Has anyone noticed that the Sobig.f worm that is going around rampantly at the moment is getting detected quite well by SpamAssassin ? :)

Normally our virus scanner runs before SA gets a chance to run, but on a test machine I'm trying 2.60-rc2 out on SA is getting to scan virus infected emails....

0.2 NO_REAL_NAME From: does not include a real name
0.0 BAYES_50 BODY: Bayesian spam probability is 50 to 56%
[score: 0.5460]
1.1 RAZOR2_CF_RANGE_51_100 BODY: Razor2 gives confidence between 51 and 100
[cf: 100]
0.1 MICROSOFT_EXECUTABLE RAW: Message includes Microsoft executable program
1.0 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
2.9 DCC_CHECK Listed in DCC (http://rhyolite.com/anti-spam/dcc/)
0.8 MSGID_FROM_MTA_BACKUP Message-Id was added by a relay
1.6 MISSING_MIMEOLE Message has X-MSMail-Priority, but no X-MimeOLE
0.5 MIME_BOUND_NEXTPART Spam tool pattern in MIME boundary
2.6 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook


Looks like people submitted the worm's emails to both razor and DCC :)

Regards,
Simon



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Spamassassin-talk mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/spamassassin-talk

Reply via email to