Nigerian spam from Google Gmail Part 2
Posted by Dave Yadallee onpts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[74.125.224.48 listed in dnsbl.ahbl.org]
[74.125.224.48 listed in dnsbl.ahbl.org]
[74.125.224.48 listed in dnsbl.ahbl.org]
[74.125.224.48 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[74.125.224.48 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[74.125.224.48 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[74.125.224.48 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[74.125.224.48 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[74.125.224.48 listed in will-spam-for-food.eu.org]
[74.125.224.48 listed in will-spam-for-food.eu.org]
[74.125.224.48 listed in will-spam-for-food.eu.org]
[74.125.224.48 listed in will-spam-for-food.eu.org]
[74.125.224.48 listed in will-spam-for-food.eu.org]
[74.125.224.48 listed in will-spam-for-food.eu.org]
[74.125.224.48 listed in will-spam-for-food.eu.org]
[74.125.224.48 listed in will-spam-for-food.eu.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[74.125.224.48 listed in list.dnswl.org]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
-0.0 SPF_PASS SPF: sender matches SPF record
1.0 HK_RANDOM_FROM From username looks random
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.6 HK_RANDOM_ENVFROM Envelope sender username looks random
1.5 GR_DOMAIN_UNDISC1 To contains undisclosed recipient (undisc)
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[74.125.224.48 listed in bl.score.senderscore.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[74.125.224.48 listed in wl.mailspike.net]
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit
[compaorekone3(at)gmail.com]
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit
[abbttnb001(at)gmail.com]
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
[abbttnb001(at)gmail.com]
2.7 UNCLAIMED_MONEY BODY: People just leave money laying around
1.8 MILLION_HUNDRED BODY: Million "One to Nine" Hundred
2.6 HK_SCAM_N13 BODY: No description available.
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
1.5 VOWEL_FROM_6 Impronouncable from header (6 consecutive vowels)
0.0 LOTS_OF_MONEY Huge... sums of money
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different
freemails
2.8 UNDISC_FREEM Undisclosed recipients + freemail reply-to
0.0 MONEY_FREEMAIL_REPTO Lots of money from someone using free email?
0.5 MONEY_FRAUD_8 Lots of money and very many fraud phrases
3.7 ADVANCE_FEE_5_NEW_MONEY Advance Fee fraud and lots of money
2.6 UNDISC_MONEY Undisclosed recipients + money/fraud signs
Subject: {SPAM?} Greetings from Kone
--000000000000d94b850655de9121
Content-Type: text/plain; charset="UTF-8"
Greetings to you and your family.
My name is Mr. Kone Compaore, the auditing general with the bank, Africa
Develop bank (ADB) Ouagadougou, Burkina Faso, in West Africa. I am
contacting you to seek your honesty and sincere cooperation in confidential
manner to transfer the sum of 10.5 (Ten million five hundred thousand
Dollars) to your existing or new bank account.
This money belongs to one of our bank client, a Libyan oil exporter who was
working with the former Libyan government; I learn that he was killed by
the revolutionary forces since October 2012. Our bank is planning to
transfer this entire fund into the government public
treasury as unclaimed fund if nobody comes to claim the money from our bank
after six years without account activities .
What the bank need is proof and information about the late customer which I
will assist you on. This is a genuine, risk free and legal business
transaction, All details shall be sent to you once I hear from you.
The information as contained herein be accorded the necessary attention,
urgency as well as the secrecy it deserves.
If you are really sure of your integrity, trustworthy and confidentiality
reply back to me urgently for more details
Best regards,
Kone Compaore
--000000000000d94b850655de9121
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
data-smartmail=3D"gmail_signature">
Greetings to you and your family.
>
My name is Mr. Kone Compaore, the auditing general with the bank, Afri=
ca Develop bank (ADB) Ouagadougou, Burkina Faso, in West Africa. I am conta=
cting you to seek your honesty and sincere cooperation in confidential mann=
er to transfer the sum of 10.5 (Ten million five hundred thousand Dollars) =
to your existing or new bank account.
This money belongs to one of o=
ur bank client, a Libyan oil exporter who was working with the former Libya=
n government; I learn that he was killed by the revolutionary forces since =
October 2012. Our bank is planning to transfer this entire fund into the go=
vernment public
treasury as unclaimed fund if nobody comes to claim the =
money from our bank after six years without account activities .
Wha=
t the bank need is proof and information about the late customer which I wi=
ll assist you on. This is a genuine, risk free and legal business transacti=
on, All details shall be sent to you once I hear from you.
The infor=
mation as contained herein be accorded the necessary attention, urgency as =
well as the secrecy it deserves.
If you are really sure of your inte=
grity, trustworthy and confidentiality reply back to me urgently for more d=
etails
Best regards,
Kone Compaore
--000000000000d94b850655de9121--