> Hi all,
> I am new to the list and want thank you in advance if you help me on this.
>
> I am creating the following rule:
>
> header VIRUS_DHL1 FROM =~ /dhl-usa.com/i
> header VIRUS_DHL2 ALL =~ /text inside the email to check for/i
> meta VIRUS_DHLTOTAL (VIRUS_DHL1 && VIRUS_DHL2)
> describe VIRUS_DHLTOTAL DHL-USA Virus
> score VIRUS_DHLTOTAL 11
>
> But the rule is not working fine. Any idea what is the error with this
> rule?
>
> By the way, if you wonder if my antivirus has stopped this, yes it has
> stopped all the emails that comes with the exe file attached to the email,
> but there was a lot of them that didn't come with the EXE file and for that
> is why I am creating this rule.
>
> Best Regards,
>
> Sergio Cabrera
>