# # 2008-2010 Victor Ustugov # ######################################## header FROM_administrator_freemail_hu From =~ /(admlnistrator|adminlstrator|p0stmasters?)\@freemail\.hu/ describe FROM_administrator_freemail_hu From administrator@freemail.hu (DSPAM autolearn) score FROM_administrator_freemail_hu 4.0 header ENV_FROM_administrator_freemail_hu X-Envelope-From =~ /^\s*<(admlnistrator|adminlstrator|p0stmasters?)\@freemail\.hu>$/ describe ENV_FROM_administrator_freemail_hu From administrator@freemail.hu (DSPAM autolearn) score ENV_FROM_administrator_freemail_hu 4.0 header RETURN_PATH_administrator_freemail_hu Return-Path =~ /^\s*<(admlnistrator|adminlstrator|p0stmasters?)\@freemail\.hu>$/ describe RETURN_PATH_administrator_freemail_hu From administrator@freemail.hu (DSPAM autolearn) score RETURN_PATH_administrator_freemail_hu 4.0 ######################################## header Infomedia_Mailer X-Mailer =~ /^\s*Infomedia Mailer \d+\.\d+$/ describe Infomedia_Mailer Message from Infomedia (DSPAM autolearn) score Infomedia_Mailer 3.0 tflags Infomedia_Mailer mandatory_learn header Infomedia_Organization Organization =~ /^\s*(Infomedia( LLC)?|ООО Инфомедиа|ТОВ .НФОМЕД.А|ТОВ Інфомедіа)$/ describe Infomedia_Organization Message from Infomedia (DSPAM autolearn) score Infomedia_Organization 3.0 tflags Infomedia_Organization mandatory_learn header Infomedia_From From =~ /(notify\@center1\.com\.ua|noreply\@ethnostyling\.com|promotion\@regularnewsletter\.com|promo(tion)?\@infoletter\.com\.ua)/ describe Infomedia_From Message from Infomedia (DSPAM autolearn) score Infomedia_From 4.0 tflags Infomedia_From mandatory_learn header Infomedia_Reply_To Reply-To =~ /^\s*(seminar|promotion)\@(infomedia\.com\.ua|ethno\.ua)$/ describe Infomedia_Reply_To Message from Infomedia (DSPAM autolearn) score Infomedia_Reply_To 3.0 tflags Infomedia_Reply_To mandatory_learn header Infomedia_Message_Id Message-Id =~ /^\s*<(19[789]\d|20\d\d)(0\d|1[012])([012]\d|3[01])([0-5]\d)([0-5]\d)([0-5]\d)\.[A-F\d]{11,12}\@(srv\d|apollo)\.ethnohosting\.com>$/ describe Infomedia_Message_Id Message from Infomedia (DSPAM autolearn) score Infomedia_Message_Id 3.0 tflags Infomedia_Message_Id mandatory_learn header Infomedia_List_Unsubscribe List-Unsubscribe =~ /^\s*, $/ describe Infomedia_List_Unsubscribe Message from Infomedia (DSPAM autolearn) score Infomedia_List_Unsubscribe 3.0 tflags Infomedia_List_Unsubscribe mandatory_learn header RECEIVED_ethnohosting_com Received =~ /(juno|srv5)\.ethnohosting\.com/ describe RECEIVED_ethnohosting_com Received via ethnohosting.com score RECEIVED_ethnohosting_com 3.0 tflags RECEIVED_ethnohosting_com mandatory_learn ######################################## header SUSPICIOUS_RECEIVED_HELO_Delldim5150 Received =~ /from ([\w\d\-]+\.)+[a-z]{2,3} \(HELO Delldim5150\)[\s\r\n]+\(\[\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\]\) by ([\w\d\-]+\.)+[a-z]{2,3} with ESMTP;/ describe SUSPICIOUS_RECEIVED_HELO_Delldim5150 Suspicious header Received with HELO Delldim5150 (DSPAM autolearn) score SUSPICIOUS_RECEIVED_HELO_Delldim5150 6.0 meta SUSPICIOUS_RECEIVED_HELO_Delldim5150_DSPAM SUSPICIOUS_RECEIVED_HELO_Delldim5150 && DSPAM_CHECK_00_01 describe SUSPICIOUS_RECEIVED_HELO_Delldim5150_DSPAM DSPAM compensation for suspicious header Received with HELO Delldim5150 score SUSPICIOUS_RECEIVED_HELO_Delldim5150_DSPAM 3.5 header SUSPICIOUS_MSGID_Delldim5150 Message-ID =~ /^\s*<\S+\@Delldim5150$/ describe SUSPICIOUS_MSGID_Delldim5150 Suspicious header Message-ID with Delldim5150 (DSPAM autolearn) score SUSPICIOUS_MSGID_Delldim5150 6.0 meta SUSPICIOUS_MSGID_Delldim5150_DSPAM SUSPICIOUS_MSGID_Delldim5150 && DSPAM_CHECK_00_01 describe SUSPICIOUS_MSGID_Delldim5150_DSPAM DSPAM compensation for Suspicious header Message-ID with Delldim5150 score SUSPICIOUS_MSGID_Delldim5150_DSPAM 3.5 ######################################## header SUSPICIOUS_Message_ID_boria Message-ID =~ /^\s*<[A-F\d]{32}\@boria-c6525c0ff>$/ describe SUSPICIOUS_Message_ID_boria Suspicious Message-ID boria-c6525c0ff (DSPAM autolearn), already read score SUSPICIOUS_Message_ID_boria 5.0 tflags SUSPICIOUS_Message_ID_boria mandatory_learn header SUSPICIOUS_Message_ID_vlad Message-ID =~ /^\s*<[A-F\d]{32}\@vlad-2c92667ea5>$/ describe SUSPICIOUS_Message_ID_vlad Suspicious Message-ID vlad-2c92667ea5 (DSPAM autolearn), already read score SUSPICIOUS_Message_ID_vlad 5.0 tflags SUSPICIOUS_Message_ID_vlad mandatory_learn header SUSPICIOUS_Message_ID_hamid Message-ID =~ /^\s*<[A-F\d]{32}\@hamid-a8613958b>$/ describe SUSPICIOUS_Message_ID_hamid Suspicious Message-ID hamid-a8613958b (DSPAM autolearn), already read score SUSPICIOUS_Message_ID_hamid 5.0 tflags SUSPICIOUS_Message_ID_hamid mandatory_learn header SUSPICIOUS_Message_ID_your Message-ID =~ /^\s*<[A-F\d]{32}\@your-012b27d9cc>$/ describe SUSPICIOUS_Message_ID_your Suspicious Message-ID your-012b27d9cc (DSPAM autolearn), already read score SUSPICIOUS_Message_ID_your 5.0 tflags SUSPICIOUS_Message_ID_your mandatory_learn header SUSPICIOUS_Message_ID_acer Message-ID =~ /^\s*<[A-F\d]{32}\@acer-614e8ddbaf>$/ describe SUSPICIOUS_Message_ID_acer Suspicious Message-ID acer-614e8ddbaf (DSPAM autolearn), already read score SUSPICIOUS_Message_ID_acer 5.0 tflags SUSPICIOUS_Message_ID_acer mandatory_learn header SUSPICIOUS_Message_ID_vlados Message-ID =~ /^\s*<[A-F\d]{32}\@vlados-70d3a2e0>$/ describe SUSPICIOUS_Message_ID_vlados Suspicious Message-ID vlados-70d3a2e0 (DSPAM autolearn), already read score SUSPICIOUS_Message_ID_vlados 5.0 tflags SUSPICIOUS_Message_ID_vlados mandatory_learn # aaaa-b7e7feda0d # cct-0f6054a23a8 # comp-e0913b897f # e-ba9e952ca3b04 # factory-a538f88 # fc-b73fa790688a # fg-fb17a0c2bc47 # home-4c68bcf688 # home-sgf0cty15m # ITQUANGN-D334F3 # jenouled-397aed # lehman-a62733aa # mainz-zxovkpzrc # microsof-2a759e # microsof-54770d # microsof-9d8959 # microsof-a9a893 # microsof-ab7818 # MICROSOF-DBD9B3 # pcuser-8d9c70eb # personal-8784e8 # q-7432c7d38a134 # suarez-559e80e2 # user-39025ed6f0 # wipronot-c965e9 # xpsp2-488223409 # pc-1pdv8tv1cpuw # UKFAST-0JTLWF8J header SUSPICIOUS_Message_ID_microsof Message-ID =~ /^\s*<[A-F\d]{32}\@microsof-[\da-f]{6,10}>$/ describe SUSPICIOUS_Message_ID_microsof Suspicious Message-ID microsof (DSPAM autolearn) score SUSPICIOUS_Message_ID_microsof 4.0 tflags SUSPICIOUS_Message_ID_microsof mandatory_learn header SUSPICIOUS_Message_ID_microsof_9413b5 Message-ID =~ /^\s*<[A-F\d]{32}\@microsof-9413b5>$/ describe SUSPICIOUS_Message_ID_microsof_9413b5 Suspicious Message-ID microsof-9413b5 (DSPAM autolearn) score SUSPICIOUS_Message_ID_microsof_9413b5 1.0 tflags SUSPICIOUS_Message_ID_microsof_9413b5 mandatory_learn header SUSPICIOUS_Message_ID_microsof_d29149 Message-ID =~ /^\s*<[A-F\d]{32}\@microsof-d29149>$/ describe SUSPICIOUS_Message_ID_microsof_d29149 Suspicious Message-ID microsof-d29149 (DSPAM autolearn) score SUSPICIOUS_Message_ID_microsof_d29149 1.0 tflags SUSPICIOUS_Message_ID_microsof_d29149 mandatory_learn header SUSPICIOUS_Message_ID_microsof_42dbe3 Message-ID =~ /^\s*<[A-F\d]{32}\@microsof-42dbe3>$/ describe SUSPICIOUS_Message_ID_microsof_42dbe3 Suspicious Message-ID microsof-42dbe3 (DSPAM autolearn) score SUSPICIOUS_Message_ID_microsof_42dbe3 1.0 tflags SUSPICIOUS_Message_ID_microsof_42dbe3 mandatory_learn header SUSPICIOUS_Message_ID_ESX40 Message-ID =~ /^\s*<[A-F\d]{32}\@ESX40-1827>$/ describe SUSPICIOUS_Message_ID_ESX40 Suspicious Message-ID ESX40-1827 (DSPAM autolearn), already read score SUSPICIOUS_Message_ID_ESX40 5.0 tflags SUSPICIOUS_Message_ID_ESX40 mandatory_learn ######################################## # http://www.cooleremail.com/ - CoolerEmail 2.0 - E-mail Marketing Services header CT_SUSP_BOUNDARY_CoolerEmail Content-Type =~ /boundary="============_?CoolerEmail_?============"/ describe CT_SUSP_BOUNDARY_CoolerEmail Suspicious non-unique boundary (DSPAM autolearn) score CT_SUSP_BOUNDARY_CoolerEmail 2.5 tflags CT_SUSP_BOUNDARY_CoolerEmail mandatory_learn # http://www.flexmail.be - E-mail Marketing Services header FLEXMAIL_MSGID Message-ID =~ /\@flexmail\.be>/ describe FLEXMAIL_MSGID flexmail.be Message-ID score FLEXMAIL_MSGID 1.2 header FLEXMAIL_SENDER Return-path =~ /^\s*$/ describe FLEXMAIL_SENDER flexmail.be Return-Path score FLEXMAIL_SENDER 1.2 header FLEXMAIL_X_ENVELOPE_FROM X-Envelope-From =~ /^\s*$/ describe FLEXMAIL_X_ENVELOPE_FROM flexmail.be X-Envelope-From score FLEXMAIL_X_ENVELOPE_FROM 1.2 header FLEXMAIL_X_MAILER X-Mailer =~ /^\s*Flexmail/ describe FLEXMAIL_X_MAILER flexmail.be X-Mailer score FLEXMAIL_X_MAILER 1.2 header FLEXMAIL_X_Flexmail_ID X-Flexmail-ID =~ /./ describe FLEXMAIL_X_Flexmail_ID flexmail.be X-Flexmail-ID score FLEXMAIL_X_Flexmail_ID 1.2 header FROM_PROMOTION_MYPERSONAL From =~ /$/ describe FROM_PROMOTION_MYPERSONAL promotion@mypersonal.com.ua (DSPAM autolearn) score FROM_PROMOTION_MYPERSONAL 5.0 tflags FROM_PROMOTION_MYPERSONAL mandatory_learn header FROM_OFFICE_MYPERSONAL From =~ /$/ describe FROM_OFFICE_MYPERSONAL office@mypersonal.com.ua (DSPAM autolearn) score FROM_OFFICE_MYPERSONAL 5.0 tflags FROM_OFFICE_MYPERSONAL mandatory_learn # X-Mailer: TOL Mailer header CT_SUSP_BOUNDARY_TOL_Mailer Content-Type =~ /boundary=_0_\.__\.__TOL__Mailer__Part_Boundary_$/ describe CT_SUSP_BOUNDARY_TOL_Mailer Suspicious non-unique boundary (DSPAM autolearn) score CT_SUSP_BOUNDARY_TOL_Mailer 3.0 ######################################## header __RealName_BListed_From_Subj Subject =~ /^\s*((Re(\[\d+\])|Fw|Fwd):)?\s*(Building|Ceминаp|Conference services|Cтатьи для менеджepa|goodyear|Ground-2005|Hа пoльзу бизнecу|Kapпаты. Oтдыx|KoнсЦентр|Kонcaлтингoвый Цeнтр|Kонсaлтингoвый Цeнтр|Kак удеpжaть публику|LOGISTIKA|OBRIY CONSULTING COMPANY|Ofshore|Oтчeтнocть|Oтчeтнoсть|Oтчетнoсть|Oтчетноcть|Petr Petrovich|Pазвитиe бизнeса|tyre|Tyre|UkrBusinessConsulting-2000|Vega Consulting|Vengriya|БЦ Национальный|БЦ.*"?Национальный"?|бТВБМЙУФ|Буx-конcалтинг|Буx-консалтинг|Буxгaлтеp|Буxгалтep|Буxгалтер|Бух-кoнcaлтинг|Бух-кoнсалтинг|Бух-конcалтинг|Бухгaлтep|Бухгaлтеp|Бухгалтеp|Бухгалтер|БУХГАЛТЕРИИ|Библиотeкa упpавлeния перcoнaлoм на CД|Библиотекa упрaвлeния пepсoналoм на СД|Бизнeс-Центp|Бизнеc|Бизнес-Центр.*"?Национальный"?|Бизнесмeну|бюджет|Бюджетирование|бюджетирование|бюро дойче мессен|ВЭД|Все на отдых|Земля|земля под строительство|Задолжность|Застpойка|Дойче мессен|Дистрибуция|Цeнтp Paзвития Пpедпpинимaтeльcтва|Цeнтp Paзвития Пpедпpинимaтeльства|Цeнтp Paзвития Пpедпринимaтельствa|Цeнтр Pазвития Прeдпринимaтeльcтвa|Цeнтр Развития Пpедпpиниматeльcтва|Центp Pазвития Пpeдпринимательcтва|Центp Pазвития Пpедпpинимательcтва|Центр Pазвития Пpeдприниматeльствa|Центр повышeния квaлификации|Центр Рaзвития Пpедпpинимaтельcтвa|Центр Рaзвития Пpедпринимaтельствa|Центр Развития Прeдпpинимательствa|Кaникулы в Beнгpии|Кaрпaты. Отдых|Кoнcалтинговый Центр|Кoнсaлтингoвый Цeнтр|Кoнсaлтингoвый Центp|Кoнсaлтинговый Цeнтp|Кoнсалтингoвый Цeнтp|Коммерческая недвижимость|Конcaлтинговый Центp|Конференц-зал|Консaлтинговый Цeнтр|Консалтингoвый Центр|кредитной политикой|(Киев )?ДОЙЧЕ МЕССЕН|Киевское представительство|ЛЧБТФЙТЩ РЕТЕЕЪДЩ|Мeнеджмeнт|Менeджмент|Менеджмент|мПЗЙУФ|Нa пoльзу бизнесу|Нeдвижимоcть|недвижимость|Новый Гoд и Рождecтвo на Гуцульщине|Новый Год|Ноутбуки|Начальнику|Оpaтoрcкое иcкусcтво|Объединенный адвокатский офис|о защите прав потребителей|ООО|Отчетнoсть|Отчетность|Отдыx в Карпaтax|отдых|Отдых в Beнгpии|Пoexaли c нaми|Пoдъeм экономики|Пoдъем|Пoдъем экономики|Пoднимем эконoмику|Пoднимем экономику|Планування податкiв|Подъeм|Подъeм экoнoмики|Подъeм экoномики|Полиграфия|полиграфия|построение бр.нда|Прoдaжa|Презентации|Продaжа|Примiщення у Львовi|Приглашение|Практикум|Путeшecтвиe|Путешecтвиe в Beнгрию|Рaзвитие|Рaзвитие бизнесa|Реклама|Развитие бизнесa|Тeхникa речи|Тeхника речи|тБУРТПДБЦБ|Техника речи|торгово-развлекательный комплекс|Торговые Марки|Тренинг|Транспортная логистика|Туp-oпеpaтор|Туp-оператop|Турпутeвки|Таможня|УкрБизнесКонсалтинг|УкрБизнесКонсалтинг-2000|Украинские семинары|Умнoжим знaния|Умножим знaния|Умножим знания|управление персоналом|фТБОУРПТФ|хУМЕДХАЭЙНЙ|Инкотермс 2000|Инфopмациoнный pecурc|((информационное )?бюро )?дойче мессен|информационное бюро дойче мессен|Информационный реcурс|Юридическая Группа|Юрискунсульт|Юрист|эффективные переговоры|эффективная организация|ьЛУРПТФОП-ЙНРПТФОЩЕ ПРЕТБГЙЙ|Аpхив эффективного менеджмeнтa|Адвокатский офис|Актерское мастерство|Агенство рассылок|Свышe 400 стaтeй по HR-мeнеджменту|Свыше 400 стaтей по HR-мeнeджменту|Сдaть уcтный экзaмен|Сдать устный экзамeн|Семинар|семинар|Семинар в Праге|Семинар-тренинг|СОНАТА|Стaтьи для мeнeджeра)[\s\r\n]*$/ describe MAIDAN_ORG_UA_FROM From (DSPAM autolearn) score MAIDAN_ORG_UA_FROM 4.0 tflags MAIDAN_ORG_UA_FROM mandatory_learn header ADMIN_XPORTAL_COM_UA_FROM From =~ /^\s*admin\@xportal\.com\.ua$/ describe ADMIN_XPORTAL_COM_UA_FROM From admin@xportal.com.ua (DSPAM autolearn) score ADMIN_XPORTAL_COM_UA_FROM 4.0 tflags ADMIN_XPORTAL_COM_UA_FROM mandatory_learn header FROM_Seminar_vega_st_com From:raw =~ /^\s*seminar\@vega-st\.com$/ describe FROM_Seminar_vega_st_com Message from seminar@vega-st.com score FROM_Seminar_vega_st_com 2.5 header FROM_mail_fish_net_ua From =~ /mail\@fish\.net\.ua/ describe FROM_mail_fish_net_ua e-mail from mail@fish.net.ua (DSPAM autolearn) score FROM_mail_fish_net_ua 3.5 tflags FROM_mail_fish_net_ua mandatory_learn header FROM_YAHOO_BESSIE From =~ /bessie\..+\@yahoo\./ describe FROM_YAHOO_BESSIE Header From contains bessie in mailbox and yahoo in domain score FROM_YAHOO_BESSIE 2.0 header FROM_SV_Development From =~ /^\s*SV Development $/ describe FROM_SV_Development From SV Development (DSPAM autolearn) score FROM_SV_Development 3.0 tflags FROM_SV_Development mandatory_learn header REPLY_TO_KAM_POD_UNIVER Reply-To =~ // describe REPLY_TO_KAM_POD_UNIVER Message from Kamenets-Podolsky National University (DSPAM autolearn), already read score REPLY_TO_KAM_POD_UNIVER 4.0 tflags REPLY_TO_KAM_POD_UNIVER mandatory_learn header FROM_computerra_net_ua From =~ // describe FROM_computerra_net_ua From spam service mail@computerra.net.ua (DSPAM autolearn) score FROM_computerra_net_ua 5.0 tflags FROM_computerra_net_ua mandatory_learn header FROM_MESSAGE_FRO_YOU_LTD From =~ /^\s*"ппп чБН рЙУШНП" $/ describe FROM_DISPATCH From WebInside/Dispatch (DSPAM autolearn), already read score FROM_DISPATCH 5.0 tflags FROM_DISPATCH mandatory_learn header FROM_SMSCENTRE From =~ /^\s*<(sales|info)\@smscentre\.com\.ua>$/ describe FROM_SMSCENTRE Message from sales@smscentre.com.ua (DSPAM autolearn) score FROM_SMSCENTRE 4.0 tflags FROM_SMSCENTRE mandatory_learn header FROM_MIXPRINT From =~ /^\s*$/ describe FROM_MIXPRINT Message from mixpintu@mail.ru (DSPAM autolearn) score FROM_MIXPRINT 2.0 tflags FROM_MIXPRINT mandatory_learn header FROM_REGULARNEWSLETTER From =~ /\@regularnewsletter\.com>$/ describe FROM_REGULARNEWSLETTER Message from regularnewsletter.com (DSPAM autolearn) score FROM_REGULARNEWSLETTER 4.0 tflags FROM_REGULARNEWSLETTER mandatory_learn header FROM_OEVEL From =~ /\@oevel\.com>$/ describe FROM_OEVEL Message from oevel.com (DSPAM autolearn) score FROM_OEVEL 4.0 tflags FROM_OEVEL mandatory_learn header FROM_SITEDESIGNER From =~ /info\@sitedesigner\.com\.ua>$/ describe FROM_SITEDESIGNER Message from info@sitedesigner.com.ua (DSPAM autolearn) score FROM_SITEDESIGNER 2.0 tflags FROM_SITEDESIGNER mandatory_learn header FROM_SPECTOVAR From =~ // describe HEADER_TO_YET_ANOTHER_ROW Very stratnge spammer's mistake score HEADER_TO_YET_ANOTHER_ROW 3.0 header HEADER_TO_USER To =~ /^\s*User$/ describe HEADER_TO_USER Suspicious heaer To (DSPAM autolearn) score HEADER_TO_USER 4.0 tflags HEADER_TO_USER mandatory_learn header FROM_Freshfile_Net From =~ /^\s*Freshfile\.Net $/ describe FROM_Freshfile_Net Message from Freshfile.Net score FROM_Freshfile_Net 2.0 header HEADER_CT_MIME_VER Content-Type:raw =~ /^\s*text\/html; charset=iso-8859-1 MIME-Version: 1\.0 $/ describe HEADER_CT_MIME_VER Stupid mistake in header Content-Type (DSPAM autolearn) score HEADER_CT_MIME_VER 5.0 tflags HEADER_CT_MIME_VER mandatory_learn header MYPERSONAL_FROM_MAILRU X-Collect-Stat =~ /^\s*87686$/ describe MYPERSONAL_FROM_MAILRU Message from promotion@mypersonal.com.ua thru mailer@sender5.mail.ru score MYPERSONAL_FROM_MAILRU 2.2