Business proposal spam from Google Gmail Part 2
Posted by Dave Yadallee onpts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[34.231.63.135 listed in will-spam-for-food.eu.org]
[34.231.63.135 listed in will-spam-for-food.eu.org]
[34.231.63.135 listed in will-spam-for-food.eu.org]
[34.231.63.135 listed in will-spam-for-food.eu.org]
[34.231.63.135 listed in will-spam-for-food.eu.org]
[34.231.63.135 listed in will-spam-for-food.eu.org]
[34.231.63.135 listed in will-spam-for-food.eu.org]
[34.231.63.135 listed in will-spam-for-food.eu.org]
[209.85.214.232 listed in will-spam-for-food.eu.org]
[209.85.214.232 listed in will-spam-for-food.eu.org]
[209.85.214.232 listed in will-spam-for-food.eu.org]
[209.85.214.232 listed in will-spam-for-food.eu.org]
[209.85.214.232 listed in will-spam-for-food.eu.org]
[209.85.214.232 listed in will-spam-for-food.eu.org]
[209.85.214.232 listed in will-spam-for-food.eu.org]
[209.85.214.232 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[34.231.63.135 listed in dnsbl.ahbl.org]
[34.231.63.135 listed in dnsbl.ahbl.org]
[34.231.63.135 listed in dnsbl.ahbl.org]
[34.231.63.135 listed in dnsbl.ahbl.org]
[209.85.214.232 listed in dnsbl.ahbl.org]
[209.85.214.232 listed in dnsbl.ahbl.org]
[209.85.214.232 listed in dnsbl.ahbl.org]
[209.85.214.232 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[34.231.63.135 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[34.231.63.135 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[34.231.63.135 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[34.231.63.135 listed in dnsbl.ahbl.org]
1.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[209.85.214.232 listed in sa-accredit.habeas.com]
0.0 T_SPF_TEMPERROR SPF: test of record failed (temperror)
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
1.5 GR_DOMAIN_UNDISC1 To contains undisclosed recipient (undisc)
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit
[franktsockton654(at)outlook.com]
1.6 SUBJ_ALL_CAPS Subject is all capitals
1.1 DATE_IN_PAST_03_06 Date: is 3 to 6 hours before Received: date
0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The
query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[209.85.214.232 listed in sa-trusted.bondedsender.org]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.214.232 listed in wl.mailspike.net]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.214.232 listed in list.dnswl.org]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[209.85.214.232 listed in bl.score.senderscore.com]
0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[209.85.214.232 listed in bl.score.senderscore.com]
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
2.0 US_8BIT US-ASCII isn't an eight bit charset
0.0 LOTS_OF_MONEY Huge... sums of money
2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
0.9 MONEY_FREEMAIL_REPTO Lots of money from someone using free email?
2.9 UNDISC_MONEY Undisclosed recipients + money/fraud signs
Subject: {SPAM?} BUSINESS PROPOSAL !!!
This is a multi-part message in MIME format.
--14da1bab14540aaf3b0fafbcf078de42d
Content-Type: text/plain; charset=us-ascii
I have a Business proposal worth $35M USD, please contact me for more information.
Sincerely,
Frank Stockton
--14da1bab14540aaf3b0fafbcf078de42d
Content-Type: text/html; charset=us-ascii
I have a Business proposal worth $35M USD, please contact me for more information.
Sincerely,
Frank Stockton
--14da1bab14540aaf3b0fafbcf078de42d--