Wow. I think this is the most blocklist hits I’ve ever seen in
a mail… the open relay 61.159.235.36 is listed in a whole 19 DNS
blocklists.
Aha. looking it up, it’s in China. That explains it… Full message here.
Date: Thu, 17 Apr 2003 07:51:51 +0000
From: “HGH Free Sample” (spam-protected)
To: (spam-protected)
Subject: SPAM(40.60) Shed Weight While You Sleep with HGH hyvsjpilripyoiebf
This is a multi-part message in MIME format.
————=_3E9E19A5.69236551
Content-Disposition: inline
This mail is probably spam. The original message has been attached
along with this report, so you can recognize or block similar unwanted
mail in future. See http://spamassassin.org/tag/ for more details.
Content preview: As seen on NBC, CBS, CNN, and even Oprah! The health
discovery that actually reverses aging while burning fat.
Content analysis details: (40.60 points, 5 required)
T_DATE_SPAMWARE_Y2K (0.0 points) Date header uses unusual Y2K formatting
ADDR_FREE (0.8 points) From Address contains FREE
RATWARE_EGROUPS (4.3 points) Bulk email software fingerprint (eGroups) foun
d in headers
FROM_ENDS_IN_NUMS (0.7 points) From: ends in numbers
BANG_OPRAH (4.3 points) BODY: Talks about Oprah with an exclamation!
SOME_BREAKTHROUGH (0.9 points) BODY: Describes some sort of breakthrough
WHILE_YOU_SLEEP (2.6 points) BODY: While you Sleep
REVERSE_AGING (2.9 points) BODY: Reverses Aging
BANG_EXERCISE (2.7 points) BODY: Talks about exercise with an exclamation
!
DIET (0.0 points) BODY: Lose Weight Spam
AS_SEEN_ON (3.3 points) BODY: As seen on national TV!
T_AS_SEEN_ON (0.0 points) BODY: /seenn\b\s*(?:TV|ABC|NBC|CBS|CNN|Op
rah|USA Today|48 Hours|(The )?New York Times|\w+\s+TV|:)/i
T_BLANK_LINE_RATIO_01_08_10 (0.0 points) BODY: T_BLANK_LINE_RATIO_01_08_10
HTML_50_60 (0.1 points) BODY: Message is 50% to 60% HTML
BAYES_90 (2.9 points) BODY: Bayesian classifier says spam probabilit
y is 90 to 99%
[score: 0.9050]
HTML_MESSAGE (0.0 points) BODY: HTML included in message
T_BLANK_LINE_RATIO_20_08_10 (0.0 points) BODY: T_BLANK_LINE_RATIO_20_08_10
T_BLANK_LINE_RATIO_04_08_10 (0.0 points) BODY: T_BLANK_LINE_RATIO_04_08_10
T_BLANK_LINE_RATIO_08_08_10 (0.0 points) BODY: T_BLANK_LINE_RATIO_08_08_10
HTML_TAG_BALANCE_HTML (0.0 points) BODY: HTML has unbalanced “html” tags
T_MIME_QP (0.0 points) RAW: T_MIME_QP
MIME_HTML_NO_CHARSET (0.0 points) RAW: Message text in HTML without specified
charset
FORGED_RCVD_HELO (1.0 points) Received: contains a forged HELO
DATE_IN_FUTURE_03_06 (1.5 points) Date: is 3 to 6 hours after Received: date
T_RCVD_IN_DEADBEEF (0.0 points) RBL: T_RCVD_IN_DEADBEEF
[RBL A check: found 36.235.159.61.bl.deadbeef.com., type: 12
7.0.0.2]
RCVD_IN_NJABL (1.2 points) RBL: Received via a relay in dnsbl.njabl.org
[RBL A check: found 36.235.159.61.dnsbl.njabl.org., type: 12
7.0.0.9]
RCVD_IN_OSIRUSOFT_COM (0.5 points) RBL: Received via a relay in relays.osiruso
ft.com
[RBL A check: found 36.235.159.61.relays.osirusoft.com., typ
e: 127.0.0.9]
RCVD_IN_UNCONFIRMED_DSBL (0.0 points) RBL: Received via a relay in unconfirmed
.dsbl.org
[RBL TXT check: found 36.235.159.61.unconfirmed.dsbl.org., t
ype: http://dsbl.org/listing?ip=61.159.235.36]
T_RCVD_IN_WIREHUB_PROXIES (0.0 points) RBL: T_RCVD_IN_WIREHUB_PROXIES
[RBL A check: found 36.235.159.61.proxies.blackholes.wirehub
.net., type: 127.0.0.2]
T_RCVD_IN_GIPPER (0.0 points) RBL: T_RCVD_IN_GIPPER
[RBL A check: found 36.235.159.61.proxy.bl.gweep.ca., type:
127.0.0.1]
T_RCVD_IN_WIREHUB_BH (0.0 points) RBL: T_RCVD_IN_WIREHUB_BH
[RBL A check: found 36.235.159.61.blackholes.wirehub.net., t
ype: 127.0.0.2]
RCVD_IN_DSBL (4.3 points) RBL: Received via a relay in list.dsbl.org
[RBL TXT check: found 36.235.159.61.list.dsbl.org., type: ht
tp://dsbl.org/listing?ip=61.159.235.36]
RCVD_IN_BL_SPAMCOP_NET (0.0 points) RBL: Received via a relay in bl.spamcop.ne
t
[RBL TXT check: found 36.235.159.61.bl.spamcop.net., type: B
locked – see http://spamcop.net/bl.shtml?61.159.235.36]
T_RCVD_IN_SORBS (0.0 points) RBL: T_RCVD_IN_SORBS
[RBL A check: found 36.235.159.61.dnsbl.sorbs.net., type: 12
7.0.0.2]
RCVD_IN_SBL (1.1 points) RBL: Received via SBLed relay, see http://www.
spamhaus.org/sbl/
[RBL TXT check: found 36.235.159.61.sbl.spamhaus.org., type:
Listed on SBL - see http://spamhaus.org/SBL/sbl.lasso?query=SBL5950]
RCVD_IN_OPM (4.3 points) RBL: Received via a relay in opm.blitzed.org
[RBL TXT check: found 36.235.159.61.opm.blitzed.org., type:
open proxy – see http://blitzed.org/proxy/?ip=61.159.235.36]
T_RCVD_IN_OSSOCKS (0.0 points) RBL: T_RCVD_IN_OSSOCKS
[RBL A check: found 36.235.159.61.socks.relays.osirusoft.com
., type: 127.0.0.9]
T_RCVD_IN_MONKEYS_UPL (0.0 points) RBL: Received via a relay in proxies.relays
.monkeys.com.
[RBL TXT check: found 36.235.159.61.proxies.relays.monkeys.c
om., type: BLOCKED: See http://www.monkeys.com/upl/listed-ip-0.cgi?ip=61.159.23
5.36]
T_RCVD_IN_OPM_HTTP_CONNECT (0.0 points) RBL: T_RCVD_IN_OPM_HTTP_CONNECT
T_RCVD_IN_SORBS_HTTP (0.0 points) RBL: T_RCVD_IN_SORBS_HTTP
T_RCVD_IN_FIVETEN_SPAM (0.0 points) RBL: T_RCVD_IN_FIVETEN_SPAM
T_RCVD_IN_OPM_HTTP_POST (0.0 points) RBL: T_RCVD_IN_OPM_HTTP_POST
MISSING_MIMEOLE (0.1 points) Message has X-MSMail-Priority, but no X-MimeOL
E
MIME_HTML_ONLY (0.1 points) Message only has text/html MIME parts
HG_HORMONE (1.0 points) Talks about hormones for human growth
T_MIME_HTML_NO_DOCTYPE (0.0 points) T_MIME_HTML_NO_DOCTYPE
MISSING_OUTLOOK_NAME (0.0 points) Message looks like Outlook, but isn’t
The original message did not contain plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.
————=_3E9E19A5.69236551
Content-Description: original message before SpamAssassin
Content-Disposition: attachment
by localhost.jmason.org (Postfix) with ESMTP id 714158B318
for (spam-protected) Wed, 16 Apr 2003 23:03:54 -0400 (EDT)
by localhost with IMAP (fetchmail-5.9.0)
for (spam-protected) (single-drop); Wed, 16 Apr 2003 20:03:54 -0700 (PDT)
From: “HGH Free Sample” (spam-protected)
To: (spam-protected)
Subject: Shed Weight While You Sleep with HGH hyvsjpilripyoiebf
Date: Thu, 17 Apr 03 07:51:51 GMT
This is a multi-part message in MIME format.
–8_0AED7_CBCE_D_E.1F.
<
p>
> As seen on
NBC, CBS, CNN, and even Oprah!
> The health
discovery that actually reverses aging while burning fat.
> Without dieting
or exercise!
<
p>
> Forget aging
and dieting forever!
>
l, Helvetica, sans-serif”>Get
<
p>
Your Free Bottle Now! Visit Us Here
<
p align=’3D”center”‘>
<
p align=’3D”center”‘>
<
p align=’3D”center”‘>
<
p align=’3D”center”‘>
<
p align=’3D”center”‘>
<
p align=’3D”center”‘>
Why was this email sent to you? At
some point you registered or
made a purchase on a Web site with privacy policies
explaining that they may
share your information with partners who will send you
valuable offers
from time to time.
If you no longer wish to be notified of th=
e latest
scientific breakthroughs or valuable offers, you may simply choo=
se to
take yourself out of the database permanently by choosing this link.
|