First, SA does not by default drop emails, but it can take them so high in spam content that they don’t appear to anyone in your inbox. Secondly, the “ingredients” I started with were wrong, plus messed up with the ability of SA to function at all.
Actually this trick was added in /etc/spamassassin/local.cf :
full TROJAN_ZIPUNDS /\w*[_][\d]{1,6}\.zip/img score TROJAN_ZIPUNDS 99 describe TROJAN_ZIPUNDS RM zip attached trojan underscore
Despite the fact that these spammers have been changed from zip to rar to emphasize dashes, different file names, etc., creating rules to deal with them has become easy after success with the first. Here is what I added:
full TROJAN_RARDASH /\w*[-][\d]{1,6}\.rar/img score TROJAN_RARDASH 99 describe TROJAN_RARDASH RM rar attached trojan dash
In addition, as described above, I had to specifically block some zip file names, which soon turned into rar and dash, so converting a regular expression and adding a triad as a rule to spamassassin local.cf (and restarting) is currently running, until next spam wave :-)
Finally, this is a very very dumb workaround, so anyone with experience in this area is more than welcome to listen.
source share