[clamav-users] Matching variant patterns in logical or Yara signatures

Kris Deugau kdeugau at vianet.ca
Wed Jan 17 16:33:44 UTC 2018

G.W. Haywood wrote:
> Hi there,
> On Tue, 16 Jan 2018, Kris Deugau wrote:
>> I'm trying to create signatures to match a particular series of
>> large to very large spams whose main identifier is a <style> or
>> <script> tag containing neither CSS or Javascript.
>> However, I'm having trouble finding a valid signature string ...
> I wonder if it would be easier to filter the sender(s) rather than to
> filter the messages.  I use GeoIP and a homebrew Sendmail milter very
> successfully, and I never see the sort of spam you describe.  Can you
> share with this list some of the IP addresses from which the messages
> are being sent?  A couple of dozen would be a good start I think.

"All over the place".

Received: from propet.ouruntain.com (propet.ouruntain.com [])
Received: from ohours.healtspa.net (unknown []) by
Received: from obesrum.net (obesrum.net []) by mx1.vianet.ca
Received: from promt.easyuest.net (promt.easyuest.net []) by
Received: from smpx.infcket.com (smpx.infcket.com []) by
Received: from [] (helo=vedla.renthant.net) by
Received: from frisplay.net (frisplay.net []) by 
Received: from yoyita.shallenge.net (yoyita.shallenge.net []) by
Received: from firsia.net (firsia.net []) by mx2.vianet.ca
Received: from yoyita.ouruntain.com (yoyita.ouruntain.com []) by
Received: from redha.direghting.com (redha.direghting.com []) by
Received: from perie.awesomder.net ([]) by
Received: from khabhi.smoothving.com (khabhi.smoothving.com 
Received: from [] (helo=purplebin.net) by
Received: from udg.karft.net (unknown []) by mx1.vianet.ca
Received: from starz.virtualree.net ([]) by
Received: from umrp.exceama.net ([]) by

We only hard block on Spamhaus hits and a handful of sender addresses; 
our experience with seeing other providers' variously more aggressive IP 
blocking result in blocked legitimate mail has left us disinclined to do 
the same.

I feed the IPs to a local DNSBL, but it's only used as a scored result 
in SpamAssassin;  we don't get enough volume in the process (and 
occasionally mis-list something that shouldn't have been) to reliably 
reject mail outright on it.

We also don't see these broadly over our user base (I don't see any to 
my staff account or any of the aliases it's in, nor to anything directed 
to my personal account on my own server), but they're regularly reported 
by a couple of customers.


