Spam detection software, running on the system "kualalumpur.lrde.epita.fr", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or block
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Save URI:http://newsoftupdates.info/index.php?s`33 HUGE
amounts by buying URI:http://newsoftupdates.info/index.php?s`33 "OEM"
software! If you see a title you need below, you can save
URI:http://newsoftupdates.info/index.php?s`33 40%-80% on it
URI:http://newsoftupdates.info/index.php?s`33 HERE! [...]
Content analysis details: (39.3 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.5 X_PRIORITY_HIGH Sent with 'X-Priority' set to high
0.3 FROM_HAS_MIXED_NUMS From: contains numbers mixed in with letters
4.3 RCVD_AM_PM Received headers forged (AM/PM)
1.1 FROM_NUM_AT_WEBMAIL From address is webmail, but starts with a number
4.3 RATWARE_EGROUPS Bulk email fingerprint (eGroups) found
1.2 BANG_MORE BODY: Talks about more with an exclamation!
3.5 TRACKER_ID BODY: Incorporates a tracking ID number
0.5 HTML_40_50 BODY: Message is 40% to 50% HTML
0.1 HTML_LINK_CLICK_HERE BODY: HTML link text says "click here"
0.3 HTML_TAG_BALANCE_BODY BODY: HTML has unbalanced "body" tags
0.0 HTML_MESSAGE BODY: HTML included in message
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
4.3 FORGED_AOL_RCVD Received forged, contains fake AOL relays
3.0 FORGED_RCVD_NET_HELO Host HELO'd using the wrong IP network
0.5 FORGED_YAHOO_RCVD 'From'
yahoo.com does not match 'Received'
headers
1.1 RCVD_IN_SORBS_SOCKS RBL: SORBS: sender is open SOCKS proxy server
[212.17.72.204 listed in
dnsbl.sorbs.net]
1.1 RCVD_IN_SORBS_HTTP RBL: SORBS: sender is open HTTP proxy server
[212.17.72.204 listed in
dnsbl.sorbs.net]
1.1 RCVD_IN_DSBL RBL: Received via a relay in
list.dsbl.org
[<http://dsbl.org/listing?ip=212.17.72.204>]
2.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in
bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?212.17.72.204>]
0.1 RCVD_IN_SORBS RBL: SORBS: sender is listed in SORBS
[212.17.72.204 listed in
dnsbl.sorbs.net]
0.1 RCVD_IN_RFCI RBL: Sent via a relay in
ipwhois.rfc-ignorant.org
[147.119.50.98 has inaccurate or missing WHOIS]
[data at the RIR]
1.7 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag
0.0 CLICK_BELOW Asks you to click below
2.8 MULTI_FORGED Received headers indicate multiple forgeries
4.3 CONFIRMED_FORGED Received headers are forged
0.8 MSGID_FROM_MTA_HEADER Message-Id was added by a relay
The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.