Last Modified:

OITC's
STF Virus & SPAM/UCE Rule Data Base
Release Notes

OITC uses the Eudora Internet Mail Server and Simple Text Filter


VirusAlert_120x60 OITC's rules data base has been built to attempt to help mail admins manage and select the contextual filtering rules appropriate to there own facility.

The Rules Set Data Base for Simple Text Filter version 1.5.1.3 and below is presently available online in a database at Common Ground Softworks or downloadable in Excel format with expanded information at OITC's EIMS Information Area. If you cannot support Excel and do not wish to use the online database, please contact us at STFRules@oitc.com


Release Notes

Version 1.5.1.5, dated 18 April 2004

Corrected some errors. Added new special rules.

Version 1.5.1.4, dated 24 March 2004

Rules have been tightened and consolidated to support winnow. AV rules added. Note: There are new MACROs required.

Version 1.5.1.3, dated 12/17/2003

Rules have been tightened and consolidated to support winnow. Note: There are new MACROs required.

Version 1.5.1.2, dated 8/28/2003

New virus rules have been added to deal with sobig and others as well as new format and content rules. Some older format and content rules have been retired. Persistent rules in 45 days have moved to Content as well as having new 45 day rules and an updated whitelist and filter exclusions. More persistant spammer's IPs have been located and placed in the DNSbl list.

Version 1.5.1.1, dated 7/28/2003

New virus rules have been added to deal with variants as well as new format and content rules. Some older format and content rules have been retired. Persistent rules in 45 days have moved to Content as well as having new 45 day rules and an updated whitelist and filter exclusions. More persistant spammer's IPs have been located and placed in the DNSbl list. Note: There is a new MACRO required.

Version 1.4.2.2, dated 6/19/2003

The current version of the rules is 1.4.2.2, dated 6/19/2003 for version 1.4.2 and below of the Filter.

New virus rules have been added to deal with variants of Yaha as well as new format and content rules. Some older format and content rules have been retired. Persistent rules in 45 days have moved to Content as well as having new 45 day rules and an updated whitelist and filter exclusions. More persistant spammer's IPs have been located and placed in the DNSbl list. Note: There is a new MACRO required.

Version 1.4.2, dated 2/23/2003

Version 1.4.2 of the rules is dated 2/23/2003 for version 1.4.2 and below of the Filter.

New virus rules have been added as well as new format rules covering more insecure form texts and a new mailer signature. Persistent rules in 45 days have moved to Content as well as new 45 day rules and an updated whitelist.

Version 1.4, dated 10/26/2002

TVersion 1.4 of the rules is dated 11/3/2002.

This release notes file will not be updated just for a rule addition as rules could be added multiple times per day under a new, not covered virus attack, for example. This FAQ will only be updated when something signigicant happens to the rules set or a new release of Simple Text Filter happens.

11/3/2002 - New virus rules, deleted old and more anti-Nigeria. Won't is ever stop?
10/26/2002 - 1.4a New virus rules, deleted old and added persistant spammer rules and more anti-Nigeria
9/22/2002 - Retailoring
8/12/2002 - Maintenance update after work with Scott
7/10/2002 - Rules updated for 1.3.1
5/10/2002 - Rules updated for 1.3
3/15/2002 - Rules updated for 1.2


Previous History

# 12/29/01	v1.1.1		History moved to webpages
# 12/14/01	v1.1.1a1		Converted over to Excel
# 12/01/01	v1.0.47		Mass mailers & FFA's, removed lotsfree, dsl speedup, another 911 scam
# 11/30/01	v1.0.46		Gambling, secure email, porno, protection, cromagnons, latvian spammer, and security software. Added & removed some test rules and redid messages also removed mindspink, linksus rules
# 11/28/01	v1.0.45		Reordered history, tightened up spam 1, panix update, x, bulk, redirect site, more "senders"
# 09/02/01	v1.0		Completed initial debug and went operational after testing
# 09/05/01	v1.0.1		Added backup testing for attachments and language testing
# 09/07/01	v1.0.2		Added more spam filters and removed some and minor fix for W95.Hybris.gen
# 09/08/01	v1.0.3		Improved some SPAM greps
# 09/09/01	v1.0.4		Improved some SPAM greps
# 09/10/01	v1.0.5		More SPAM greps
# 09/11/01	v1.0.6		Caught more bulkmailers & spy & golf spams & some SPAM domains
# 09/12/01	v1.0.7		Caught more spam & casino domains
# 09/13/01	v1.0.8		Fixed remove me regex and big 5
# 09/16/01	v1.0.9		Added some CC SPAM, grants and others. Removed W97M/Melissa.gen@MM.U
# 09/18/01	v1.0.10		Fine tuned more regex and added more language varients and spam companies
# 09/19/01	v1.0.11		Fine tuned more regex and added another spam company and porno removes
# 09/21/01	v1.0.12		Added Insurance SPAMs, SCAMs and Printer Supplies
# 09/26/01	v1.0.13		More spam domains, refined filters and W32.Vote.A@mm virus [0, %h (%i), %s]
# 09/28/01	v1.0.14		More spam domains, removals, search engines, clipping, more tuning and W32.Vote.B@mm and removed Pricilla virus [0, %h (%i), %s]
# 09/28/01	v1.0.15		Misc updates
# 10/05/01	v1.0.16		Converted over from Filtre & Go to SimpleTextFilter
# 10/06/01	v1.0.17		Added more SPAM detections specialially around Spamware and receive chains
# 10/10/01	v1.0.18		Misc updates - attachments still don't work yet
# 10/27/01	v1.0.19		Major update and rework
# 10/28/01	v1.0.20		New emails and spam sites
# 10/29/01	v1.0.21		Added TLD SCAMs, and new casinos, domains, drugs, removes and cell phones as well as misc updates
# 10/30/01	v1.0.22		Added new casino, mass mailers and freewebs. Also Anthrax drugs and chains
# 10/31/01	v1.0.23		Fixed attachment filters, added support for b9, misc SPAM updates and new virus
# 11/04/01	v1.0.24		Stopped some legal, superbowl spam, free sites, and typos
# 11/06/01	v1.0.25		Only a single new casino and some other stuff
# 11/07/01	v1.0.26		911 spam this morning and new bulk mailer. Also added older attachment detection and rule fine tuning
# 11/08/01	v1.0.27		Added support for b12 and found a new nigeria variant. Corrected some rule errors
# 11/09/01	v1.0.28		Delt with travel scams and timeshares and added filtering for dialup domain spam
# 11/12/01	v1.0.29		Delt with travel scams and timeshares and added filtering for dialup domain spam
# 11/13/01	v1.0.30		Pirates, more drugs, more domains, more psyic, merged in Steve's and a new update from concordia.ca
# 11/14/01	v1.0.31		More pirates and maybe a new signature for SPAM
# 11/15/01	v1.0.32		More free spams and maybe a new signature for SPAM
# 11/16/01	v1.0.33		New telephones, film spammer and a new remove site and a make-it-bigger scam
# 11/17/01	v1.0.34		Sildenafil Citrate (fake viagra) , another X, a cartoon X site, more bulk mailers, vending machines and anti IRS Also removed 2 test rules due to too many false positives.
# 11/18/01	v1.0.35		Changed number of cc's and bcc's to 19 to trip rule, gems, drugs, and another bulk sender
# 11/19/01	v1.0.36		New Nigeria variant, canadian registrar spam, javascript, qatarmail.com, new remove, new redirects, and personals. Also retired some rules in test
# 11/20/01	v1.0.37		New work at home, new bulk mailers, new spam support site, new sex site, insurance scam
# 11/21/01	v1.0.38		Fixed error in receive: 000 rule updated attachment rules, removed some rules in test, block travel spam
# 11/22/01	v1.0.39		Put some new rules under test, child support, new tld, clothes, invest, search ranking, various spam, concordia.ca update, added date & source tracking
# 11/23/01	v1.0.40		New remove, identity hijack, new drugs & dsl speedup.
# 11/24/01	v1.0.41		Because %* stops at first char. tightened up the SIRCAM checks, and free host
# 11/25/01	x-Inactive		mass mailer, shortened patterns for attachments and viruses
# 11/26/01	v1.0.43		new XXX, sweeps, and french scam
# 11/27/01	v1.0.44		New tld, get rich quick, meds, hosting, collapsed some rules, linen (can you believe it), and added support for W32.Badtrans.B@mm and corrected Content-Disposition: rules (newer standard) to Content-Type: (original MIME standard) rules to cath older Microsoft and other mail clients.



©2001-2002 by OITC. All rights Reserved, USA and Worldwide