[Antir_scribes] Pharmacy Online Sale 80% OFF!

VIAGRA Inc. antir_scribes at castle.org
Sun Jul 12 21:42:23 PDT 2009


Spam detection software, running on the system "castle.org", has
identified this incoming email as possible spam.  The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email.  If you have any questions, see
The administrator of that system for details.

Content preview:  Welcome to WebMD • Mon, 13 Jul 2009 12:42:23 +0800 New from
   WebMD: Dear antir_scribes at castle.org! Sign-up today! You are subscribed as
   antir_scribes at castle.org. View and manage your WebMD newsletter preferences.
   Subscribe to more newsletters. Change/update your email address. [...] 

Content analysis details:   (31.9 points, 5.0 required)

 pts rule name              description
---- ---------------------- --------------------------------------------------
 2.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
               [Blocked - see <http://www.spamcop.net/bl.shtml?58.244.220.95>]
 0.5 RCVD_IN_PBL            RBL: Received via a relay in Spamhaus PBL
                            [58.244.220.95 listed in zen.spamhaus.org]
 2.9 RCVD_IN_XBL            RBL: Received via a relay in Spamhaus XBL
 2.0 URIBL_BLACK            Contains an URL listed in the URIBL blacklist
                            [URIs: arrivemight.com]
 0.9 URIBL_RHS_DOB          Contains an URI of a new domain (Day Old Bread)
                            [URIs: batfizz.com]
 1.6 URIBL_AB_SURBL         Contains an URL listed in the AB SURBL blocklist
                            [URIs: towneffect.com]
 2.1 URIBL_WS_SURBL         Contains an URL listed in the WS SURBL blocklist
                            [URIs: towneffect.com]
 2.9 URIBL_JP_SURBL         Contains an URL listed in the JP SURBL blocklist
                            [URIs: towneffect.com]
 2.5 URIBL_SC_SURBL         Contains an URL listed in the SC SURBL blocklist
                            [URIs: towneffect.com]
 2.1 URIBL_OB_SURBL         Contains an URL listed in the OB SURBL blocklist
                            [URIs: animalenter.com]
 3.1 DATE_IN_FUTURE_06_12   Date: is 6 to 12 hours after Received: date
 0.2 HTML_IMAGE_RATIO_04    BODY: HTML has a low ratio of text to image area
 0.0 HTML_MESSAGE           BODY: HTML included in message
 1.5 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
                            above 50%
                            [cf: 100]
 0.5 RAZOR2_CHECK           Listed in Razor2 (http://razor.sf.net/)
 0.5 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
                            [cf: 100]
 0.0 FORGED_OUTLOOK_TAGS    Outlook can't send HTML in this format
 0.1 RDNS_NONE              Delivered to trusted network by a host with no rDNS
 2.2 FAKE_REPLY_C           FAKE_REPLY_C
 4.2 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook

The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam.  If you wish to view
it, it may be safer to save it to a file and open it with an editor.



More information about the Antir_scribes mailing list