body Dangerous_URL /http{1,200}\.(?:exe|scr|pif)/i
describe Dangerous_URL Dangerous URL
score Dangerous_URL 7.5
Thanks in advance!
I am still getting some Storm Worm messages that are not being caught,
even with Sane Security / ClamAV. I thought I'd write a rule to score
any URL that has a dot exe, scr or pif extension. However, my rule is
not working. Can someone help advise what is wrong? I want it to
pickup any http or https with those extensions.
- Please help with rule Dave Koontz
- Please help with rule Dave Koontz
- Re: Please help with rule Joseph Brennan
- RE: Please help with rule Dave Koontz
- RE: Please help with rule Michael Hutchinson
- Re: Please help with rule Benny Pedersen
- Re: Please help with rule Loren Wilton
