I took a look at that, and I couldn't clearly see any generic Windows
executable signature strings. It looks like basically:

 1) test (using straight procmail) for MIME headers about an
executable attachment, then

   2) scan for signature strings to identify which specific attack

Those rules look like a limited subset of what the Sanitizer already
does. I've discussed before why pure procmail cannot reliably detect
attachment-based attacks.

