One of our clients setup the following rule:
B~TVqQA...AMAAA!OR!B~UEsD ... BAoAAA:NUL
So far it has successfully only caught the my doom variants. I believe however that this has the tendency to catch legit attachments. Can attest to this?
I believe that will capture all .exe files and most .ZIP files.
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
