summaryrefslogtreecommitdiffstats
path: root/conf
diff options
context:
space:
mode:
authorheraklit256 <37872459+heraklit256@users.noreply.github.com#>2018-09-09 18:21:12 +0200
committerheraklit256 <37872459+heraklit256@users.noreply.github.com#>2018-09-09 18:21:12 +0200
commit04b52561b0cf2545e40e7a87c330cd2c088063ac (patch)
treed43b885bb2dbdaf44deacdd6bbd58d78c8f64c83 /conf
parent5312495106b0dd974570b18495b1830cbdc525fd (diff)
downloadrspamd-04b52561b0cf2545e40e7a87c330cd2c088063ac.tar.gz
rspamd-04b52561b0cf2545e40e7a87c330cd2c088063ac.zip
improve composite rules for phish messages
Diffstat (limited to 'conf')
-rw-r--r--conf/composites.conf4
1 files changed, 2 insertions, 2 deletions
diff --git a/conf/composites.conf b/conf/composites.conf
index 24f198aac..12f445990 100644
--- a/conf/composites.conf
+++ b/conf/composites.conf
@@ -68,7 +68,7 @@ composites {
expression = "MAILER_1C_8 & (FROM_EXCESS_BASE64 | MIME_BASE64_TEXT | SUBJ_EXCESS_BASE64 | TO_EXCESS_BASE64)";
}
HACKED_WP_PHISHING {
- expression = "HAS_X_POS & HAS_WP_URI & PHISHING";
+ expression = "(HAS_X_POS | HAS_PHPMAILER_SIG) & HAS_WP_URI & (PHISHING | DBL_PHISH | PHISHED_OPENPHISH | PHISHED_PHISHTANK)";
description = "Phish message sent by hacked Wordpress instance";
policy = "leave";
}
@@ -105,7 +105,7 @@ composites {
score = 1.0;
}
PHISH_EMOTION {
- expression = "(HACKED_WP_PHISHING | DBL_PHISH | PHISHED_OPENPHISH | PHISHED_PHISHTANK) & (SUBJECT_ENDS_QUESTION | SUBJECT_ENDS_EXCLAIM)";
+ expression = "(PHISHING | DBL_PHISH | PHISHED_OPENPHISH | PHISHED_PHISHTANK) & (SUBJECT_ENDS_QUESTION | SUBJECT_ENDS_EXCLAIM)";
description = "Phish message with subject trying to address users emotion";
score = 2.0;
}