Spam detection software, running on the system "kualalumpur.lrde.epita.fr", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or block
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Save 70 percent on Viagra Save 70 percent on Viagra and
Increase Sex Drive. Most places charge $19.95, we charge only
URI:http://www.medz4cheap.com//via/?mrbig $2.95.
URI:http://www.medz4cheap.com//via/?mrbig What is ZENEGRA (Generic
Viagra)? ZENEGRA is a male impotence drug. It helps men obtain and
maintain an erection. Men that do not have impotence problems report
that ZENEGRA increases sexual pleasure and staying power, as well as
increasing the size and hardness of erections. 744114617
URI:http://www.medz4cheap.com//via/?mrbig Why should I buy ZENEGRA
(Generic Viagra)? We the cheapest source of generic Viagra on the
Internet. Viagra has helped over 25,000,000 American men regain their
sexual power. 242503 URI:http://www.medz4cheap.com//via/?mrbig Will you
ship ZENEGRA (Generic Viagra) to my country? Generic Viagra Online
ships worldwide including Canada, Japan, UK and Australia. We ship our
product in a discrete brown package that does not mention the contents
of the shipment. All orders are shipped from India and usually take
15-30 days to arive. 242503 URI:http://www.medz4cheap.com//via/?mrbig
How do i pay for ZENEGRA (Generic Viagra)? We accept major creditcards,
and checking accounts (US only). All data is transmitted directly to
the bank using 134bit encription, and processed instantly. We never
keep your information stored on our server. You are totally safe to
order online from us. Infact ordering online from us is safer than
using your card at a restaurant or store. 288708127
URI:http://www.medz4cheap.com//via/?mrbig Buy ZENEGRA Generic Viagra
and save over 70 percent! We have the worlds lowest prices GUARANTEED.
[...]
Content analysis details: (35.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
2.1 FROM_WEBMAIL_END_NUMS6 From webmail service and address ends in numbers
0.3 NO_REAL_NAME From: does not include a real name
0.9 FROM_ENDS_IN_NUMS From: ends in numbers
1.7 INVALID_DATE_TZ_ABSURD Invalid Date: header (timezone does not exist)
1.1 FROM_NUM_AT_WEBMAIL From address is webmail, but starts with a number
2.8 SUBJ_VIAGRA Subject includes "viagra"
0.7 ADDR_NUMS_AT_BIGSITE Uses an address with lots of numbers, at a big ISP
1.6 FROM_STARTS_WITH_NUMS From: starts with nums
4.2 IMPOTENCE BODY: Impotence cure
4.3 GENERIC_VIAGRA BODY: Mentions Generic Viagra
1.9 INCREASE_SEX BODY: Talks about a bigger drive for sex
1.1 VIAGRA_ONLINE BODY: Fast Viagra Delivery
0.5 HTML_40_50 BODY: Message is 40% to 50% HTML
0.0 HTML_MESSAGE BODY: HTML included in message
0.1 HTML_FONT_BIG BODY: HTML has a big font
0.1 HTML_FONTCOLOR_UNSAFE BODY: HTML font color not in safe 6x6x6 palette
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.4 HTML_FONT_INVISIBLE BODY: HTML font color is same as background
0.1 HTML_FONTCOLOR_RED BODY: HTML font color is red
0.6 DATE_IN_PAST_06_12 Date: is 6 to 12 hours before Received: date
0.5 FORGED_YAHOO_RCVD 'From' yahoo.com does not match 'Received' headers
1.1 RCVD_IN_DSBL RBL: Received via a relay in list.dsbl.org
[<http://dsbl.org/listing?ip=217.162.102.21>]
2.5 RCVD_IN_DYNABLOCK RBL: Sent directly from dynamic IP address
[217.162.102.21 listed in dnsbl.sorbs.net]
0.1 RCVD_IN_SORBS RBL: SORBS: sender is listed in SORBS
[217.162.102.21 listed in dnsbl.sorbs.net]
1.2 FROM_ALL_NUMS From an address that is all numbers (non-phone)
1.1 FORGED_MUA_IMS Forged mail pretending to be from IMS
4.3 FORGED_IMS_HTML IMS can't send HTML message only
The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.
Spam detection software, running on the system "kualalumpur.lrde.epita.fr", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or block
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: OEM Software URI:http://www.valuedsoft.biz/?242418
Specials good thru 11/12/03. Please use discount code mail9221 to
receive these prices. Software: Windows XP Suites, Adobe software,
Clearance, Corel Draw/Corel Ventura, Games, 3D Studio Max, Operating
Systems, Utilities. [...]
Content analysis details: (14.7 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.3 NO_REAL_NAME From: does not include a real name
0.9 FROM_ENDS_IN_NUMS From: ends in numbers
0.7 ADDR_NUMS_AT_BIGSITE Uses an address with lots of numbers, at a big ISP
1.6 FROM_STARTS_WITH_NUMS From: starts with nums
0.1 HTML_FONTCOLOR_UNKNOWN BODY: HTML font color is unknown to us
0.1 HTML_TAG_BALANCE_A BODY: HTML has excess "a" close tags
0.0 HTML_MESSAGE BODY: HTML included in message
0.2 HTML_TAG_BALANCE_TABLE BODY: HTML is missing "table" close tags
0.1 HTML_FONT_BIG BODY: HTML has a big font
0.1 HTML_70_80 BODY: Message is 70% to 80% HTML
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.8 BIZ_TLD URI: Contains a URL in the BIZ top-level domain
2.0 DATE_IN_FUTURE_12_24 Date: is 12 to 24 hours after Received: date
1.1 RCVD_IN_DSBL RBL: Received via a relay in list.dsbl.org
[<http://dsbl.org/listing?ip=67.87.229.145>]
0.5 RCVD_IN_NJABL_DIALUP RBL: NJABL: dialup sender did non-local SMTP
[67.87.229.145 listed in dnsbl.njabl.org]
2.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?67.87.229.145>]
2.5 RCVD_IN_DYNABLOCK RBL: Sent directly from dynamic IP address
[67.87.229.145 listed in dnsbl.sorbs.net]
0.1 RCVD_IN_NJABL RBL: Received via a relay in dnsbl.njabl.org
[67.87.229.145 listed in dnsbl.njabl.org]
0.1 RCVD_IN_SORBS RBL: SORBS: sender is listed in SORBS
[67.87.229.145 listed in dnsbl.sorbs.net]
1.2 FROM_ALL_NUMS From an address that is all numbers (non-phone)
The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.
Spam detection software, running on the system "kualalumpur.lrde.epita.fr", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or block
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Hello! My name is Victoria. I am an advertising manager
of the KARAVAN Co. In connection with expansion of our business to us
the agents in your country are required. If you is interesting this
information - ask to send us summary on [...]
Content analysis details: (25.6 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.3 NO_REAL_NAME From: does not include a real name
0.5 HTML_40_50 BODY: Message is 40% to 50% HTML
0.0 HTML_MESSAGE BODY: HTML included in message
0.4 HTML_TAG_BALANCE_HTML BODY: HTML has unbalanced "html" tags
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.3 HTML_EMBEDS BODY: HTML with embedded plugin object
3.1 USERPASS URI: URL contains username and (optional) password
2.4 HTTP_ESCAPED_HOST URI: Uses %-escapes inside a URL's hostname
2.4 URI_OFFERS URI: Message has link to company offers
1.9 DATE_IN_FUTURE_06_12 Date: is 6 to 12 hours after Received: date
1.1 RCVD_IN_DSBL RBL: Received via a relay in list.dsbl.org
[<http://dsbl.org/listing?ip=24.131.160.233>]
2.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?24.131.160.233>]
1.1 RCVD_IN_NJABL_PROXY RBL: NJABL: sender is an open proxy
[24.131.160.233 listed in dnsbl.njabl.org]
0.1 RCVD_IN_NJABL RBL: Received via a relay in dnsbl.njabl.org
[24.131.160.233 listed in dnsbl.njabl.org]
1.1 FORGED_MUA_IMS Forged mail pretending to be from IMS
4.3 FORGED_IMS_HTML IMS can't send HTML message only
4.3 FORGED_IMS_TAGS IMS mailers can't send HTML in this format
The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.
Spam detection software, running on the system "kualalumpur.lrde.epita.fr", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or block
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: OEM Software URI:http://www.valuedsoft.biz/?242279
Specials good thru 11/12/03. Please use discount code mail9221 to
receive these prices. Software: Windows XP Suites, Adobe software,
Clearance, Corel Draw/Corel Ventura, Games, 3D Studio Max, Operating
Systems, Utilities. [...]
Content analysis details: (12.9 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.3 NO_REAL_NAME From: does not include a real name
0.9 FROM_ENDS_IN_NUMS From: ends in numbers
0.7 ADDR_NUMS_AT_BIGSITE Uses an address with lots of numbers, at a big ISP
1.6 FROM_STARTS_WITH_NUMS From: starts with nums
0.1 HTML_FONTCOLOR_UNKNOWN BODY: HTML font color is unknown to us
0.1 HTML_TAG_BALANCE_A BODY: HTML has excess "a" close tags
0.0 HTML_MESSAGE BODY: HTML included in message
0.2 HTML_TAG_BALANCE_TABLE BODY: HTML is missing "table" close tags
0.1 HTML_FONT_BIG BODY: HTML has a big font
0.1 HTML_70_80 BODY: Message is 70% to 80% HTML
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.8 BIZ_TLD URI: Contains a URL in the BIZ top-level domain
0.6 DATE_IN_PAST_06_12 Date: is 6 to 12 hours before Received: date
0.2 SUBJ_HAS_UNIQ_ID Subject contains a unique ID
1.1 RCVD_IN_DSBL RBL: Received via a relay in list.dsbl.org
[<http://dsbl.org/listing?ip=68.63.77.61>]
2.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?68.63.77.61>]
2.5 RCVD_IN_DYNABLOCK RBL: Sent directly from dynamic IP address
[68.63.77.61 listed in dnsbl.sorbs.net]
0.1 RCVD_IN_SORBS RBL: SORBS: sender is listed in SORBS
[68.63.77.61 listed in dnsbl.sorbs.net]
1.2 FROM_ALL_NUMS From an address that is all numbers (non-phone)
The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.
Spam detection software, running on the system "kualalumpur.lrde.epita.fr", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or block
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Find your Match by Compatibility
URI:http://65.110.21.2/compatti/redirectCompatti.jsp?source=ntk040203
Find Your Match by Compatibility with Unique Relationship Astrology
URI:http://65.110.21.2/compatti/images/marriage_336x280_static.jpg
[...]
Content analysis details: (16.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.3 NO_REAL_NAME From: does not include a real name
1.0 SUBJ_HAS_SPACES Subject contains lots of white space
0.9 FROM_ENDS_IN_NUMS From: ends in numbers
0.7 ADDR_NUMS_AT_BIGSITE Uses an address with lots of numbers, at a big ISP
1.6 FROM_STARTS_WITH_NUMS From: starts with nums
0.3 LOTS_OF_STUFF BODY: Thousands or millions of pics/movies/etc
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 LINES_OF_YELLING BODY: A WHOLE LINE OF YELLING DETECTED
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.4 HTML_FONT_INVISIBLE BODY: HTML font color is same as background
0.2 HTML_50_60 BODY: Message is 50% to 60% HTML
1.5 HTML_IMAGE_ONLY_04 BODY: HTML: images with 200-400 bytes of words
0.2 NORMAL_HTTP_TO_IP URI: Uses a dotted-decimal IP address in URL
0.2 SUBJ_HAS_UNIQ_ID Subject contains a unique ID
1.1 RCVD_IN_DSBL RBL: Received via a relay in list.dsbl.org
[<http://dsbl.org/listing?ip=24.15.48.10>]
2.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?24.15.48.10>]
1.2 FROM_ALL_NUMS From an address that is all numbers (non-phone)
1.1 FORGED_OUTLOOK_TAGS Outlook can't send HTML in this format
0.3 UPPERCASE_25_50 message body is 25-50% uppercase
2.7 FORGED_MUA_OIMO Forged mail pretending to be from MS Outlook IMO
The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.