You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@spamassassin.apache.org by Robert Schetterer <ro...@schetterer.org> on 2007/06/21 00:58:37 UTC
stock spam with pdf
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi @ll,
here is some more info
http://www.forbes.com/security/2007/06/20/stock-spam-internet-tech-security-cx_ag_0620spam.html
- --
Mit freundlichen Gruessen
Best Regards
Robert Schetterer
https://www.schetterer.org
Germany
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org
iD8DBQFGebEdfGH2AvR16oERAkiXAJ9dBW4rdaAcDlfRxwYaCceu8PLSqQCfeQE5
hUg2B54kHTvuisfQ9X+r7ho=
=JQZb
-----END PGP SIGNATURE-----
Re: stock spam with pdf
Posted by arni <ma...@arni.name>.
Robert Schetterer schrieb:
> http://www.forbes.com/security/2007/06/20/stock-spam-internet-tech-security-cx_ag_0620spam.html
>
Got like 7 of them, all look pretty much like this:
X-Spam-Report:
* 5.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100%
* [score: 0.9998]
* 0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS
* 5.0 BOTNET Relay might be a spambot or virusbot
* [botnet0.7,ip=89.234.73.196,nordns]
* 0.0 DKIM_POLICY_SIGNSOME Domain Keys Identified Mail: policy says domain
* signs some mails
* 0.0 BOTNET_NORDNS Relay's IP address has no PTR record
* [botnet_nordns,ip=89.234.73.196]
* 0.0 HTML_MESSAGE BODY: HTML included in message