Need a SpamAssassin rule for sober.p worm

Posted on 2005-05-05
Last Modified: 2010-04-21
I am running procmail with Spam Assassin 2.63 on a FreeBSD server.  I am new to spam assassin and have some difficulty understanding the syntax.  Does anyone have a rule written to filter out the bombardment of mail with the sober.p virus attached?  
The subject lines include:
Re: mailing error
Re: Registration Confirmation
Re: Your email was blocked
Re: Your Password

I also see that although spam assassin may mark many of these messages as spam, it still lets them through to the user.  Is there a way that they can be bounced or deleted immediately?
Please help, when our mailboxes fill up it shuts down our ecommerce shared webserver at Verio!
Question by:sfghadmin
    LVL 40

    Accepted Solution

    You'd be better served by installing an Anti-Virus scanner on your system and integrating it into your mail system. I think you can build ClamAV ( on FreeBSD and setting the system up to use MailScanner ( would integrate the A/V and SpamAssassin checks on the mail stream.

    FYI: I've seen more subject lines than that...

    Assisted Solution

    ClamAV with Mailscanner strips the attachment, but still delivers the message.  To block the message, use the spamassassin rule from

    Otherwise, you can make your own rules as described at based on the virus description at

    I'm working on rules to block this as well.  Anybody got an SA ruleset specific to Sober that they want to share?

    Featured Post

    How to improve team productivity

    Quip adds documents, spreadsheets, and tasklists to your Slack experience
    - Elevate ideas to Quip docs
    - Share Quip docs in Slack
    - Get notified of changes to your docs
    - Available on iOS/Android/Desktop/Web
    - Online/Offline

    Join & Write a Comment

    Suggested Solutions

    Hello fellow BSD lovers, I've created a patch process for patching openjdk6 for BSD (FreeBSD specifically), although I tried to keep all BSD versions in mind when creating my patch. Welcome to OpenJDK6 on BSD First let me start with a little …
    FreeBSD on EC2 FreeBSD ( is a robust Unix-like operating system that has been around for many years. FreeBSD is available on Amazon EC2 through Amazon Machine Images (AMIs) provided by FreeBSD developer and security office…
    Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
    This video shows how to set up a shell script to accept a positional parameter when called, pass that to a SQL script, accept the output from the statement back and then manipulate it in the Shell.

    732 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now