From etca-all at discoveret.org Mon Dec 26 06:31:24 2011 From: etca-all at discoveret.org (etca-all@discoveret.org) Date: Mon Dec 26 06:31:27 2011 Subject: [Etca-all] [SPAM] etca-all@korrnet.org Rolex Today -04% Message-ID: <154c01ccc3b1$2005cae0$c17c57c9@servico> An HTML attachment was scrubbed... URL: http://www.discoveret.org/pipermail/etca-all/attachments/20111226/aa73fbb9/attachment.html -------------- next part -------------- Spam detection software, running on the system "discoveret.org", has identified this incoming email as possible spam. The original message has been attached to this so you can view it (if it isn't spam) or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Click here! [...] Content analysis details: (23.9 points, 10.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 4.4 HELO_DYNAMIC_IPADDR2 Relay HELO'd using suspicious hostname (IP addr 2) 4.2 HELO_DYNAMIC_SPLIT_IP Relay HELO'd using suspicious hostname (Split IP) 0.5 TVD_RCVD_IP TVD_RCVD_IP 0.0 MISSING_DATE Missing Date: header 2.6 RCVD_NUMERIC_HELO Received: contains an IP address used for HELO 0.0 HS_INDEX_PARAM URI: Link contains a common tracker pattern. 0.0 HTML_MESSAGE BODY: HTML included in message 2.6 HTML_IMAGE_ONLY_08 BODY: HTML: images with 400-800 bytes of words 2.3 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 2.5 HTML_SHORT_LINK_IMG_1 HTML is very short with a linked image 2.9 RATWARE_OUTLOOK_NONAME Bulk email fingerprint (Outlook no name) found 2.0 RATWARE_MS_HASH Bulk email fingerprint (msgid ms hash) found