (VIRUS_DHL1 && VIRUS_DHL2)
> describe VIRUS_DHLTOTAL    DHL-USA Virus
> score    VIRUS_DHLTOTAL    11
>
> But the rule is not working fine. Any idea what is the error with this
> rule?
>
> By the way, if you wonder if my antivirus has stopped this, yes it has
> stopped all the emails that comes with the exe file attached to the email,
> but there was a lot of them that didn't come with the EXE file and for that
> is why I am creating this rule.
>
> Best Regards,
>
> Sergio Cabrera
>

Reply via email to