Hi Gang
At the moment we see a lot of phishing emails with UTF-8 encoded
subject containing emojis like:
=?UTF-8?Q?=E2=9C=85_Dein_Paket_wartet_auf_dich!_-14.12.2021-?=
I noticed a Rule:
header PP001 Subject =~ /=\?UTF-8\?Q\?=E2=9C=85_Dein_Paket/
is not matching.
Neiter does: /Dein_Paket/
But /Dein\ Paket/
Does match. So it looks like SpamAssassin is passing the 'decoded'
header.
Unfortunately the 'readable' part is a bit too generic. I would like to
also match the emoji.
How do I do this? There is no rawheader or rawbody matcher as far as I
could determine.
--
Mit freundlichen Grüssen
-Benoît Panizzon- @ HomeOffice und normal erreichbar
--
I m p r o W a r e A G - Leiter Commerce Kunden
______________________________________________________
Zurlindenstrasse 29 Tel +41 61 826 93 00
CH-4133 Pratteln Fax +41 61 826 93 01
Schweiz Web http://www.imp.ch
______________________________________________________
At the moment we see a lot of phishing emails with UTF-8 encoded
subject containing emojis like:
=?UTF-8?Q?=E2=9C=85_Dein_Paket_wartet_auf_dich!_-14.12.2021-?=
I noticed a Rule:
header PP001 Subject =~ /=\?UTF-8\?Q\?=E2=9C=85_Dein_Paket/
is not matching.
Neiter does: /Dein_Paket/
But /Dein\ Paket/
Does match. So it looks like SpamAssassin is passing the 'decoded'
header.
Unfortunately the 'readable' part is a bit too generic. I would like to
also match the emoji.
How do I do this? There is no rawheader or rawbody matcher as far as I
could determine.
--
Mit freundlichen Grüssen
-Benoît Panizzon- @ HomeOffice und normal erreichbar
--
I m p r o W a r e A G - Leiter Commerce Kunden
______________________________________________________
Zurlindenstrasse 29 Tel +41 61 826 93 00
CH-4133 Pratteln Fax +41 61 826 93 01
Schweiz Web http://www.imp.ch
______________________________________________________