70_sare_header2.cf 107 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633
  1. # SARE Header Abuse Ruleset for SpamAssassin -- file 2
  2. # Version: 01.03.21
  3. # Created: 2004-04-25
  4. # Modified: 2006-05-21
  5. # Usage instructions and documentation in 70_sare_header0.cf
  6. # Full Revision History / Change Log in 70_sare_header.log
  7. #@@# 01.03.20 May 20 2005
  8. #@@# Minor score updates based on additional mass-check
  9. #@@# Modified "rule has been moved" meta flags
  10. #@@# Moved file 0 to file 2 SARE_BOUNDARY_02
  11. #@@# Moved file 0 to file 2 SARE_BOUNDARY_ANYDIG
  12. #@@# Moved file 0 to file 2 SARE_BOUNDARY_D11
  13. #@@# Moved file 0 to file 2 SARE_FROM_SPAM_NAME2
  14. #@@# Moved file 0 to file 2 SARE_FROM_WSJ
  15. #@@# Moved file 0 to file 2 SARE_HEAD_BDY_BOUNCES %%% OR ARCHIVE
  16. #@@# Moved file 0 to file 2 SARE_HEAD_HDR_CONVER
  17. #@@# Moved file 0 to file 2 SARE_HEAD_HDR_NLETRID
  18. #@@# Moved file 0 to file 2 SARE_HEAD_HDR_PID
  19. #@@# Moved file 0 to file 2 SARE_HEAD_HDR_XBNCETR
  20. #@@# Moved file 0 to file 2 SARE_HEAD_HDR_XGMAILA
  21. #@@# Moved file 0 to file 2 SARE_HEAD_HDR_XIDSRVR
  22. #@@# Moved file 0 to file 2 SARE_HEAD_THRD_ALNUM
  23. #@@# Moved file 0 to file 2 SARE_HEAD_XM4
  24. #@@# Moved file 0 to file 2 SARE_HEAD_XMF_AUTHSNDR
  25. #@@# Moved file 0 to file 2 SARE_HELO_MAILUSER
  26. #@@# Moved file 0 to file 2 SARE_MSGID_HEX30
  27. #@@# Moved file 0 to file 2 SARE_MULT_SEXCLUB
  28. #@@# Moved file 0 to file 2 SARE_MULT_SUBJ
  29. #@@# Moved file 0 to file 2 SARE_RECV_IP_004078
  30. #@@# Moved file 0 to file 2 SARE_RECV_IP_038112147
  31. #@@# Moved file 0 to file 2 SARE_RECV_IP_064192082
  32. #@@# Moved file 0 to file 2 SARE_RECV_IP_066063
  33. #@@# Moved file 0 to file 2 SARE_RECV_IP_066114a
  34. #@@# Moved file 0 to file 2 SARE_RECV_IP_066159017
  35. #@@# Moved file 0 to file 2 SARE_RECV_IP_069060122
  36. #@@# Moved file 0 to file 2 SARE_RECV_IP_070096177
  37. #@@# Moved file 0 to file 2 SARE_RECV_IP_207182
  38. #@@# Moved file 0 to file 2 SARE_RECV_IP_208048182
  39. #@@# Moved file 0 to file 2 SARE_RECV_IP_216055133
  40. #@@# Moved file 0 to file 2 SARE_RECV_LOCALHOST
  41. #@@# Moved file 0 to file 2 SARE_RECV_SUSP_2
  42. #@@# Moved file 0 to file 2 SARE_RECV_TRADVALUES
  43. #@@# Moved file 0 to file 2 SARE_RECV_VIPLIST
  44. #@@# Moved file 0 to file 2 SARE_RECV_XACTRIX
  45. #@@# Moved file 0 to file 2 SARE_REPLY_XACTRIX
  46. #@@# Moved file 0 to file 2 SARE_XMAIL_DIRUNIV
  47. #@@# Moved file 0 to file 2 SARE_XMAIL_INTERMED
  48. #@@# Moved file 0 to file 2 SARE_XMAIL_LEO
  49. #@@# Moved file 0 to file 2 SARE_XMAIL_PHPBulkEmai
  50. #@@# Moved file 0 to file 3 SARE_RECV_ADDR5
  51. #@@# Moved file 1 to file 2 SARE_HEAD_DATE_RNDDATE
  52. #@@# Moved file 1 to file 2 SARE_HEAD_HDR_MSGTYPE
  53. #@@# Moved file 1 to file 2 SARE_HEAD_HDR_X400RCV
  54. #@@# Moved file 1 to file 2 SARE_HEAD_HDR_XCNDINF
  55. #@@# Moved file 1 to file 2 SARE_HEAD_HDR_XRIPE
  56. #@@# Moved file 1 to file 2 SARE_HEAD_HDR_XSAFMMI
  57. #@@# Moved file 1 to file 2 SARE_RECV_IP_062023
  58. #@@# Moved file 1 to file 2 SARE_RECV_IP_065205157
  59. #@@# Moved file 1 to file 2 SARE_RECV_IP_066248154
  60. #@@# Moved file 1 to file 2 SARE_RECV_IP_206248152
  61. #@@# Moved file 1 to file 2 SARE_RECV_RND_DATE
  62. #@@# Moved file 1 to file 2 SARE_XMAIL_GDI
  63. #@@# Moved file 2 to file 0 SARE_HEAD_HDR_CONVWLS
  64. #@@# Moved file 2 to file 0 SARE_HEAD_SUBJ_RAND
  65. #@@# Moved file 2 to file 0 SARE_HEAD_XORIP_IP
  66. #@@# Moved file 2 to file 3 SARE_MULT_RATW_03
  67. #@@# Returned file 2 to file 0 SARE_HEAD_HDR_EPATH
  68. #@@# Returned file 2 to file 0 SARE_RECV_IP_063111025
  69. #@@# Returned file 2 to file 1 SARE_RECV_IP_142046
  70. #@@# 01.03.21 May 21 2005
  71. #@@# Minor repairs to "downgraded rule" metas.
  72. ######## ###################### ##################################################
  73. # Meta rules used to prevent --lint errors after moving/changing rules
  74. ######## ###################### ##################################################
  75. meta __SARE_HEAD_FALSE __FROM_AOL_COM && !__FROM_AOL_COM
  76. meta SARE_MULT_RATW_03 __SARE_HEAD_FALSE
  77. ######## ###################### ##################################################
  78. # Component rules used within meta rules
  79. ######## ###################### ##################################################
  80. header __SARE_HEAD_8BIT_SUBJ Subject =~ /[\x80-\xff]{3,}/
  81. #####################################################################################
  82. # SARE Header-Exists rules
  83. ######## ###################### ##################################################
  84. header SARE_HEAD_HDR_CONVER exists:Conversion
  85. describe SARE_HEAD_HDR_CONVER Message headers used which identify spam
  86. score SARE_HEAD_HDR_CONVER 1.111
  87. #stype SARE_HEAD_HDR_CONVER spamp
  88. #counts SARE_HEAD_HDR_CONVER 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  89. #max SARE_HEAD_HDR_CONVER 54s/0h of 275081 corpus (134226s/140855h RM) 05/30/05
  90. #counts SARE_HEAD_HDR_CONVER 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  91. #counts SARE_HEAD_HDR_CONVER 9s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  92. #max SARE_HEAD_HDR_CONVER 10s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  93. #counts SARE_HEAD_HDR_CONVER 0s/0h of 13303 corpus (7429s/5874h CT) 05/14/06
  94. #max SARE_HEAD_HDR_CONVER 5s/0h of 11052 corpus (6614s/4438h CT) 03/10/05
  95. #counts SARE_HEAD_HDR_CONVER 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  96. #counts SARE_HEAD_HDR_CONVER 0s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  97. header SARE_HEAD_HDR_JLH exists:X-JLH
  98. describe SARE_HEAD_HDR_JLH Message headers used which identify spam
  99. score SARE_HEAD_HDR_JLH 1.111
  100. #stype SARE_HEAD_HDR_JLH spamp
  101. #counts SARE_HEAD_HDR_JLH 0s/0h of 280812 corpus (109490s/171322h RM) 05/05/05
  102. #max SARE_HEAD_HDR_JLH 71s/0h of 114271 corpus (81068s/33203h RM) 01/15/05
  103. #counts SARE_HEAD_HDR_JLH 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  104. #counts SARE_HEAD_HDR_JLH 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  105. #counts SARE_HEAD_HDR_JLH 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  106. #counts SARE_HEAD_HDR_JLH 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  107. header SARE_HEAD_HDR_MSGTYPE exists:Message-Type
  108. describe SARE_HEAD_HDR_MSGTYPE Message headers used which identify spam
  109. score SARE_HEAD_HDR_MSGTYPE 0.555
  110. #stype SARE_HEAD_HDR_MSGTYPE spamp
  111. #counts SARE_HEAD_HDR_MSGTYPE 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  112. #max SARE_HEAD_HDR_MSGTYPE 1s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  113. #counts SARE_HEAD_HDR_MSGTYPE 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  114. #counts SARE_HEAD_HDR_MSGTYPE 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  115. #counts SARE_HEAD_HDR_MSGTYPE 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  116. #counts SARE_HEAD_HDR_MSGTYPE 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  117. header SARE_HEAD_HDR_NLETRID exists:Newsletter-ID
  118. describe SARE_HEAD_HDR_NLETRID Message headers used which identify spam
  119. score SARE_HEAD_HDR_NLETRID 1.666
  120. #stype SARE_HEAD_HDR_NLETRID spamp
  121. #counts SARE_HEAD_HDR_NLETRID 0s/0h of 259338 corpus (110116s/149222h RM) 05/16/05
  122. #max SARE_HEAD_HDR_NLETRID 173s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  123. #counts SARE_HEAD_HDR_NLETRID 0s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  124. #max SARE_HEAD_HDR_NLETRID 1s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  125. #counts SARE_HEAD_HDR_NLETRID 28s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  126. #counts SARE_HEAD_HDR_NLETRID 0s/0h of 10590 corpus (5819s/4771h CT) 07/26/05
  127. #max SARE_HEAD_HDR_NLETRID 12s/0h of 11052 corpus (6614s/4438h CT) 03/10/05
  128. #counts SARE_HEAD_HDR_NLETRID 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  129. header SARE_HEAD_HDR_PID exists:PID
  130. describe SARE_HEAD_HDR_PID Message headers used which identify spam
  131. score SARE_HEAD_HDR_PID 1.666
  132. #stype SARE_HEAD_HDR_PID spamp
  133. #counts SARE_HEAD_HDR_PID 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  134. #max SARE_HEAD_HDR_PID 139s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  135. #counts SARE_HEAD_HDR_PID 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  136. #counts SARE_HEAD_HDR_PID 36s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  137. #counts SARE_HEAD_HDR_PID 0s/0h of 10590 corpus (5819s/4771h CT) 07/26/05
  138. #max SARE_HEAD_HDR_PID 20s/0h of 11052 corpus (6614s/4438h CT) 03/10/05
  139. #counts SARE_HEAD_HDR_PID 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  140. header SARE_HEAD_HDR_REDIRTO exists:Redirect-to
  141. describe SARE_HEAD_HDR_REDIRTO Message headers used which identify spam
  142. score SARE_HEAD_HDR_REDIRTO 0.555
  143. #stype SARE_HEAD_HDR_REDIRTO spamp
  144. #counts SARE_HEAD_HDR_REDIRTO 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  145. #max SARE_HEAD_HDR_REDIRTO 1s/0h of 114261 corpus (81069s/33192h RM) 01/15/05
  146. #counts SARE_HEAD_HDR_REDIRTO 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  147. #counts SARE_HEAD_HDR_REDIRTO 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  148. #counts SARE_HEAD_HDR_REDIRTO 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  149. #counts SARE_HEAD_HDR_REDIRTO 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  150. header SARE_HEAD_HDR_ROT exists:Rot
  151. describe SARE_HEAD_HDR_ROT Message headers used which identify spam
  152. score SARE_HEAD_HDR_ROT 0.555
  153. #stype SARE_HEAD_HDR_ROT spamp
  154. #counts SARE_HEAD_HDR_ROT 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  155. #max SARE_HEAD_HDR_ROT 3s/0h of 114261 corpus (81069s/33192h RM) 01/15/05
  156. #counts SARE_HEAD_HDR_ROT 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  157. #counts SARE_HEAD_HDR_ROT 2s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  158. #counts SARE_HEAD_HDR_ROT 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  159. #counts SARE_HEAD_HDR_ROT 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  160. header SARE_HEAD_HDR_RTNPATH exists:List-Return-Path
  161. describe SARE_HEAD_HDR_RTNPATH Message headers used which identify spam
  162. score SARE_HEAD_HDR_RTNPATH 1.111
  163. #stype SARE_HEAD_HDR_RTNPATH spamp
  164. #counts SARE_HEAD_HDR_RTNPATH 0s/0h of 280812 corpus (109490s/171322h RM) 05/05/05
  165. #max SARE_HEAD_HDR_RTNPATH 32s/0h of 114271 corpus (81068s/33203h RM) 01/15/05
  166. #counts SARE_HEAD_HDR_RTNPATH 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  167. #counts SARE_HEAD_HDR_RTNPATH 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  168. #counts SARE_HEAD_HDR_RTNPATH 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  169. #counts SARE_HEAD_HDR_RTNPATH 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  170. header SARE_HEAD_HDR_WCMSGID exists:WcMessage-ID
  171. describe SARE_HEAD_HDR_WCMSGID Message headers used which identify spam
  172. score SARE_HEAD_HDR_WCMSGID 0.555
  173. #stype SARE_HEAD_HDR_WCMSGID spamp
  174. #counts SARE_HEAD_HDR_WCMSGID 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  175. #max SARE_HEAD_HDR_WCMSGID 1s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  176. #counts SARE_HEAD_HDR_WCMSGID 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  177. #counts SARE_HEAD_HDR_WCMSGID 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  178. #counts SARE_HEAD_HDR_WCMSGID 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  179. #counts SARE_HEAD_HDR_WCMSGID 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  180. header SARE_HEAD_HDR_X400MTI exists:X400-MTS-Identifier
  181. describe SARE_HEAD_HDR_X400MTI Message headers used which identify spam
  182. score SARE_HEAD_HDR_X400MTI 0.555
  183. #stype SARE_HEAD_HDR_X400MTI spamp
  184. #counts SARE_HEAD_HDR_X400MTI 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  185. #max SARE_HEAD_HDR_X400MTI 1s/0h of 114261 corpus (81069s/33192h RM) 01/15/05
  186. #counts SARE_HEAD_HDR_X400MTI 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  187. #counts SARE_HEAD_HDR_X400MTI 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  188. #counts SARE_HEAD_HDR_X400MTI 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  189. #counts SARE_HEAD_HDR_X400MTI 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  190. header SARE_HEAD_HDR_X400RCV exists:X400-Received
  191. describe SARE_HEAD_HDR_X400RCV Message headers used which identify spam
  192. score SARE_HEAD_HDR_X400RCV 0.555
  193. #stype SARE_HEAD_HDR_X400RCV spamp
  194. #counts SARE_HEAD_HDR_X400RCV 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  195. #max SARE_HEAD_HDR_X400RCV 1s/0h of 114261 corpus (81069s/33192h RM) 01/15/05
  196. #counts SARE_HEAD_HDR_X400RCV 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  197. #counts SARE_HEAD_HDR_X400RCV 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  198. #counts SARE_HEAD_HDR_X400RCV 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  199. #counts SARE_HEAD_HDR_X400RCV 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  200. header SARE_HEAD_HDR_XAR exists:X-AR
  201. describe SARE_HEAD_HDR_XAR Message headers used which identify spam
  202. score SARE_HEAD_HDR_XAR 0.555
  203. #stype SARE_HEAD_HDR_XAR spamp
  204. #counts SARE_HEAD_HDR_XAR 0s/0h of 196688 corpus (96191s/100497h RM) 02/21/05
  205. #max SARE_HEAD_HDR_XAR 2s/0h of 66087 corpus (40127s/25960h RM) 09/11/04
  206. #counts SARE_HEAD_HDR_XAR 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  207. #counts SARE_HEAD_HDR_XAR 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  208. #counts SARE_HEAD_HDR_XAR 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  209. #counts SARE_HEAD_HDR_XAR 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  210. header SARE_HEAD_HDR_XAUTGEN exists:X-Auto-Generated
  211. describe SARE_HEAD_HDR_XAUTGEN Message headers used which identify spam
  212. score SARE_HEAD_HDR_XAUTGEN 0.555
  213. #stype SARE_HEAD_HDR_XAUTGEN spamp
  214. #counts SARE_HEAD_HDR_XAUTGEN 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  215. #max SARE_HEAD_HDR_XAUTGEN 1s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  216. #counts SARE_HEAD_HDR_XAUTGEN 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  217. #counts SARE_HEAD_HDR_XAUTGEN 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  218. #counts SARE_HEAD_HDR_XAUTGEN 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  219. #counts SARE_HEAD_HDR_XAUTGEN 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  220. header SARE_HEAD_HDR_XBNCETR exists:X-BounceTrace
  221. describe SARE_HEAD_HDR_XBNCETR Message headers used which identify spam
  222. score SARE_HEAD_HDR_XBNCETR 1.111
  223. #stype SARE_HEAD_HDR_XBNCETR spamp
  224. #counts SARE_HEAD_HDR_XBNCETR 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  225. #max SARE_HEAD_HDR_XBNCETR 96s/0h of 619677 corpus (318875s/300802h RM) 09/11/05
  226. #counts SARE_HEAD_HDR_XBNCETR 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  227. #counts SARE_HEAD_HDR_XBNCETR 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  228. #counts SARE_HEAD_HDR_XBNCETR 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  229. #counts SARE_HEAD_HDR_XBNCETR 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  230. header SARE_HEAD_HDR_XCNDINF exists:X-CND-Info
  231. describe SARE_HEAD_HDR_XCNDINF Message headers used which identify spam
  232. score SARE_HEAD_HDR_XCNDINF 0.555
  233. #stype SARE_HEAD_HDR_XCNDINF spamp
  234. #counts SARE_HEAD_HDR_XCNDINF 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  235. #max SARE_HEAD_HDR_XCNDINF 6s/0h of 689155 corpus (348140s/341015h RM) 09/18/05
  236. #counts SARE_HEAD_HDR_XCNDINF 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  237. #counts SARE_HEAD_HDR_XCNDINF 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  238. #counts SARE_HEAD_HDR_XCNDINF 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  239. #counts SARE_HEAD_HDR_XCNDINF 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  240. header SARE_HEAD_HDR_XCROSS exists:X-cross
  241. describe SARE_HEAD_HDR_XCROSS Message headers used which identify spam
  242. score SARE_HEAD_HDR_XCROSS 0.100
  243. #stype SARE_HEAD_HDR_XCROSS spamp
  244. #counts SARE_HEAD_HDR_XCROSS 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  245. #counts SARE_HEAD_HDR_XCROSS 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  246. #counts SARE_HEAD_HDR_XCROSS 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  247. #counts SARE_HEAD_HDR_XCROSS 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  248. #counts SARE_HEAD_HDR_XCROSS 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  249. header SARE_HEAD_HDR_XEMGBMS exists:X-EMailGateBouncedMessage
  250. describe SARE_HEAD_HDR_XEMGBMS Message headers used which identify spam
  251. score SARE_HEAD_HDR_XEMGBMS 0.555
  252. #stype SARE_HEAD_HDR_XEMGBMS spamp
  253. #counts SARE_HEAD_HDR_XEMGBMS 0s/0h of 298277 corpus (136400s/161877h RM) 06/06/05
  254. #max SARE_HEAD_HDR_XEMGBMS 6s/0h of 274235 corpus (109066s/165169h RM) 05/15/05
  255. #counts SARE_HEAD_HDR_XEMGBMS 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  256. #counts SARE_HEAD_HDR_XEMGBMS 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  257. #counts SARE_HEAD_HDR_XEMGBMS 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  258. #counts SARE_HEAD_HDR_XEMGBMS 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  259. header SARE_HEAD_HDR_XGMAILA exists:X-Gmail-Account
  260. describe SARE_HEAD_HDR_XGMAILA Message headers used which identify spam
  261. score SARE_HEAD_HDR_XGMAILA 1.111
  262. #stype SARE_HEAD_HDR_XGMAILA spamp
  263. #counts SARE_HEAD_HDR_XGMAILA 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  264. #max SARE_HEAD_HDR_XGMAILA 20s/0h of 259338 corpus (110116s/149222h RM) 05/16/05
  265. #counts SARE_HEAD_HDR_XGMAILA 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  266. #counts SARE_HEAD_HDR_XGMAILA 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  267. #counts SARE_HEAD_HDR_XGMAILA 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  268. #counts SARE_HEAD_HDR_XGMAILA 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  269. header SARE_HEAD_HDR_XIDSRVR exists:X-Identity-Server
  270. describe SARE_HEAD_HDR_XIDSRVR Message headers used which identify spam
  271. score SARE_HEAD_HDR_XIDSRVR 1.111
  272. #stype SARE_HEAD_HDR_XIDSRVR spamp
  273. #hist SARE_HEAD_HDR_XIDSRVR Bob Menschel, June 3 2005, idea by Alex Broens
  274. #counts SARE_HEAD_HDR_XIDSRVR 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  275. #max SARE_HEAD_HDR_XIDSRVR 15s/0h of 689155 corpus (348140s/341015h RM) 09/18/05
  276. #counts SARE_HEAD_HDR_XIDSRVR 0s/0h of 5653 corpus (1019s/4634h ft) 06/04/05
  277. #counts SARE_HEAD_HDR_XIDSRVR 0s/0h of 47283 corpus (43206s/4077h MY) 06/05/05
  278. #counts SARE_HEAD_HDR_XIDSRVR 0s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  279. #counts SARE_HEAD_HDR_XIDSRVR 0s/0h of 10590 corpus (5819s/4771h CT) 07/26/05
  280. header SARE_HEAD_HDR_XLC exists:X-L-C
  281. describe SARE_HEAD_HDR_XLC Message headers used which identify spam
  282. score SARE_HEAD_HDR_XLC 0.100
  283. #stype SARE_HEAD_HDR_XLC spamp
  284. #counts SARE_HEAD_HDR_XLC 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  285. #counts SARE_HEAD_HDR_XLC 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  286. #counts SARE_HEAD_HDR_XLC 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  287. #counts SARE_HEAD_HDR_XLC 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  288. #counts SARE_HEAD_HDR_XLC 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  289. header SARE_HEAD_HDR_XLIDCOD exists:X-LIDCode
  290. describe SARE_HEAD_HDR_XLIDCOD Message headers used which identify spam
  291. score SARE_HEAD_HDR_XLIDCOD 0.100
  292. #stype SARE_HEAD_HDR_XLIDCOD spamp
  293. #counts SARE_HEAD_HDR_XLIDCOD 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  294. #counts SARE_HEAD_HDR_XLIDCOD 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  295. #counts SARE_HEAD_HDR_XLIDCOD 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  296. #counts SARE_HEAD_HDR_XLIDCOD 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  297. #counts SARE_HEAD_HDR_XLIDCOD 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  298. header SARE_HEAD_HDR_XMISCID exists:X-Misc_ID
  299. describe SARE_HEAD_HDR_XMISCID Message headers used which identify spam
  300. score SARE_HEAD_HDR_XMISCID 0.100
  301. #stype SARE_HEAD_HDR_XMISCID spamp
  302. #hist SARE_HEAD_HDR_XMISCID FH_XMISCID
  303. #counts SARE_HEAD_HDR_XMISCID 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  304. #counts SARE_HEAD_HDR_XMISCID 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  305. #counts SARE_HEAD_HDR_XMISCID 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  306. #counts SARE_HEAD_HDR_XMISCID 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  307. #counts SARE_HEAD_HDR_XMISCID 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  308. header SARE_HEAD_HDR_XMLCIPH exists:X-mlcipher
  309. describe SARE_HEAD_HDR_XMLCIPH Message headers used which identify spam
  310. score SARE_HEAD_HDR_XMLCIPH 0.100
  311. #stype SARE_HEAD_HDR_XMLCIPH spamp
  312. #counts SARE_HEAD_HDR_XMLCIPH 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  313. #counts SARE_HEAD_HDR_XMLCIPH 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  314. #counts SARE_HEAD_HDR_XMLCIPH 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  315. #counts SARE_HEAD_HDR_XMLCIPH 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  316. #counts SARE_HEAD_HDR_XMLCIPH 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  317. header SARE_HEAD_HDR_XMLMSGI exists:X-mlmsgid
  318. describe SARE_HEAD_HDR_XMLMSGI Message headers used which identify spam
  319. score SARE_HEAD_HDR_XMLMSGI 0.100
  320. #stype SARE_HEAD_HDR_XMLMSGI spamp
  321. #counts SARE_HEAD_HDR_XMLMSGI 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  322. #counts SARE_HEAD_HDR_XMLMSGI 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  323. #counts SARE_HEAD_HDR_XMLMSGI 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  324. #counts SARE_HEAD_HDR_XMLMSGI 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  325. #counts SARE_HEAD_HDR_XMLMSGI 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  326. header SARE_HEAD_HDR_XMAGDID exists:X-magdalene-ID
  327. describe SARE_HEAD_HDR_XMAGDID Message headers used which identify spam
  328. score SARE_HEAD_HDR_XMAGDID 0.555
  329. #stype SARE_HEAD_HDR_XMAGDID spamp
  330. #counts SARE_HEAD_HDR_XMAGDID 0s/0h of 71334 corpus (43633s/27701h RM) 10/03/04
  331. #max SARE_HEAD_HDR_XMAGDID 1s/0h of 60201 corpus (35226s/24975h RM) 08/14/04
  332. #counts SARE_HEAD_HDR_XMAGDID 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  333. #counts SARE_HEAD_HDR_XMAGDID 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  334. #counts SARE_HEAD_HDR_XMAGDID 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  335. #counts SARE_HEAD_HDR_XMAGDID 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  336. header SARE_HEAD_HDR_XMPM exists:X-mpm
  337. describe SARE_HEAD_HDR_XMPM Message headers used which identify spam
  338. score SARE_HEAD_HDR_XMPM 0.100
  339. #stype SARE_HEAD_HDR_XMPM spamp
  340. #counts SARE_HEAD_HDR_XMPM 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  341. #counts SARE_HEAD_HDR_XMPM 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  342. #counts SARE_HEAD_HDR_XMPM 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  343. #counts SARE_HEAD_HDR_XMPM 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  344. #counts SARE_HEAD_HDR_XMPM 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  345. header SARE_HEAD_HDR_XMS exists:X-ms
  346. describe SARE_HEAD_HDR_XMS Message headers used which identify spam
  347. score SARE_HEAD_HDR_XMS 0.100
  348. #stype SARE_HEAD_HDR_XMS spamp
  349. #counts SARE_HEAD_HDR_XMS 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  350. #counts SARE_HEAD_HDR_XMS 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  351. #counts SARE_HEAD_HDR_XMS 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  352. #counts SARE_HEAD_HDR_XMS 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  353. #counts SARE_HEAD_HDR_XMS 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  354. header SARE_HEAD_HDR_XNOSPAM exists:X-No-Spam
  355. describe SARE_HEAD_HDR_XNOSPAM Message headers used which identify spam
  356. score SARE_HEAD_HDR_XNOSPAM 1.111
  357. #stype SARE_HEAD_HDR_XNOSPAM spamp
  358. #counts SARE_HEAD_HDR_XNOSPAM 0s/0h of 196688 corpus (96191s/100497h RM) 02/21/05
  359. #max SARE_HEAD_HDR_XNOSPAM 12s/0h of 60201 corpus (35226s/24975h RM) 08/14/04
  360. #counts SARE_HEAD_HDR_XNOSPAM 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  361. #max SARE_HEAD_HDR_XNOSPAM 4s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  362. #counts SARE_HEAD_HDR_XNOSPAM 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  363. #counts SARE_HEAD_HDR_XNOSPAM 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  364. #counts SARE_HEAD_HDR_XNOSPAM 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  365. header SARE_HEAD_HDR_XNTC exists:X-ntc
  366. describe SARE_HEAD_HDR_XNTC Message headers used which identify spam
  367. score SARE_HEAD_HDR_XNTC 0.100
  368. #stype SARE_HEAD_HDR_XNTC spamp
  369. #counts SARE_HEAD_HDR_XNTC 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  370. #counts SARE_HEAD_HDR_XNTC 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  371. #counts SARE_HEAD_HDR_XNTC 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  372. #counts SARE_HEAD_HDR_XNTC 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  373. #counts SARE_HEAD_HDR_XNTC 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  374. header SARE_HEAD_HDR_XPOPB4S exists:X-Pop-Before-SMTP-Sender
  375. describe SARE_HEAD_HDR_XPOPB4S Message headers used which identify spam
  376. score SARE_HEAD_HDR_XPOPB4S 0.555
  377. #stype SARE_HEAD_HDR_XPOPB4S spamp
  378. #counts SARE_HEAD_HDR_XPOPB4S 0s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  379. #max SARE_HEAD_HDR_XPOPB4S 1s/0h of 60201 corpus (35226s/24975h RM) 08/14/04
  380. #counts SARE_HEAD_HDR_XPOPB4S 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  381. #counts SARE_HEAD_HDR_XPOPB4S 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  382. #counts SARE_HEAD_HDR_XPOPB4S 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  383. #counts SARE_HEAD_HDR_XPOPB4S 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  384. header SARE_HEAD_HDR_XPOPFLK exists:X-POPFile-Link
  385. describe SARE_HEAD_HDR_XPOPFLK Message headers used which identify spam
  386. score SARE_HEAD_HDR_XPOPFLK 0.555
  387. #stype SARE_HEAD_HDR_XPOPFLK spamp
  388. #counts SARE_HEAD_HDR_XPOPFLK 0s/0h of 71334 corpus (43633s/27701h RM) 10/03/04
  389. #max SARE_HEAD_HDR_XPOPFLK 3s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  390. #counts SARE_HEAD_HDR_XPOPFLK 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  391. #counts SARE_HEAD_HDR_XPOPFLK 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  392. #counts SARE_HEAD_HDR_XPOPFLK 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  393. #counts SARE_HEAD_HDR_XPOPFLK 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  394. header SARE_HEAD_HDR_XPRIOMS exists:X-Prioserve-MailScanner
  395. describe SARE_HEAD_HDR_XPRIOMS Message headers used which identify spam
  396. score SARE_HEAD_HDR_XPRIOMS 0.555
  397. #stype SARE_HEAD_HDR_XPRIOMS spamp
  398. #counts SARE_HEAD_HDR_XPRIOMS 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  399. #max SARE_HEAD_HDR_XPRIOMS 1s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  400. #counts SARE_HEAD_HDR_XPRIOMS 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  401. #counts SARE_HEAD_HDR_XPRIOMS 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  402. #counts SARE_HEAD_HDR_XPRIOMS 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  403. #counts SARE_HEAD_HDR_XPRIOMS 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  404. header SARE_HEAD_HDR_XPRIOMF exists:X-Prioserve-MailScanner-From
  405. describe SARE_HEAD_HDR_XPRIOMF Message headers used which identify spam
  406. score SARE_HEAD_HDR_XPRIOMF 0.555
  407. #stype SARE_HEAD_HDR_XPRIOMF spamp
  408. #counts SARE_HEAD_HDR_XPRIOMF 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  409. #max SARE_HEAD_HDR_XPRIOMF 1s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  410. #counts SARE_HEAD_HDR_XPRIOMF 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  411. #counts SARE_HEAD_HDR_XPRIOMF 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  412. #counts SARE_HEAD_HDR_XPRIOMF 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  413. #counts SARE_HEAD_HDR_XPRIOMF 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  414. header SARE_HEAD_HDR_XPRIOMI exists:X-Prioserve-MailScanner-Information
  415. describe SARE_HEAD_HDR_XPRIOMI Message headers used which identify spam
  416. score SARE_HEAD_HDR_XPRIOMI 0.555
  417. #stype SARE_HEAD_HDR_XPRIOMI spamp
  418. #counts SARE_HEAD_HDR_XPRIOMI 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  419. #max SARE_HEAD_HDR_XPRIOMI 1s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  420. #counts SARE_HEAD_HDR_XPRIOMI 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  421. #counts SARE_HEAD_HDR_XPRIOMI 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  422. #counts SARE_HEAD_HDR_XPRIOMI 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  423. #counts SARE_HEAD_HDR_XPRIOMI 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  424. header SARE_HEAD_HDR_XPIROMC exists:X-Prioserve-MailScanner-SpamCheck
  425. describe SARE_HEAD_HDR_XPIROMC Message headers used which identify spam
  426. score SARE_HEAD_HDR_XPIROMC 0.555
  427. #stype SARE_HEAD_HDR_XPIROMC spamp
  428. #counts SARE_HEAD_HDR_XPIROMC 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  429. #max SARE_HEAD_HDR_XPIROMC 1s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  430. #counts SARE_HEAD_HDR_XPIROMC 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  431. #counts SARE_HEAD_HDR_XPIROMC 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  432. #counts SARE_HEAD_HDR_XPIROMC 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  433. #counts SARE_HEAD_HDR_XPIROMC 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  434. header SARE_HEAD_HDR_XRBLTST exists:X-RBL-TST
  435. describe SARE_HEAD_HDR_XRBLTST Message headers used which identify spam
  436. score SARE_HEAD_HDR_XRBLTST 0.555
  437. #stype SARE_HEAD_HDR_XRBLTST spamp
  438. #counts SARE_HEAD_HDR_XRBLTST 0s/0h of 120459 corpus (71363s/49096h RM) 02/12/05
  439. #max SARE_HEAD_HDR_XRBLTST 2s/0h of 114238 corpus (81067s/33171h RM) 01/15/05
  440. #counts SARE_HEAD_HDR_XRBLTST 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  441. #counts SARE_HEAD_HDR_XRBLTST 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  442. #counts SARE_HEAD_HDR_XRBLTST 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  443. #counts SARE_HEAD_HDR_XRBLTST 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  444. header SARE_HEAD_HDR_XREC exists:X-Rec
  445. describe SARE_HEAD_HDR_XREC Message headers used which identify spam
  446. score SARE_HEAD_HDR_XREC 2.222
  447. #stype SARE_HEAD_HDR_XREC spamp
  448. #counts SARE_HEAD_HDR_XREC 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  449. #counts SARE_HEAD_HDR_XREC 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  450. #counts SARE_HEAD_HDR_XREC 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  451. #counts SARE_HEAD_HDR_XREC 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  452. #counts SARE_HEAD_HDR_XREC 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  453. header SARE_HEAD_HDR_XRIPE exists:X-RIPE
  454. describe SARE_HEAD_HDR_XRIPE Message headers used which identify spam
  455. score SARE_HEAD_HDR_XRIPE 1.111
  456. #stype SARE_HEAD_HDR_XRIPE spamp
  457. #counts SARE_HEAD_HDR_XRIPE 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  458. #max SARE_HEAD_HDR_XRIPE 16s/0h of 400432 corpus (178148s/222284h RM) 03/31/05
  459. #counts SARE_HEAD_HDR_XRIPE 0s/0h of 10995 corpus (6568s/4427h CT) 03/10/05
  460. #counts SARE_HEAD_HDR_XRIPE 0s/0h of 54806 corpus (17633s/37173h JH-3.01) 03/14/05
  461. #counts SARE_HEAD_HDR_XRIPE 0s/0h of 31513 corpus (27912s/3601h MY) 03/09/05
  462. #counts SARE_HEAD_HDR_XRIPE 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  463. #counts SARE_HEAD_HDR_XRIPE 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  464. header SARE_HEAD_HDR_XSAFMMI exists:X-SafeMailer-MsgId
  465. describe SARE_HEAD_HDR_XSAFMMI Message headers used which identify spam
  466. score SARE_HEAD_HDR_XSAFMMI 0.555
  467. #stype SARE_HEAD_HDR_XSAFMMI spamp
  468. #counts SARE_HEAD_HDR_XSAFMMI 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  469. #max SARE_HEAD_HDR_XSAFMMI 1s/0h of 114238 corpus (81067s/33171h RM) 01/15/05
  470. #counts SARE_HEAD_HDR_XSAFMMI 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  471. #counts SARE_HEAD_HDR_XSAFMMI 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  472. #counts SARE_HEAD_HDR_XSAFMMI 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  473. #counts SARE_HEAD_HDR_XSAFMMI 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  474. header SARE_HEAD_HDR_XSPAMSC exists:X-Spam-Score
  475. describe SARE_HEAD_HDR_XSPAMSC Message headers used which identify spam
  476. score SARE_HEAD_HDR_XSPAMSC 0.555
  477. #stype SARE_HEAD_HDR_XSPAMSC spamp
  478. #counts SARE_HEAD_HDR_XSPAMSC 0s/0h of 60201 corpus (35226s/24975h RM) 08/14/04
  479. #counts SARE_HEAD_HDR_XSPAMSC 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  480. #max SARE_HEAD_HDR_XSPAMSC 1s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  481. #counts SARE_HEAD_HDR_XSPAMSC 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  482. #counts SARE_HEAD_HDR_XSPAMSC 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  483. #counts SARE_HEAD_HDR_XSPAMSC 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  484. header SARE_HEAD_HDR_XSRK exists:X-srk
  485. describe SARE_HEAD_HDR_XSRK Message headers used which identify spam
  486. score SARE_HEAD_HDR_XSRK 0.100
  487. #stype SARE_HEAD_HDR_XSRK spamp
  488. #counts SARE_HEAD_HDR_XSRK 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  489. #counts SARE_HEAD_HDR_XSRK 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  490. #counts SARE_HEAD_HDR_XSRK 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  491. #counts SARE_HEAD_HDR_XSRK 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  492. #counts SARE_HEAD_HDR_XSRK 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  493. header SARE_HEAD_HDR_XSUBID exists:X-SubID
  494. describe SARE_HEAD_HDR_XSUBID Message headers used which identify spam
  495. score SARE_HEAD_HDR_XSUBID 0.555
  496. #stype SARE_HEAD_HDR_XSUBID spamp
  497. #counts SARE_HEAD_HDR_XSUBID 0s/0h of 120459 corpus (71363s/49096h RM) 02/12/05
  498. #max SARE_HEAD_HDR_XSUBID 3s/0h of 114238 corpus (81067s/33171h RM) 01/15/05
  499. #counts SARE_HEAD_HDR_XSUBID 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  500. #counts SARE_HEAD_HDR_XSUBID 1s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  501. #counts SARE_HEAD_HDR_XSUBID 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  502. #counts SARE_HEAD_HDR_XSUBID 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  503. header SARE_HEAD_HDR_XTRANS exists:X-Trans
  504. describe SARE_HEAD_HDR_XTRANS Message headers used which identify spam
  505. score SARE_HEAD_HDR_XTRANS 0.100
  506. #stype SARE_HEAD_HDR_XTRANS spamp
  507. #counts SARE_HEAD_HDR_XTRANS 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  508. #counts SARE_HEAD_HDR_XTRANS 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  509. #counts SARE_HEAD_HDR_XTRANS 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  510. #counts SARE_HEAD_HDR_XTRANS 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  511. #counts SARE_HEAD_HDR_XTRANS 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  512. header SARE_HEAD_HDR_XTXTCLS exists:X-Text-Classification
  513. describe SARE_HEAD_HDR_XTXTCLS Message headers used which identify spam
  514. score SARE_HEAD_HDR_XTXTCLS 0.555
  515. #stype SARE_HEAD_HDR_XTXTCLS spamp
  516. #counts SARE_HEAD_HDR_XTXTCLS 0s/0h of 71334 corpus (43633s/27701h RM) 10/03/04
  517. #max SARE_HEAD_HDR_XTXTCLS 3s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  518. #counts SARE_HEAD_HDR_XTXTCLS 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  519. #counts SARE_HEAD_HDR_XTXTCLS 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  520. #counts SARE_HEAD_HDR_XTXTCLS 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  521. #counts SARE_HEAD_HDR_XTXTCLS 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  522. header SARE_HEAD_HDR_XVIG exists:X-Vig
  523. describe SARE_HEAD_HDR_XVIG Message headers used which identify spam
  524. score SARE_HEAD_HDR_XVIG 0.100
  525. #stype SARE_HEAD_HDR_XVIG spamp
  526. #counts SARE_HEAD_HDR_XVIG 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  527. #counts SARE_HEAD_HDR_XVIG 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  528. #counts SARE_HEAD_HDR_XVIG 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  529. #counts SARE_HEAD_HDR_XVIG 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  530. #counts SARE_HEAD_HDR_XVIG 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  531. header SARE_HEAD_HDR_XYD exists:X-yd
  532. describe SARE_HEAD_HDR_XYD Message headers used which identify spam
  533. score SARE_HEAD_HDR_XYD 0.100
  534. #stype SARE_HEAD_HDR_XYD spamp
  535. #counts SARE_HEAD_HDR_XYD 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  536. #counts SARE_HEAD_HDR_XYD 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  537. #counts SARE_HEAD_HDR_XYD 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  538. #counts SARE_HEAD_HDR_XYD 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  539. #counts SARE_HEAD_HDR_XYD 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  540. header SARE_HEAD_HDR_XI exists:X-I
  541. describe SARE_HEAD_HDR_XI Message headers used which identify spam
  542. score SARE_HEAD_HDR_XI 0.100
  543. #stype SARE_HEAD_HDR_XI spamp
  544. #counts SARE_HEAD_HDR_XI 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  545. #counts SARE_HEAD_HDR_XI 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  546. #counts SARE_HEAD_HDR_XI 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  547. #counts SARE_HEAD_HDR_XI 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  548. #counts SARE_HEAD_HDR_XI 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  549. header SARE_HEAD_HDR_XIM exists:X-IM
  550. describe SARE_HEAD_HDR_XIM Message headers used which identify spam
  551. score SARE_HEAD_HDR_XIM 0.100
  552. #stype SARE_HEAD_HDR_XIM spamp
  553. #counts SARE_HEAD_HDR_XIM 0s/0h of 60624 corpus (35501s/25123h RM) 08/13/04
  554. #counts SARE_HEAD_HDR_XIM 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  555. #counts SARE_HEAD_HDR_XIM 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  556. #counts SARE_HEAD_HDR_XIM 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  557. #counts SARE_HEAD_HDR_XIM 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  558. #####################################################################################
  559. # SARE Content-Type and Boundary rules
  560. ######## ###################### ##################################################
  561. header SARE_BOUNDARY_01 Content-Type =~ /boundary==?\".{0,}XXXX-/
  562. describe SARE_BOUNDARY_01 Spam tool pattern in MIME boundary
  563. score SARE_BOUNDARY_01 0.100
  564. #hist SARE_BOUNDARY_01 L.MIME_BOUND_SIMPLE
  565. #counts SARE_BOUNDARY_01 0s/0h of 89541 corpus (67467s/22074h RM) 05/28/04
  566. #counts SARE_BOUNDARY_01 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  567. #counts SARE_BOUNDARY_01 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  568. #counts SARE_BOUNDARY_01 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  569. header SARE_BOUNDARY_02 Content-Type =~ /boundary\=('|\")?\~{10,}/
  570. describe SARE_BOUNDARY_02 Too many ~'s in the boundary.
  571. score SARE_BOUNDARY_02 0.650
  572. #hist SARE_BOUNDARY_02 MY_BOUNDARY2
  573. #counts SARE_BOUNDARY_02 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  574. #max SARE_BOUNDARY_02 51s/0h of 327690 corpus (159737s/167953h RM) 07/27/05
  575. #counts SARE_BOUNDARY_02 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  576. #counts SARE_BOUNDARY_02 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  577. #counts SARE_BOUNDARY_02 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  578. header SARE_BOUNDARY_ANYDIG Content-Type =~ /boundary="--.*\[\d\]/i
  579. describe SARE_BOUNDARY_ANYDIG Content type boundary used in spam and viruses
  580. score SARE_BOUNDARY_ANYDIG 1.666
  581. #hist SARE_BOUNDARY_ANYDIG Created by Bob Menschel May 7 2005, suggested by Alex Broens
  582. #counts SARE_BOUNDARY_ANYDIG 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  583. #max SARE_BOUNDARY_ANYDIG 282s/0h of 298277 corpus (136400s/161877h RM) 06/06/05
  584. #counts SARE_BOUNDARY_ANYDIG 0s/0h of 13303 corpus (7429s/5874h CT) 05/14/06
  585. #max SARE_BOUNDARY_ANYDIG 3s/0h of 10590 corpus (5819s/4771h CT) 07/26/05
  586. #counts SARE_BOUNDARY_ANYDIG 0s/0h of 15713 corpus (7767s/7946h FT) 05/14/06
  587. #max SARE_BOUNDARY_ANYDIG 85s/0h of 5653 corpus (1019s/4634h ft) 06/04/05
  588. #counts SARE_BOUNDARY_ANYDIG 2s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  589. header SARE_BOUNDARY_D11 Content-Type =~ /boundary="\d{11}"/
  590. describe SARE_BOUNDARY_D11 Content type boundary used in spam or virus
  591. score SARE_BOUNDARY_D11 1.666
  592. #stype SARE_BOUNDARY_D11 spamp
  593. #hist SARE_BOUNDARY_D11 Created by Bob Menschel May 31 2004
  594. #counts SARE_BOUNDARY_D11 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  595. #max SARE_BOUNDARY_D11 112s/0h of 689155 corpus (348140s/341015h RM) 09/18/05
  596. #counts SARE_BOUNDARY_D11 3s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  597. #counts SARE_BOUNDARY_D11 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  598. #counts SARE_BOUNDARY_D11 0s/0h of 13303 corpus (7429s/5874h CT) 05/14/06
  599. #max SARE_BOUNDARY_D11 7s/0h of 10590 corpus (5819s/4771h CT) 07/26/05
  600. #counts SARE_BOUNDARY_D11 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  601. full SARE_CONTENT_BITBITNUM /\nContent-Encoding: BitBitNUM\n/
  602. describe SARE_CONTENT_BITBITNUM Unlikely content encoding
  603. score SARE_CONTENT_BITBITNUM 1.406
  604. #hist SARE_CONTENT_BITBITNUM Loren Wilton, Feb 1 2005
  605. #counts SARE_CONTENT_BITBITNUM 0s/0h of 280812 corpus (109490s/171322h RM) 05/05/05
  606. #max SARE_CONTENT_BITBITNUM 153s/0h of 95210 corpus (59682s/35528h RM) 02/01/05
  607. #counts SARE_CONTENT_BITBITNUM 64s/0h of 54179 corpus (17002s/37177h JH-3.01) 03/01/05
  608. #counts SARE_CONTENT_BITBITNUM 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  609. #counts SARE_CONTENT_BITBITNUM 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  610. #####################################################################################
  611. # SARE From Rules
  612. ######## ###################### ##################################################
  613. header SARE_FROM_AMERICA From =~ /[^\-]\bamerica\.com\b/i
  614. describe SARE_FROM_AMERICA From user address is used by spammer
  615. score SARE_FROM_AMERICA 1.111
  616. #stype SARE_FROM_AMERICA spamp
  617. #hist SARE_FROM_AMERICA Created by Bob Menschel Sep 24 2004
  618. #counts SARE_FROM_AMERICA 0s/0h of 268479 corpus (127479s/141000h RM) 06/17/05
  619. #max SARE_FROM_AMERICA 5s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  620. #counts SARE_FROM_AMERICA 0s/0h of 54179 corpus (17002s/37177h JH-3.01) 03/01/05
  621. #counts SARE_FROM_AMERICA 0s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  622. #max SARE_FROM_AMERICA 4s/0h of 27758 corpus (24297s/3461h MY) 02/27/05
  623. #counts SARE_FROM_AMERICA 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  624. #counts SARE_FROM_AMERICA 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  625. header SARE_FROM_SPAM_DOMN2 From =~ /\@wses\.(?:com|org)/i
  626. describe SARE_FROM_SPAM_DOMN2 From address suggests this is spam
  627. score SARE_FROM_SPAM_DOMN2 0.100
  628. #stype SARE_FROM_SPAM_DOMN2 spamp
  629. #hist SARE_FROM_SPAM_DOMN2 RM_fa_wses
  630. #counts SARE_FROM_SPAM_DOMN2 0s/0h of 85084 corpus (62489s/22595h RM) 06/08/04
  631. #counts SARE_FROM_SPAM_DOMN2 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  632. #counts SARE_FROM_SPAM_DOMN2 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  633. #counts SARE_FROM_SPAM_DOMN2 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  634. header SARE_FROM_SPAM_NAME2 From =~ /(?:Dating Tips|Email-Gallery|everyday-solution|Free Credit Report|FreebieFix|Long Distance|medmicro|Shape Solutions|TMobile Authorized Dealer|TheGolfWarehouses|Typing Teacher|Value Center|freePriority Shipping|koldny|propecia|thedailyfreesamples)/i
  635. describe SARE_FROM_SPAM_NAME2 From address suggests this is spam
  636. score SARE_FROM_SPAM_NAME2 1.666
  637. #stype SARE_FROM_SPAM_NAME2 spamp
  638. #hist SARE_FROM_SPAM_NAME2 COMBINED.FROM and other sources
  639. #counts SARE_FROM_SPAM_NAME2 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  640. #max SARE_FROM_SPAM_NAME2 140s/0h of 689155 corpus (348140s/341015h RM) 09/18/05
  641. #counts SARE_FROM_SPAM_NAME2 0s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  642. #max SARE_FROM_SPAM_NAME2 1s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  643. #counts SARE_FROM_SPAM_NAME2 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  644. #max SARE_FROM_SPAM_NAME2 16s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  645. #counts SARE_FROM_SPAM_NAME2 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  646. #counts SARE_FROM_SPAM_NAME2 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  647. header SARE_FROM_VIRUS1 ALL=~ /From:\ssupport\@microsoft.com/
  648. describe SARE_FROM_VIRUS1 From address suggests this is a virus
  649. score SARE_FROM_VIRUS1 3.333
  650. #stype SARE_FROM_VIRUS1 vbgg
  651. #counts SARE_FROM_VIRUS1 0s/0h of 280812 corpus (109490s/171322h RM) 05/05/05
  652. #max SARE_FROM_VIRUS1 21s/0h of 400432 corpus (178148s/222284h RM) 03/31/05
  653. #counts SARE_FROM_VIRUS1 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  654. #counts SARE_FROM_VIRUS1 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  655. #counts SARE_FROM_VIRUS1 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  656. header __SARE_FROM_WSJ From:name =~ /Wall Street (?:News Alert|Journal Online|Stock Wizard|Detective|Universe|Update|Chronicle)/i
  657. meta SARE_FROM_WSJ __SARE_FROM_WSJ && __SARE_WHITELIST_FLAG && !USER_IN_WHITELIST
  658. score SARE_FROM_WSJ 1.666
  659. #hist SARE_FROM_WSJ Matt Yackley, Apr 15 2005, expanded by Bob Menschel
  660. #hist SARE_FROM_WSJ Dec 24 2005: Added real WSJ whitelist entry to 70_sare_whitelist.cf; added whitelist flags to new meta to force this rule to NOT hit if this is actually the WSJ.
  661. #counts SARE_FROM_WSJ 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  662. #max SARE_FROM_WSJ 86s/0h of 259338 corpus (110116s/149222h RM) 05/16/05
  663. #counts SARE_FROM_WSJ 0s/0h of 13303 corpus (7429s/5874h CT) 05/14/06
  664. #max SARE_FROM_WSJ 2s/0h of 10590 corpus (5819s/4771h CT) 07/26/05
  665. #counts SARE_FROM_WSJ 0s/0h of 15713 corpus (7767s/7946h FT) 05/14/06
  666. #max SARE_FROM_WSJ 11s/0h of 5653 corpus (1019s/4634h ft) 06/04/05
  667. #counts SARE_FROM_WSJ 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  668. #max SARE_FROM_WSJ 258s/0h of 47809 corpus (43224s/4585h MY) 07/27/05
  669. #counts SARE_FROM_WSJ 0s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  670. #####################################################################################
  671. # SARE From Rules -- Emails coming from free webmail accounts
  672. # Since spam from these can vary depending upon country of origin,
  673. # country of destination, policies, and enforcement of policies,
  674. # most of these are kept as separate rules rather than combined.
  675. ######## ###################### ##################################################
  676. header SARE_FREE_WEBM_Iamfi From =~ /\biamfinallyonline\.com/i
  677. describe SARE_FREE_WEBM_Iamfi Sender used free email account - may be spammer
  678. score SARE_FREE_WEBM_Iamfi 0.555
  679. #stype SARE_FREE_WEBM_Iamfi spamp
  680. #hist SARE_FREE_WEBM_Iamfi Created by Bob Menschel Apr 09 2004
  681. #counts SARE_FREE_WEBM_Iamfi 0s/0h of 327690 corpus (159737s/167953h RM) 07/27/05
  682. #max SARE_FREE_WEBM_Iamfi 3s/0h of 60630 corpus (35509s/25121h RM) 08/11/04
  683. #counts SARE_FREE_WEBM_Iamfi 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  684. #counts SARE_FREE_WEBM_Iamfi 0s/0h of 47809 corpus (43224s/4585h MY) 07/27/05
  685. #max SARE_FREE_WEBM_Iamfi 1s/0h of 27758 corpus (24297s/3461h MY) 02/27/05
  686. #counts SARE_FREE_WEBM_Iamfi 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  687. #counts SARE_FREE_WEBM_Iamfi 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  688. header SARE_FREE_WEBM_USACOPS From =~ /\@usacops\.com/i
  689. describe SARE_FREE_WEBM_USACOPS Maybe spammer with free email
  690. score SARE_FREE_WEBM_USACOPS 0.555
  691. #stype SARE_FREE_WEBM_USACOPS spamp
  692. #hist SARE_FREE_WEBM_USACOPS Created by Bob Menschel Feb 24 2005
  693. #counts SARE_FREE_WEBM_USACOPS 0s/0h of 327690 corpus (159737s/167953h RM) 07/27/05
  694. #max SARE_FREE_WEBM_USACOPS 2s/0h of 238550 corpus (112525s/126025h RM) 02/28/05
  695. #counts SARE_FREE_WEBM_USACOPS 0s/0h of 54179 corpus (17002s/37177h JH-3.01) 03/01/05
  696. #counts SARE_FREE_WEBM_USACOPS 2s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  697. #counts SARE_FREE_WEBM_USACOPS 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  698. #counts SARE_FREE_WEBM_USACOPS 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  699. #####################################################################################
  700. # SARE Message-ID rules
  701. ######## ###################### ##################################################
  702. header SARE_MSGID_06D6 MESSAGEID =~ /<0{6}\d{6}\$\d/
  703. describe SARE_MSGID_06D6 Message-ID has ratware pattern (000009999$9)
  704. score SARE_MSGID_06D6 1.061
  705. #counts SARE_MSGID_06D6 0s/0h of 298277 corpus (136400s/161877h RM) 06/06/05
  706. #max SARE_MSGID_06D6 91s/0h of 115439 corpus (94250s/21189h RM) 04/30/04
  707. #counts SARE_MSGID_06D6 0s/0h of 38374 corpus (14893s/23481h JH-SA3.0rc1) 08/18/04
  708. #counts SARE_MSGID_06D6 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  709. #counts SARE_MSGID_06D6 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  710. #counts SARE_MSGID_06D6 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  711. header MSGID_SPAM_CAPS Message-ID =~ /^\s*<?[A-Z]+\@(?!(?:mailcity|whowhere)\.com)/
  712. #hist MSGID_SPAM_CAPS Distrib: SA 2.64, 3.0.0
  713. header __SARE_MSGID_ALL_CAPHM MESSAGEID =~ /<[A-Z]+\@hotmail.com>/ # no /i
  714. meta SARE_MSGID_ALL_CAPHM __SARE_MSGID_ALL_CAPHM && !MSGID_SPAM_CAPS
  715. describe SARE_MSGID_ALL_CAPHM Ratware all-caps message-id
  716. score SARE_MSGID_ALL_CAPHM 1.666
  717. #stype SARE_MSGID_ALL_CAPHM spamg
  718. #hist SARE_MSGID_ALL_CAPHM Created by Bob Menschel May 15 2004
  719. #note SARE_MSGID_ALL_CAPHM Most emails that match __SARE_MSGID_ALL_CAPHM fall into SARE_MSGID_ALL_CAPS
  720. #counts SARE_MSGID_ALL_CAPHM 0s/0h of 70566 corpus (43013s/27553h RM) 10/02/04
  721. #max SARE_MSGID_ALL_CAPHM 1s/0h of 69619 corpus (42582s/27037h RM) 09/26/04
  722. #counts SARE_MSGID_ALL_CAPHM 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  723. #max SARE_MSGID_ALL_CAPHM 1s/0h of 38398 corpus (14914s/23484h JH) 08/14/04 TM2 SA3.0-pre2
  724. #counts SARE_MSGID_ALL_CAPHM 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  725. #counts SARE_MSGID_ALL_CAPHM 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  726. #counts SARE_MSGID_ALL_CAPHM 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  727. header MSGID_SPAM_CAPS Message-ID =~ /^\s*<?[A-Z]+\@(?!(?:mailcity|whowhere)\.com)/
  728. #hist MSGID_SPAM_CAPS Distrib: SA 2.64, 3.0.0
  729. header __SARE_MSGID_ALL_CAPMS MESSAGEID =~ /<[A-Z]+\@msn.com>/ # no /i
  730. meta SARE_MSGID_ALL_CAPMS __SARE_MSGID_ALL_CAPMS && !MSGID_SPAM_CAPS
  731. describe SARE_MSGID_ALL_CAPMS Ratware all-caps message-id
  732. score SARE_MSGID_ALL_CAPMS 1.666
  733. #hist SARE_MSGID_ALL_CAPMS Created by Bob Menschel May 15 2004
  734. #note SARE_MSGID_ALL_CAPHM Most emails that match __SARE_MSGID_ALL_CAPMS fall into SARE_MSGID_ALL_CAPS
  735. #counts SARE_MSGID_ALL_CAPMS 0s/0h of 58336 corpus (33608s/24728h RM) 08/07/04
  736. #counts SARE_MSGID_ALL_CAPMS 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  737. #counts SARE_MSGID_ALL_CAPMS 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  738. #counts SARE_MSGID_ALL_CAPMS 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  739. header SARE_MSGID_H7H4H4 MESSAGEID =~ /<[a-z0-9]{7}(\$[a-z0-9]{4}){2}\@/
  740. describe SARE_MSGID_H7H4H4 Message-ID has ratware pattern (7hex$4hex$4hex@)
  741. score SARE_MSGID_H7H4H4 0.222
  742. #counts SARE_MSGID_H7H4H4 0s/0h of 273595 corpus (108821s/164774h RM) 05/13/05
  743. #max SARE_MSGID_H7H4H4 2s/0h of 115439 corpus (94250s/21189h) 04/30/04
  744. #counts SARE_MSGID_H7H4H4 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  745. #max SARE_MSGID_H7H4H4 2s/0h of 38374 corpus (14893s/23481h JH-SA3.0rc1) 08/18/04
  746. #counts SARE_MSGID_H7H4H4 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  747. #counts SARE_MSGID_H7H4H4 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  748. #counts SARE_MSGID_H7H4H4 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  749. header SARE_MSGID_HEX30 MESSAGEID =~ /<[A-Z0-9]{30}\$[0-9a-z]{9}\@/
  750. describe SARE_MSGID_HEX30 Message-ID has ratware pattern (HEXHEXHEX$9x9@)
  751. score SARE_MSGID_HEX30 1.666
  752. #counts SARE_MSGID_HEX30 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  753. #max SARE_MSGID_HEX30 18s/0h of 619677 corpus (318875s/300802h RM) 09/11/05
  754. #counts SARE_MSGID_HEX30 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  755. #max SARE_MSGID_HEX30 235s/0h of 47809 corpus (43224s/4585h MY) 07/27/05
  756. #counts SARE_MSGID_HEX30 0s/0h of 15713 corpus (7767s/7946h FT) 05/14/06
  757. #max SARE_MSGID_HEX30 2s/0h of 6924 corpus (1403s/5521h ft) 07/27/05
  758. #counts SARE_MSGID_HEX30 0s/0h of 38374 corpus (14893s/23481h JH-SA3.0rc1) 08/18/04
  759. #counts SARE_MSGID_HEX30 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  760. header SARE_MSGID_SPAM_DOMN0 MESSAGEID =~ /\bjeanvaljean\.com/i
  761. describe SARE_MSGID_SPAM_DOMN0 Message ID implies possible spammer relay
  762. score SARE_MSGID_SPAM_DOMN0 1.666
  763. #stype SARE_MSGID_SPAM_DOMN0 spamg
  764. #hist SARE_MSGID_SPAM_DOMN0 Created by Bob Menschel Mar 22 2004
  765. #hist SARE_MSGID_SPAM_DOMN0 Removed moosq.com, since now in specific.cf
  766. #counts SARE_MSGID_SPAM_DOMN0 0s/0h of 298277 corpus (136400s/161877h RM) 06/06/05
  767. #max SARE_MSGID_SPAM_DOMN0 1s/0h of 274235 corpus (109066s/165169h RM) 05/15/05
  768. #counts SARE_MSGID_SPAM_DOMN0 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  769. #counts SARE_MSGID_SPAM_DOMN0 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  770. #counts SARE_MSGID_SPAM_DOMN0 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  771. header MSGID_SPAM_ALPHA_NUM MESSAGEID =~ /<[A-Z]{7}-000[0-9]{10}\@[a-z]*>/
  772. header __SARE_RECV_LOCALHOST Received =~ /LOCALHOST/
  773. header __SARE_MSGID_SUSP2 MESSAGEID =~ /\<[A-Z]{5,15}\-\d{10,25}\@[a-z]+\>/
  774. meta SARE_MSGID_SUSP2 __SARE_MSGID_SUSP2 && !__SARE_RECV_LOCALHOST && !MSGID_SPAM_ALPHA_NUM
  775. describe SARE_MSGID_SUSP2 Message-Id is <LETTERS-digits@letters>
  776. score SARE_MSGID_SUSP2 3.000
  777. #hist SARE_MSGID_SUSP2 Loren Wilton, LW_BOGUS_MSGID6
  778. #hist SARE_MSGID_SUSP2 Broadened Aug 2004 by Jesse Houwing, with ham-evading exclude
  779. #V300 SARE_MSGID_SUSP2 strong overlap with MSGID_SPAM_ALPHA_NUM
  780. #counts SARE_MSGID_SUSP2 0s/0h of 274235 corpus (109066s/165169h RM) 05/15/05
  781. #alone SARE_MSGID_SUSP2 174s/0h of 114271 corpus (81068s/33203h RM) 01/15/05
  782. #max SARE_MSGID_SUSP2 9187s/0h of 115925 corpus (94616s/21309h RM) 05/01/04
  783. #counts SARE_MSGID_SUSP2 0s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  784. #max SARE_MSGID_SUSP2 6s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  785. #counts SARE_MSGID_SUSP2 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  786. #max SARE_MSGID_SUSP2 187s/0h of 17050 corpus (14617s/2433h MY) 08/08/04
  787. #counts SARE_MSGID_SUSP2 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  788. #counts SARE_MSGID_SUSP2 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  789. #####################################################################################
  790. # SARE Received Header Rules
  791. ######## ###################### ##################################################
  792. header SARE_HELO_AOLID Received =~ /helo=aol\.com ident=/
  793. describe SARE_HELO_AOLID Spam passed through apparent spammer relay
  794. score SARE_HELO_AOLID 0.611
  795. #counts SARE_HELO_AOLID 0s/0h of 273595 corpus (108821s/164774h RM) 05/13/05
  796. #max SARE_HELO_AOLID 10s/0h of 114241 corpus (81067s/33174h RM) 01/15/05
  797. #counts SARE_HELO_AOLID 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  798. #counts SARE_HELO_AOLID 0s/0h of 17050 corpus (14617s/2433h MY) 08/08/04
  799. #counts SARE_HELO_AOLID 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  800. #counts SARE_HELO_AOLID 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  801. header SARE_HELO_MAILUSER Received =~ /helo=MailUser\)/i
  802. describe SARE_HELO_MAILUSER Received header has possible spamsign
  803. score SARE_HELO_MAILUSER 1.111
  804. #stype SARE_HELO_MAILUSER spamp
  805. #hist SARE_HELO_MAILUSER Created by Bob Menschel May 31 2004
  806. #counts SARE_HELO_MAILUSER 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  807. #max SARE_HELO_MAILUSER 12s/0h of 298277 corpus (136400s/161877h RM) 06/06/05
  808. #counts SARE_HELO_MAILUSER 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  809. #counts SARE_HELO_MAILUSER 0s/0h of 17050 corpus (14617s/2433h MY) 08/08/04
  810. #counts SARE_HELO_MAILUSER 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  811. #counts SARE_HELO_MAILUSER 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  812. header SARE_RECV_ADDR2 Received =~ /^from \[\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\]\n/
  813. describe SARE_RECV_ADDR2 Received header missing a FQDN, IP only.
  814. score SARE_RECV_ADDR2 0.100
  815. #counts SARE_RECV_ADDR2 0s/0h of 89541 corpus (67467s/22074h RM) 05/28/04
  816. #counts SARE_RECV_ADDR2 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  817. #counts SARE_RECV_ADDR2 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  818. #counts SARE_RECV_ADDR2 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  819. header SARE_RECV_ADDR3 Received =~ /^from \(.?\[.?\].?\)\b/
  820. describe SARE_RECV_ADDR3 Received header contains an empty Recieved IP.
  821. score SARE_RECV_ADDR3 0.100
  822. #counts SARE_RECV_ADDR3 0s/0h of 89541 corpus (67467s/22074h RM) 05/28/04
  823. #counts SARE_RECV_ADDR3 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  824. #counts SARE_RECV_ADDR3 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  825. #counts SARE_RECV_ADDR3 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  826. header SARE_RECV_ADDR4 Received =~ /^from unknown \(\w+ \w+\)\b/
  827. describe SARE_RECV_ADDR4 Received contains unknown FQDN with possible HELO.
  828. score SARE_RECV_ADDR4 0.100
  829. #counts SARE_RECV_ADDR4 0s/0h of 89541 corpus (67467s/22074h RM) 05/28/04
  830. #counts SARE_RECV_ADDR4 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  831. #counts SARE_RECV_ADDR4 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  832. #counts SARE_RECV_ADDR4 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  833. header __SARE_RECV_CHAR_DASHS Received =~ /---/
  834. header __SARE_RECV_CHAR_DOTS Received =~ /\.\./
  835. meta SARE_RECV_CHAR_DSHDT __SARE_RECV_CHAR_DASHS && __SARE_RECV_CHAR_DOTS
  836. describe SARE_RECV_CHAR_DSHDT Strange dashes and dots in received line
  837. score SARE_RECV_CHAR_DSHDT 0.500
  838. #counts SARE_RECV_CHAR_DSHDT 0s/0h of 273595 corpus (108821s/164774h RM) 05/13/05
  839. #max SARE_RECV_CHAR_DSHDT 7s/0h of 114241 corpus (81067s/33174h RM) 01/15/05
  840. #counts SARE_RECV_CHAR_DSHDT 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  841. #max SARE_RECV_CHAR_DSHDT 2s/0h of 38398 corpus (14914s/23484h JH) 08/14/04 TM2 SA3.0-pre2
  842. #counts SARE_RECV_CHAR_DSHDT 0s/0h of 17050 corpus (14617s/2433h MY) 08/08/04
  843. #counts SARE_RECV_CHAR_DSHDT 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  844. #counts SARE_RECV_CHAR_DSHDT 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  845. header SARE_RECV_ESMTP Received =~ /^from \(?:unknown|\d+\.\d+\.\d+\.\d+\) \(\s+\) by \s+ with esmtp; /
  846. describe SARE_RECV_ESMTP Received header has forged lowercase 'esmtp' relay
  847. score SARE_RECV_ESMTP 0.100
  848. #counts SARE_RECV_ESMTP 0s/0h of 89541 corpus (67467s/22074h RM) 05/28/04
  849. #counts SARE_RECV_ESMTP 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  850. #counts SARE_RECV_ESMTP 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  851. #counts SARE_RECV_ESMTP 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  852. header SARE_RECV_LOCALHOST Received =~ /localhosts\.txt/i
  853. describe SARE_RECV_LOCALHOST fingerprint
  854. score SARE_RECV_LOCALHOST 1.111
  855. #stype SARE_RECV_LOCALHOST spamp
  856. #hist SARE_RECV_LOCALHOST Alex Broens, June 2005
  857. #counts SARE_RECV_LOCALHOST 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  858. #max SARE_RECV_LOCALHOST 77s/0h of 271461 corpus (129860s/141601h RM) 06/12/05
  859. #counts SARE_RECV_LOCALHOST 0s/0h of 10629 corpus (5847s/4782h CT) 09/18/05
  860. #counts SARE_RECV_LOCALHOST 0s/0h of 7500 corpus (1767s/5733h ft) 09/18/05
  861. header SARE_RECV_RANDOM Received =~ /helo[ =].{1,30}<rnddg/i
  862. describe SARE_RECV_RANDOM Spam contains random string in received header
  863. score SARE_RECV_RANDOM 4.000
  864. #stype SARE_RECV_RANDOM spamggg
  865. #hist SARE_RECV_RANDOM Created by Bob Menschel Nov 02 2004
  866. #counts SARE_RECV_RANDOM 0s/0h of 327690 corpus (159737s/167953h RM) 07/27/05
  867. #max SARE_RECV_RANDOM 80s/0h of 196708 corpus (96197s/100511h RM) 02/21/05
  868. #counts SARE_RECV_RANDOM 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  869. #counts SARE_RECV_RANDOM 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  870. #counts SARE_RECV_RANDOM 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  871. #counts SARE_RECV_RANDOM 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  872. header SARE_RECV_RND_DATE Received =~ /RND_DATE/i
  873. describe SARE_RECV_RND_DATE Spam passed through iswest.net relay
  874. score SARE_RECV_RND_DATE 1.666
  875. #stype SARE_RECV_RND_DATE spamg
  876. #counts SARE_RECV_RND_DATE 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  877. #max SARE_RECV_RND_DATE 9s/0h of 268479 corpus (127479s/141000h RM) 06/17/05
  878. #counts SARE_RECV_RND_DATE 0s/0h of 54072 corpus (16898s/37174h JH-3.01) 02/18/05
  879. #counts SARE_RECV_RND_DATE 0s/0h of 22942 corpus (17234s/5708h MY) 05/14/06
  880. #max SARE_RECV_RND_DATE 1s/0h of 47809 corpus (43224s/4585h MY) 07/27/05
  881. #counts SARE_RECV_RND_DATE 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  882. #counts SARE_RECV_RND_DATE 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  883. header SARE_RECV_RND_NUMBER Received =~ /RND_NUMBER/i
  884. describe SARE_RECV_RND_NUMBER Spam passed through iswest.net relay
  885. score SARE_RECV_RND_NUMBER 1.666
  886. #stype SARE_RECV_RND_NUMBER spamg
  887. #counts SARE_RECV_RND_NUMBER 0s/0h of 273595 corpus (108821s/164774h RM) 05/13/05
  888. #max SARE_RECV_RND_NUMBER 2s/0h of 120459 corpus (71363s/49096h RM) 02/12/05
  889. #counts SARE_RECV_RND_NUMBER 0s/0h of 54072 corpus (16898s/37174h JH-3.01) 02/18/05
  890. #counts SARE_RECV_RND_NUMBER 0s/0h of 26184 corpus (22793s/3391h MY) 02/16/05
  891. #counts SARE_RECV_RND_NUMBER 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  892. #counts SARE_RECV_RND_NUMBER 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  893. header SARE_RECV_SUSP_2 Received =~ /from\s+[A-Z0-9]+\s+\(\[10\.2\.202\.25\]\)\s+by\s+[A-Z0-9]+\.[a-z]+/
  894. describe SARE_RECV_SUSP_2 Spammer sign in headers
  895. score SARE_RECV_SUSP_2 1.666
  896. #hist SARE_RECV_SUSP_2 LW_RATWARE1
  897. #counts SARE_RECV_SUSP_2 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  898. #max SARE_RECV_SUSP_2 69s/0h of 114271 corpus (81068s/33203h RM) 01/15/05
  899. #counts SARE_RECV_SUSP_2 31s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  900. #max SARE_RECV_SUSP_2 124s/0h of 38398 corpus (14914s/23484h JH) 08/14/04 TM2 SA3.0-pre2
  901. #counts SARE_RECV_SUSP_2 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  902. #max SARE_RECV_SUSP_2 1s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  903. #counts SARE_RECV_SUSP_2 0s/0h of 13303 corpus (7429s/5874h CT) 05/14/06
  904. #max SARE_RECV_SUSP_2 8s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  905. #counts SARE_RECV_SUSP_2 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  906. header SARE_RECV_TRADVALUES Received =~ /\btraditionalvalues\.org/i
  907. describe SARE_RECV_TRADVALUES From or passed through spammer/unreliable domain
  908. score SARE_RECV_TRADVALUES 3.333
  909. #stype SARE_RECV_TRADVALUES spamgg
  910. #hist SARE_RECV_TRADVALUES RM_hr_tradvalues
  911. #counts SARE_RECV_TRADVALUES 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  912. #max SARE_RECV_TRADVALUES 97s/0h of 271461 corpus (129860s/141601h RM) 06/12/05
  913. #counts SARE_RECV_TRADVALUES 0s/0h of 18651 corpus (16120s/2531h MY) 08/29/04
  914. #counts SARE_RECV_TRADVALUES 0s/0h of 38751 corpus (15270s/23481h JH-SA3.0rc1) 08/30/04
  915. #counts SARE_RECV_TRADVALUES 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  916. #counts SARE_RECV_TRADVALUES 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  917. header SARE_RECV_VIPLIST Received =~ /\b(?:viplist\.us|\[216.74.127.234\])/
  918. describe SARE_RECV_VIPLIST Email comes from known spammer system
  919. score SARE_RECV_VIPLIST 4.000
  920. #stype SARE_RECV_VIPLIST spamggg
  921. #hist SARE_RECV_VIPLIST Created by Bob Menschel Sep 29 2004
  922. #counts SARE_RECV_VIPLIST 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  923. #max SARE_RECV_VIPLIST 255s/0h of 400432 corpus (178148s/222284h RM) 03/31/05
  924. #counts SARE_RECV_VIPLIST 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  925. #counts SARE_RECV_VIPLIST 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  926. #counts SARE_RECV_VIPLIST 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  927. #counts SARE_RECV_VIPLIST 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  928. header SARE_RECV_WITH_X2 Received =~ / with with /
  929. describe SARE_RECV_WITH_X2 Spam identified by typo in received header
  930. score SARE_RECV_WITH_X2 1.666
  931. #stype SARE_RECV_WITH_X2 spamp
  932. #counts SARE_RECV_WITH_X2 0s/0h of 56796 corpus (32203s/24593h RM) 07/25/04
  933. #max SARE_RECV_WITH_X2 341s/0h of 100795 corpus (82099s/18696h) 02/16/04
  934. #counts SARE_RECV_WITH_X2 0s/1h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  935. #counts SARE_RECV_WITH_X2 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  936. #max SARE_RECV_WITH_X2 4s/0h of 17050 corpus (14617s/2433h MY) 08/08/04
  937. #counts SARE_RECV_WITH_X2 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  938. #counts SARE_RECV_WITH_X2 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  939. header SARE_RECV_XACTRIX Received =~ /\b(?:accutra|xactrix)\.com/i
  940. describe SARE_RECV_XACTRIX From/through probable spammer system
  941. score SARE_RECV_XACTRIX 2.500
  942. #stype SARE_RECV_XACTRIX spamg
  943. #hist SARE_RECV_XACTRIX Created by Bob Menschel Sep 03 2004
  944. #counts SARE_RECV_XACTRIX 0s/0h of 280812 corpus (109490s/171322h RM) 05/05/05
  945. #max SARE_RECV_XACTRIX 11s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  946. #counts SARE_RECV_XACTRIX 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  947. #counts SARE_RECV_XACTRIX 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  948. #max SARE_RECV_XACTRIX 21s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  949. #counts SARE_RECV_XACTRIX 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  950. #counts SARE_RECV_XACTRIX 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  951. #####################################################################################
  952. # SARE Received Header IP Address Rules
  953. ######## ###################### ##################################################
  954. header SARE_RECV_IP_004078 Received =~ /\[4\.78\.193\.\d{1,3}\]/
  955. describe SARE_RECV_IP_004078 Spam passed through possible spammer relay
  956. score SARE_RECV_IP_004078 1.666
  957. #hist SARE_RECV_IP_004078 Created by Bob Menschel Feb 5 2005 from Spam-L information
  958. #note SARE_RECV_IP_004078 CWIE, LLC
  959. #counts SARE_RECV_IP_004078 0s/0h of 95095 corpus (59680s/35415h RM) 02/05/05
  960. #counts SARE_RECV_IP_004078 0s/0h of 54840 corpus (17664s/37176h JH-3.01) 03/13/05
  961. #counts SARE_RECV_IP_004078 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  962. #max SARE_RECV_IP_004078 397s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  963. #counts SARE_RECV_IP_004078 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  964. #counts SARE_RECV_IP_004078 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  965. header SARE_RECV_IP_038112147 Received =~ /\[38\.112\.147\.\d{1,3}\]/
  966. describe SARE_RECV_IP_038112147 Spam passed through possible spammer relay
  967. score SARE_RECV_IP_038112147 1.111
  968. #stype SARE_RECV_IP_038112147 spamp
  969. #hist SARE_RECV_IP_038112147 Created by Bob Menschel, Feb 19 2005, from Spam-L posting
  970. #counts SARE_RECV_IP_038112147 0s/0h of 327690 corpus (159737s/167953h RM) 07/27/05
  971. #max SARE_RECV_IP_038112147 66s/0h of 283497 corpus (129933s/153564h RM) 03/08/05
  972. #counts SARE_RECV_IP_038112147 0s/0h of 54840 corpus (17664s/37176h JH-3.01) 03/13/05
  973. #counts SARE_RECV_IP_038112147 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  974. #max SARE_RECV_IP_038112147 3s/0h of 27758 corpus (24297s/3461h MY) 02/27/05
  975. #counts SARE_RECV_IP_038112147 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  976. #counts SARE_RECV_IP_038112147 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  977. header SARE_RECV_IP_062023 Received =~ /\[62\.23\.133\.(?:19[2-9]|2\d{2})\]/
  978. describe SARE_RECV_IP_062023 Passed through possible spammer relay or source
  979. score SARE_RECV_IP_062023 1.111
  980. #stype SARE_RECV_IP_062023 spamp
  981. #hist SARE_RECV_IP_062023 Created by Bob Menschel Feb 10 2005 from Spam-L info
  982. #note SARE_RECV_IP_062023 E-Mail-Vision
  983. #counts SARE_RECV_IP_062023 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  984. #max SARE_RECV_IP_062023 22s/0h of 400432 corpus (178148s/222284h RM) 03/31/05
  985. #counts SARE_RECV_IP_062023 0s/0h of 54179 corpus (17002s/37177h JH-3.01) 03/01/05
  986. #counts SARE_RECV_IP_062023 0s/0h of 27758 corpus (24297s/3461h MY) 02/27/05
  987. #counts SARE_RECV_IP_062023 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  988. #counts SARE_RECV_IP_062023 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  989. header SARE_RECV_IP_064069032 Received =~ /\[64\.69\.32\.\d{1,3}\]/
  990. describe SARE_RECV_IP_064069032 Spam passed through possible spammer relay
  991. score SARE_RECV_IP_064069032 1.111
  992. #stype SARE_RECV_IP_064069032 spamp
  993. #hist SARE_RECV_IP_064069032 Created by Bob Menschel Aug 07 2005
  994. #counts SARE_RECV_IP_064069032 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  995. #max SARE_RECV_IP_064069032 13s/0h of 689155 corpus (348140s/341015h RM) 09/18/05
  996. #counts SARE_RECV_IP_064069032 0s/0h of 10629 corpus (5847s/4782h CT) 09/18/05
  997. #counts SARE_RECV_IP_064069032 0s/0h of 7500 corpus (1767s/5733h ft) 09/18/05
  998. header SARE_RECV_IP_064095 Received =~ /\[64\.95\.199\.\d{1,3}\]/
  999. describe SARE_RECV_IP_064095 Spam passed through probable spammer relay
  1000. score SARE_RECV_IP_064095 1.666
  1001. #stype SARE_RECV_IP_064095 spamg
  1002. #hist SARE_RECV_IP_064095 Created by Bob Menschel Apr 17 2004
  1003. #counts SARE_RECV_IP_064095 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  1004. #max SARE_RECV_IP_064095 3s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  1005. #counts SARE_RECV_IP_064095 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  1006. #max SARE_RECV_IP_064095 22s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  1007. #counts SARE_RECV_IP_064095 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  1008. #max SARE_RECV_IP_064095 2s/0h of 17050 corpus (14617s/2433h MY) 08/08/04
  1009. #counts SARE_RECV_IP_064095 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1010. #counts SARE_RECV_IP_064095 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1011. header SARE_RECV_IP_064192082 received =~ /\[64\.192\.8[23]\.\d{1,3}\]/
  1012. describe SARE_RECV_IP_064192082 Spam passed through possible spammer relay
  1013. score SARE_RECV_IP_064192082 1.111
  1014. #stype SARE_RECV_IP_064192082 spamp
  1015. #hist SARE_RECV_IP_064192082 Created by Bob Menschel Jan 29 2005 from info supplied via Spam-L
  1016. #counts SARE_RECV_IP_064192082 0s/0h of 98352 corpus (59690s/38662h RM) 01/29/05
  1017. #counts SARE_RECV_IP_064192082 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  1018. #counts SARE_RECV_IP_064192082 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  1019. #max SARE_RECV_IP_064192082 39s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  1020. #counts SARE_RECV_IP_064192082 0s/0h of 11052 corpus (6614s/4438h CT) 03/10/05
  1021. #counts SARE_RECV_IP_064192082 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1022. header SARE_RECV_IP_064192191 Received =~ /\[64\.192\.191\.\d{1,3}\]/
  1023. describe SARE_RECV_IP_064192191 Passed through possible spammer relay or source
  1024. score SARE_RECV_IP_064192191 1.111
  1025. #stype SARE_RECV_IP_064192191 spamp
  1026. #hist SARE_RECV_IP_064192191 Created by Bob Menschel Jan 14 2005, info thanks to Paul Howarth, Dec 14 2004
  1027. #note SARE_RECV_IP_064192191 WCG.NET, On The Net, Inc., onthenethosting.us
  1028. #counts SARE_RECV_IP_064192191 0s/0h of 280812 corpus (109490s/171322h RM) 05/05/05
  1029. #max SARE_RECV_IP_064192191 31s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  1030. #counts SARE_RECV_IP_064192191 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  1031. #counts SARE_RECV_IP_064192191 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  1032. #counts SARE_RECV_IP_064192191 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1033. #counts SARE_RECV_IP_064192191 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1034. header SARE_RECV_IP_065205157 received =~ /\[65\.205\.157\.(?:19[2-9]|2[01]\d|22[0-3])\]/
  1035. describe SARE_RECV_IP_065205157 Spam passed through possible spammer relay
  1036. score SARE_RECV_IP_065205157 1.111
  1037. #stype SARE_RECV_IP_065205157 spamp
  1038. #hist SARE_RECV_IP_065205157 Created by Bob Menschel Jan 29 2005 from info supplied via Spam-L
  1039. #counts SARE_RECV_IP_065205157 0s/0h of 273595 corpus (108821s/164774h RM) 05/13/05
  1040. #max SARE_RECV_IP_065205157 7s/0h of 238550 corpus (112525s/126025h RM) 02/28/05
  1041. #counts SARE_RECV_IP_065205157 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  1042. #counts SARE_RECV_IP_065205157 0s/0h of 22942 corpus (17234s/5708h MY) 05/14/06
  1043. #max SARE_RECV_IP_065205157 67s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  1044. #counts SARE_RECV_IP_065205157 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1045. #counts SARE_RECV_IP_065205157 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1046. header SARE_RECV_IP_066063 Received =~ /\[66\.63\.178\.\d{1,3}\]/
  1047. describe SARE_RECV_IP_066063 Passed through possible spammer relay or source
  1048. score SARE_RECV_IP_066063 1.111
  1049. #stype SARE_RECV_IP_066063 spamp
  1050. #hist SARE_RECV_IP_066063 Created by Bob Menschel Feb 10 2005 from Spam-L info
  1051. #counts SARE_RECV_IP_066063 0s/0h of 118836 corpus (71083s/47753h RM) 02/10/05
  1052. #counts SARE_RECV_IP_066063 0s/0h of 54179 corpus (17002s/37177h JH-3.01) 03/01/05
  1053. #counts SARE_RECV_IP_066063 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  1054. #max SARE_RECV_IP_066063 21s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  1055. #counts SARE_RECV_IP_066063 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1056. #counts SARE_RECV_IP_066063 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1057. header SARE_RECV_IP_066114a Received =~ /\[66\.114\.217\.\d{1,3}\]/
  1058. describe SARE_RECV_IP_066114a Spam passed through possible spammer relay
  1059. score SARE_RECV_IP_066114a 1.111
  1060. #stype SARE_RECV_IP_066114a spamp
  1061. #hist SARE_RECV_IP_066114a Created by Bob Menschel Feb 5 2005 from Spam-L info
  1062. #note SARE_RECV_IP_066114a SW FLA Hosting
  1063. #counts SARE_RECV_IP_066114a 0s/0h of 275081 corpus (134226s/140855h RM) 05/30/05
  1064. #max SARE_RECV_IP_066114a 27s/0h of 238550 corpus (112525s/126025h RM) 02/28/05
  1065. #counts SARE_RECV_IP_066114a 0s/0h of 54840 corpus (17664s/37176h JH-3.01) 03/13/05
  1066. #counts SARE_RECV_IP_066114a 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  1067. #max SARE_RECV_IP_066114a 13s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  1068. #counts SARE_RECV_IP_066114a 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1069. #counts SARE_RECV_IP_066114a 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1070. header SARE_RECV_IP_066159017 Received =~ /\[66\.159\.17\.8[4-7]\]/
  1071. describe SARE_RECV_IP_066159017 Spam passed through possible spammer relay
  1072. score SARE_RECV_IP_066159017 1.666
  1073. #hist SARE_RECV_IP_066159017 Created by Bob Menschel Aug 07 2005
  1074. #counts SARE_RECV_IP_066159017 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1075. #max SARE_RECV_IP_066159017 219s/0h of 689155 corpus (348140s/341015h RM) 09/18/05
  1076. #counts SARE_RECV_IP_066159017 0s/0h of 10629 corpus (5847s/4782h CT) 09/18/05
  1077. #counts SARE_RECV_IP_066159017 0s/0h of 7500 corpus (1767s/5733h ft) 09/18/05
  1078. header SARE_RECV_IP_066248154 Received =~ /\[66\.248\.154\.\d{1,3}\]/
  1079. describe SARE_RECV_IP_066248154 Spam passed through possible spammer relay
  1080. score SARE_RECV_IP_066248154 1.111
  1081. #stype SARE_RECV_IP_066248154 spamp
  1082. #hist SARE_RECV_IP_066248154 Created by Bob Menschel May 14 2005
  1083. #note SARE_RECV_IP_066248154 Advanced Dedicated Database Servers LLC
  1084. #counts SARE_RECV_IP_066248154 0s/0h of 268479 corpus (127479s/141000h RM) 06/17/05
  1085. #max SARE_RECV_IP_066248154 8s/0h of 274235 corpus (109066s/165169h RM) 05/15/05
  1086. #counts SARE_RECV_IP_066248154 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1087. #counts SARE_RECV_IP_066248154 0s/0h of 22942 corpus (17234s/5708h MY) 05/14/06
  1088. #max SARE_RECV_IP_066248154 17s/0h of 47809 corpus (43224s/4585h MY) 07/27/05
  1089. header SARE_RECV_IP_069060122 Received =~ /\[69\.60\.122\.\d{1,3}\]/
  1090. describe SARE_RECV_IP_069060122 Spam passed through possible spammer relay
  1091. score SARE_RECV_IP_069060122 1.111
  1092. #stype SARE_RECV_IP_069060122 spamp
  1093. #hist SARE_RECV_IP_069060122 Created by Bob Menschel May 14 2005
  1094. #counts SARE_RECV_IP_069060122 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1095. #counts SARE_RECV_IP_069060122 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1096. #counts SARE_RECV_IP_069060122 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  1097. #max SARE_RECV_IP_069060122 3s/0h of 47809 corpus (43224s/4585h MY) 07/27/05
  1098. header SARE_RECV_IP_070096177 Received =~ /\[70\.96\.177\.\d{1,3}\]/
  1099. describe SARE_RECV_IP_070096177 Spam passed through possible spammer relay
  1100. score SARE_RECV_IP_070096177 1.666
  1101. #stype SARE_RECV_IP_070096177 spamp
  1102. #hist SARE_RECV_IP_070096177 Created by Bob Menschel May 14 2005
  1103. #note SARE_RECV_IP_070096177 Broadlogix
  1104. #counts SARE_RECV_IP_070096177 0s/0h of 327690 corpus (159737s/167953h RM) 07/27/05
  1105. #max SARE_RECV_IP_070096177 78s/0h of 275081 corpus (134226s/140855h RM) 05/30/05
  1106. #counts SARE_RECV_IP_070096177 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1107. #counts SARE_RECV_IP_070096177 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1108. #counts SARE_RECV_IP_070096177 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  1109. #max SARE_RECV_IP_070096177 48s/0h of 47283 corpus (43206s/4077h MY) 06/05/05
  1110. header SARE_RECV_IP_081019 Received =~ /\[81\.19\.24[0-3]\.\d{1,3}\]/
  1111. describe SARE_RECV_IP_081019 Passed through possible spammer relay or source
  1112. score SARE_RECV_IP_081019 0.678
  1113. #hist SARE_RECV_IP_081019 Created by Bob Menschel Jul 27 2004
  1114. #counts SARE_RECV_IP_081019 0s/0h of 273595 corpus (108821s/164774h RM) 05/13/05
  1115. #max SARE_RECV_IP_081019 15s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  1116. #counts SARE_RECV_IP_081019 3s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  1117. #counts SARE_RECV_IP_081019 0s/0h of 47809 corpus (43224s/4585h MY) 07/27/05
  1118. #max SARE_RECV_IP_081019 4s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  1119. #counts SARE_RECV_IP_081019 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1120. #counts SARE_RECV_IP_081019 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1121. header SARE_RECV_IP_081095 Received =~ /\[81\.95\.(?:3[2-9]|4[0-7])\.\d{1,3}\]/
  1122. describe SARE_RECV_IP_081095 Spam passed through possible spammer relay
  1123. score SARE_RECV_IP_081095 0.555
  1124. #stype SARE_RECV_IP_081095 spamp
  1125. #hist SARE_RECV_IP_081095 Created by Bob Menschel June 12 2004
  1126. #counts SARE_RECV_IP_081095 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  1127. #max SARE_RECV_IP_081095 3s/0h of 66087 corpus (40127s/25960h RM) 09/11/04
  1128. #counts SARE_RECV_IP_081095 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  1129. #max SARE_RECV_IP_081095 1s/0h of 17050 corpus (14617s/2433h MY) 08/08/04
  1130. #counts SARE_RECV_IP_081095 0s/0h of 38398 corpus (14914s/23484h JH) 08/14/04 TM2 SA3.0-pre2
  1131. #counts SARE_RECV_IP_081095 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1132. #counts SARE_RECV_IP_081095 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1133. header SARE_RECV_IP_200203050 Received =~ /\[200\.203\.50\.160\]/
  1134. describe SARE_RECV_IP_200203050 Spam passed through possible spammer relay
  1135. score SARE_RECV_IP_200203050 0.555
  1136. #stype SARE_RECV_IP_200203050 spamp
  1137. #hist SARE_RECV_IP_200203050 Created by Bob Menschel, Feb 19 2005, from Spam-L posting
  1138. #counts SARE_RECV_IP_200203050 0s/0h of 174366 corpus (98964s/75402h RM) 02/18/05
  1139. #counts SARE_RECV_IP_200203050 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1140. #counts SARE_RECV_IP_200203050 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1141. header SARE_RECV_IP_202064 Received =~ /\[202\.22\.(?:24[89]|25[01])\.\d{1,3}\]/
  1142. describe SARE_RECV_IP_202064 Spam passed through possible spammer relay
  1143. score SARE_RECV_IP_202064 1.111
  1144. #stype SARE_RECV_IP_202064 spamp
  1145. #hist SARE_RECV_IP_202064 Created by Bob Menschel Apr 25 2004
  1146. #counts SARE_RECV_IP_202064 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  1147. #max SARE_RECV_IP_202064 12s/0h of 114241 corpus (81067s/33174h RM) 01/15/05
  1148. #counts SARE_RECV_IP_202064 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  1149. #counts SARE_RECV_IP_202064 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  1150. #max SARE_RECV_IP_202064 4s/0h of 17050 corpus (14617s/2433h MY) 08/08/04
  1151. #counts SARE_RECV_IP_202064 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1152. #counts SARE_RECV_IP_202064 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1153. header SARE_RECV_IP_206248152 Received =~ /\[206\.248\.153\.\d{1,3}\]/
  1154. describe SARE_RECV_IP_206248152 Spam passed through possible spammer relay
  1155. score SARE_RECV_IP_206248152 0.617
  1156. #ham SARE_RECV_IP_206248152 confirmed (1)
  1157. #hist SARE_RECV_IP_206248152 Created by Bob Menschel May 14 2005
  1158. #note SARE_RECV_IP_206248152 3zCanada-GTA1
  1159. #counts SARE_RECV_IP_206248152 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1160. #max SARE_RECV_IP_206248152 19s/0h of 298277 corpus (136400s/161877h RM) 06/06/05
  1161. #counts SARE_RECV_IP_206248152 0s/0h of 22942 corpus (17234s/5708h MY) 05/14/06
  1162. #max SARE_RECV_IP_206248152 2s/0h of 47283 corpus (43206s/4077h MY) 06/05/05
  1163. #counts SARE_RECV_IP_206248152 0s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  1164. header SARE_RECV_IP_207182 Received =~ /\[207\.182\.146\.(?:19[2-9]|2\d{2})\]/
  1165. describe SARE_RECV_IP_207182 Passed through possible spammer relay or source
  1166. score SARE_RECV_IP_207182 1.666
  1167. #stype SARE_RECV_IP_207182 spamp
  1168. #hist SARE_RECV_IP_207182 Created by Bob Menschel Feb 10 2005 from Spam-L info
  1169. #counts SARE_RECV_IP_207182 0s/0h of 327690 corpus (159737s/167953h RM) 07/27/05
  1170. #max SARE_RECV_IP_207182 26s/0h of 400432 corpus (178148s/222284h RM) 03/31/05
  1171. #counts SARE_RECV_IP_207182 71s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  1172. #counts SARE_RECV_IP_207182 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  1173. #max SARE_RECV_IP_207182 57s/0h of 27758 corpus (24297s/3461h MY) 02/27/05
  1174. #counts SARE_RECV_IP_207182 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1175. #counts SARE_RECV_IP_207182 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1176. header SARE_RECV_IP_208048182 Received =~ /\[208.48\.182\.\d{1,3}\]/
  1177. describe SARE_RECV_IP_208048182 Spam passed through possible spammer relay
  1178. score SARE_RECV_IP_208048182 1.111
  1179. #stype SARE_RECV_IP_208048182 spamp
  1180. #hist SARE_RECV_IP_208048182 Created by Bob Menschel May 14 2005
  1181. #counts SARE_RECV_IP_208048182 0s/0h of 274235 corpus (109066s/165169h RM) 05/15/05
  1182. #counts SARE_RECV_IP_208048182 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1183. #counts SARE_RECV_IP_208048182 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  1184. #max SARE_RECV_IP_208048182 43s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  1185. header SARE_RECV_IP_211049 Received =~ /\[211\.49\.185\.\d{1,3}\]/
  1186. describe SARE_RECV_IP_211049 Spam passed through possible spammer relay
  1187. score SARE_RECV_IP_211049 0.555
  1188. #stype SARE_RECV_IP_211049 spamp
  1189. #counts SARE_RECV_IP_211049 0s/0h of 327690 corpus (159737s/167953h RM) 07/27/05
  1190. #max SARE_RECV_IP_211049 3s/0h of 97268 corpus (79437s/17831h RM) 01/24/04
  1191. #counts SARE_RECV_IP_211049 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  1192. #counts SARE_RECV_IP_211049 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  1193. #counts SARE_RECV_IP_211049 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1194. header SARE_RECV_IP_212164 Received =~ /\[212\.164\.1(?:6[4-9]|[78]\d|9[01])\.\d{1,3}\]/
  1195. describe SARE_RECV_IP_212164 Spam passed through possible spammer relay
  1196. score SARE_RECV_IP_212164 0.555
  1197. #stype SARE_RECV_IP_212164 spamp
  1198. #hist SARE_RECV_IP_212164 Created by Bob Menschel May 31 2004
  1199. #counts SARE_RECV_IP_212164 0s/0h of 273595 corpus (108821s/164774h RM) 05/13/05
  1200. #max SARE_RECV_IP_212164 1s/0h of 238550 corpus (112525s/126025h RM) 02/28/05
  1201. #counts SARE_RECV_IP_212164 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  1202. #counts SARE_RECV_IP_212164 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1203. #counts SARE_RECV_IP_212164 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1204. header SARE_RECV_IP_216055133 Received =~ /\[216\.55\.133\.\d{1,3}\]/
  1205. describe SARE_RECV_IP_216055133 Spam passed through possible spammer relay
  1206. score SARE_RECV_IP_216055133 1.111
  1207. #stype SARE_RECV_IP_216055133 spamp
  1208. #hist SARE_RECV_IP_216055133 Created by Bob Menschel May 14 2005
  1209. #counts SARE_RECV_IP_216055133 0s/0h of 274235 corpus (109066s/165169h RM) 05/15/05
  1210. #counts SARE_RECV_IP_216055133 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1211. #counts SARE_RECV_IP_216055133 0s/0h of 15713 corpus (7767s/7946h FT) 05/14/06
  1212. #max SARE_RECV_IP_216055133 1s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1213. #counts SARE_RECV_IP_216055133 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  1214. #max SARE_RECV_IP_216055133 15s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  1215. #####################################################################################
  1216. # SARE Reply-To Header Rules
  1217. ######## ###################### ##################################################
  1218. header SARE_REPLY_XACTRIX Reply-To =~ /\b(?:accutra|xactrix)\.com/i
  1219. describe SARE_REPLY_XACTRIX Reply-To email addr to spammer
  1220. score SARE_REPLY_XACTRIX 1.666
  1221. #stype SARE_REPLY_XACTRIX spamg
  1222. #hist SARE_REPLY_XACTRIX Created by Bob Menschel Sep 03 2004
  1223. #counts SARE_REPLY_XACTRIX 0s/0h of 280812 corpus (109490s/171322h RM) 05/05/05
  1224. #max SARE_REPLY_XACTRIX 11s/0h of 115509 corpus (81073s/34436h RM) 01/16/05
  1225. #counts SARE_REPLY_XACTRIX 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  1226. #counts SARE_REPLY_XACTRIX 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  1227. #max SARE_REPLY_XACTRIX 21s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  1228. #counts SARE_REPLY_XACTRIX 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1229. #counts SARE_REPLY_XACTRIX 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1230. #####################################################################################
  1231. # SARE User-Agent rules
  1232. ######## ###################### ##################################################
  1233. #####################################################################################
  1234. # SARE To/Cc Destination rules
  1235. ######## ###################### ##################################################
  1236. header SARE_TOCC_MAILDOMN ToCc =~ /(?:client|recipient)\@(?:smtpdomain|maildomain)\.(?:com|net)/i
  1237. describe SARE_TOCC_MAILDOMN Destination identifies this as a virus bounce
  1238. score SARE_TOCC_MAILDOMN 1.666
  1239. #stype SARE_TOCC_MAILDOMN vbg
  1240. #hist SARE_TOCC_MAILDOMN Created by Bob Menschel Mar 28 2004
  1241. #counts SARE_TOCC_MAILDOMN 0s/0h of 238550 corpus (112525s/126025h RM) 02/28/05
  1242. #max SARE_TOCC_MAILDOMN 5s/0h of 60630 corpus (35509s/25121h RM) 08/11/04
  1243. #counts SARE_TOCC_MAILDOMN 1s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  1244. #counts SARE_TOCC_MAILDOMN 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  1245. #counts SARE_TOCC_MAILDOMN 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1246. #counts SARE_TOCC_MAILDOMN 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1247. header SARE_TOCC_SPAMWORD0 ToCc =~ /(?:alter-ego|Mailing-Boxes|ReMailer|User-info)\@/i
  1248. describe SARE_TOCC_SPAMWORD0 Addressed to bogus email address
  1249. score SARE_TOCC_SPAMWORD0 0.444
  1250. #hist SARE_TOCC_SPAMWORD0 Removed Mailinglist May 14 2005
  1251. #counts SARE_TOCC_SPAMWORD0 0s/0h of 274235 corpus (109066s/165169h RM) 05/15/05
  1252. #max SARE_TOCC_SPAMWORD0 2s/3h of 196688 corpus (96191s/100497h RM) 02/21/05
  1253. #counts SARE_TOCC_SPAMWORD0 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  1254. #counts SARE_TOCC_SPAMWORD0 0s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  1255. #max SARE_TOCC_SPAMWORD0 1s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  1256. #counts SARE_TOCC_SPAMWORD0 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1257. #counts SARE_TOCC_SPAMWORD0 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1258. #####################################################################################
  1259. # SARE X-Mailer Rules
  1260. ######## ###################### ##################################################
  1261. header SARE_XMAIL_BULK2 X-Mailer =~ /(?:Mail2000|Simple Mail Solutions)/i
  1262. describe SARE_XMAIL_BULK2 Uses bulk mailer used by spammers
  1263. score SARE_XMAIL_BULK2 0.100
  1264. #hist SARE_XMAIL_BULK2 Bob Menschel: PSS Bulk Mailer, Calypso; removed OSM Client Feb 7 2005
  1265. #counts SARE_XMAIL_BULK2 0s/0h of 85084 corpus (62489s/22595h RM) 06/08/04
  1266. #counts SARE_XMAIL_BULK2 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  1267. #counts SARE_XMAIL_BULK2 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1268. #counts SARE_XMAIL_BULK2 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1269. header SARE_XMAIL_BULK4 X-Mailer =~ /(?:Master-SMTP)/i
  1270. describe SARE_XMAIL_BULK4 Uses bulk mailer name forged by viruses
  1271. score SARE_XMAIL_BULK4 0.277
  1272. #stype SARE_XMAIL_BULK4 vbp
  1273. #hist SARE_XMAIL_BULK4 Bob Menschel: Master-SMTP
  1274. #counts SARE_XMAIL_BULK4 0s/0h of 114241 corpus (81067s/33174h RM) 01/15/05
  1275. #max SARE_XMAIL_BULK4 5s/0h of 56804 corpus (32211s/24593h RM) 07/25/04
  1276. #counts SARE_XMAIL_BULK4 0s/0h of 32586 corpus (9341s/23245h JH) 06/10/04
  1277. #counts SARE_XMAIL_BULK4 0s/0h of 17050 corpus (14617s/2433h MY) 08/08/04
  1278. #counts SARE_XMAIL_BULK4 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1279. #counts SARE_XMAIL_BULK4 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1280. header SARE_XMAIL_DIRUNIV X-Mailer =~ /Direct Universe/i
  1281. describe SARE_XMAIL_DIRUNIV Apparently uses spam/bulk mailer
  1282. score SARE_XMAIL_DIRUNIV 1.111
  1283. #stype SARE_XMAIL_DIRUNIV spamp
  1284. #hist SARE_XMAIL_DIRUNIV Bob Menschel, May 14 2005
  1285. #counts SARE_XMAIL_DIRUNIV 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1286. #max SARE_XMAIL_DIRUNIV 48s/0h of 327690 corpus (159737s/167953h RM) 07/27/05
  1287. #counts SARE_XMAIL_DIRUNIV 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1288. #counts SARE_XMAIL_DIRUNIV 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1289. #counts SARE_XMAIL_DIRUNIV 0s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  1290. #counts SARE_XMAIL_DIRUNIV 0s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  1291. header SARE_XMAIL_GDI X-Mailer=~/GDI Mailer/
  1292. describe SARE_XMAIL_GDI Ratware mailer
  1293. score SARE_XMAIL_GDI 0.100
  1294. #hist SARE_XMAIL_GDI Bob Menschel, Feb 25 2005
  1295. #counts SARE_XMAIL_GDI 0s/0h of 273595 corpus (108821s/164774h RM) 05/13/05
  1296. #max SARE_XMAIL_GDI 1s/0h of 238550 corpus (112525s/126025h RM) 02/28/05
  1297. #counts SARE_XMAIL_GDI 0s/0h of 54179 corpus (17002s/37177h JH-3.01) 03/01/05
  1298. #counts SARE_XMAIL_GDI 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1299. #counts SARE_XMAIL_GDI 0s/0h of 42275 corpus (34158s/8117h FVGT) 05/15/06
  1300. #max SARE_XMAIL_GDI 1s/0h of 6924 corpus (1403s/5521h ft) 07/27/05
  1301. header SARE_XMAIL_INTERMED X-Mailer =~ /\bIntermedia mail\b/i
  1302. describe SARE_XMAIL_INTERMED possible spamware
  1303. score SARE_XMAIL_INTERMED 0.850
  1304. #hist SARE_XMAIL_INTERMED Alex Broens, June 30 2005
  1305. #counts SARE_XMAIL_INTERMED 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1306. #max SARE_XMAIL_INTERMED 51s/0h of 689155 corpus (348140s/341015h RM) 09/18/05
  1307. #counts SARE_XMAIL_INTERMED 0s/0h of 13303 corpus (7429s/5874h CT) 05/14/06
  1308. #max SARE_XMAIL_INTERMED 1s/0h of 10629 corpus (5847s/4782h CT) 09/18/05
  1309. #counts SARE_XMAIL_INTERMED 0s/0h of 15713 corpus (7767s/7946h FT) 05/14/06
  1310. #max SARE_XMAIL_INTERMED 1s/0h of 6905 corpus (1401s/5504h ft) 07/24/05
  1311. header SARE_XMAIL_LEO X-Mailer =~ /^[A-Z][a-x]+\s[a-z]{2}\s\d\.\d\d\s*$/ # no /i
  1312. score SARE_XMAIL_LEO 2.333
  1313. describe SARE_XMAIL_LEO Spamsign in x-mailer header
  1314. #hist SARE_XMAIL_LEO Loren Wilton, Sept 07, 2005
  1315. #counts SARE_XMAIL_LEO 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1316. #max SARE_XMAIL_LEO 2625s/0h of 689155 corpus (348140s/341015h RM) 09/18/05
  1317. #counts SARE_XMAIL_LEO 0s/0h of 10629 corpus (5847s/4782h CT) 09/18/05
  1318. #counts SARE_XMAIL_LEO 0s/0h of 7500 corpus (1767s/5733h ft) 09/18/05
  1319. header SARE_XMAIL_PHPBulkEmai X-Mailer =~ /PHPBulkEmailer/i
  1320. describe SARE_XMAIL_PHPBulkEmai Apparently uses spam/bulk mailer
  1321. score SARE_XMAIL_PHPBulkEmai 1.111
  1322. #stype SARE_XMAIL_PHPBulkEmai spamp
  1323. #hist SARE_XMAIL_PHPBulkEmai Bob Menschel, Apr 11, 2005, from suggestion by Loren Wilton
  1324. #counts SARE_XMAIL_PHPBulkEmai 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1325. #max SARE_XMAIL_PHPBulkEmai 45s/0h of 275081 corpus (134226s/140855h RM) 05/30/05
  1326. #counts SARE_XMAIL_PHPBulkEmai 0s/0h of 13303 corpus (7429s/5874h CT) 05/14/06
  1327. #max SARE_XMAIL_PHPBulkEmai 1s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1328. #counts SARE_XMAIL_PHPBulkEmai 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1329. #counts SARE_XMAIL_PHPBulkEmai 0s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  1330. #counts SARE_XMAIL_PHPBulkEmai 1s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  1331. #####################################################################################
  1332. # SARE Rules which examine multiple header types
  1333. ######## ###################### ##################################################
  1334. #####################################################################################
  1335. # SARE Miscellaneous and X-Header header rules
  1336. ######## ###################### ##################################################
  1337. header SARE_HEAD_CONT_RNDCONT Content-Transfer-Encoding =~ /CONTENT_ENCODING/i
  1338. describe SARE_HEAD_CONT_RNDCONT Spam passed through iswest.net relay
  1339. score SARE_HEAD_CONT_RNDCONT 1.166
  1340. #counts SARE_HEAD_CONT_RNDCONT 0s/0h of 95112 corpus (59679s/35433h RM) 01/31/05
  1341. #counts SARE_HEAD_CONT_RNDCONT 0s/0h of 54072 corpus (16898s/37174h JH-3.01) 02/18/05
  1342. #counts SARE_HEAD_CONT_RNDCONT 0s/0h of 26184 corpus (22793s/3391h MY) 02/16/05
  1343. #counts SARE_HEAD_CONT_RNDCONT 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1344. #counts SARE_HEAD_CONT_RNDCONT 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1345. header SARE_HEAD_DATE_RNDDATE Date =~ /RND/i
  1346. describe SARE_HEAD_DATE_RNDDATE Spam passed through iswest.net relay
  1347. score SARE_HEAD_DATE_RNDDATE 1.666
  1348. #stype SARE_HEAD_DATE_RNDDATE spamg
  1349. #counts SARE_HEAD_DATE_RNDDATE 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1350. #max SARE_HEAD_DATE_RNDDATE 9s/0h of 268479 corpus (127479s/141000h RM) 06/17/05
  1351. #counts SARE_HEAD_DATE_RNDDATE 0s/0h of 54072 corpus (16898s/37174h JH-3.01) 02/18/05
  1352. #counts SARE_HEAD_DATE_RNDDATE 0s/0h of 26184 corpus (22793s/3391h MY) 02/16/05
  1353. #counts SARE_HEAD_DATE_RNDDATE 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1354. #counts SARE_HEAD_DATE_RNDDATE 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1355. header SARE_HEAD_THRD_ALNUM Thread-Index =~ /ALNUM/
  1356. describe SARE_HEAD_THRD_ALNUM Spam fingerprint in thread index
  1357. score SARE_HEAD_THRD_ALNUM 0.839
  1358. #hist SARE_HEAD_THRD_ALNUM Alex Broens, July 27 2005
  1359. #counts SARE_HEAD_THRD_ALNUM 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1360. #max SARE_HEAD_THRD_ALNUM 51s/0h of 619677 corpus (318875s/300802h RM) 09/11/05
  1361. #counts SARE_HEAD_THRD_ALNUM 0s/0h of 10629 corpus (5847s/4782h CT) 09/18/05
  1362. header SARE_HEAD_TOCC_DEFHNDL All =~ /TO_CC_DEFAULT_HANDLER/i
  1363. describe SARE_HEAD_TOCC_DEFHNDL Spam passed through iswest.net relay
  1364. score SARE_HEAD_TOCC_DEFHNDL 1.166
  1365. #counts SARE_HEAD_TOCC_DEFHNDL 0s/0h of 95112 corpus (59679s/35433h RM) 01/31/05
  1366. #counts SARE_HEAD_TOCC_DEFHNDL 0s/0h of 54072 corpus (16898s/37174h JH-3.01) 02/18/05
  1367. #counts SARE_HEAD_TOCC_DEFHNDL 0s/0h of 26184 corpus (22793s/3391h MY) 02/16/05
  1368. #counts SARE_HEAD_TOCC_DEFHNDL 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1369. #counts SARE_HEAD_TOCC_DEFHNDL 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1370. header SARE_HEAD_XAUTH_WARN2 X-Authentication-Warning =~ /\b[A-Z]{2,5}[a-z]{5,7}[0-9]{2}\b/
  1371. describe SARE_HEAD_XAUTH_WARN2 X-Authentication-Warning: Contains Spam Signature.
  1372. score SARE_HEAD_XAUTH_WARN2 2.500
  1373. #stype SARE_HEAD_XAUTH_WARN2 spamg
  1374. #hist SARE_HEAD_XAUTH_WARN2 Mike Hogsett, Tuesday, May 25, 2004, CSL_X_AUTH_WARN_2
  1375. #counts SARE_HEAD_XAUTH_WARN2 0s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  1376. #max SARE_HEAD_XAUTH_WARN2 46s/0h of 60623 corpus (35501s/25122h RM) 08/11/04
  1377. #counts SARE_HEAD_XAUTH_WARN2 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  1378. #max SARE_HEAD_XAUTH_WARN2 14s/0h of 38398 corpus (14914s/23484h JH) 08/14/04 TM2 SA3.0-pre2
  1379. #counts SARE_HEAD_XAUTH_WARN2 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  1380. #max SARE_HEAD_XAUTH_WARN2 1s/0h of 17050 corpus (14617s/2433h MY) 08/08/04
  1381. #counts SARE_HEAD_XAUTH_WARN2 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1382. #counts SARE_HEAD_XAUTH_WARN2 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1383. header SARE_HEAD_XCANIT1 X-CanItPRO-Stream =~ /^sbw\b/
  1384. describe SARE_HEAD_XCANIT1 Message headers used which identify spam
  1385. score SARE_HEAD_XCANIT1 1.111
  1386. #stype SARE_HEAD_XCANIT1 spamp
  1387. #hist SARE_HEAD_XCANIT1 Enhanced from original SARE_HEAD_HDR_XCANITP rule with help from RoaringPenguin
  1388. #counts SARE_HEAD_XCANIT1 0s/0h of 259338 corpus (110116s/149222h RM) 05/16/05
  1389. #max SARE_HEAD_XCANIT1 7s/0h of 68480 corpus (41098s/27382h RM) 09/18/04
  1390. #counts SARE_HEAD_XCANIT1 0s/0h of 18196 corpus (15673s/2523h MY) 08/16/04
  1391. #counts SARE_HEAD_XCANIT1 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  1392. #counts SARE_HEAD_XCANIT1 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1393. #counts SARE_HEAD_XCANIT1 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1394. header __SARE_HEAD_XCANIT_H exists:X-CanItPRO-Stream
  1395. header __SARE_HEAD_XCANIT_S exists:X-Scanned-By
  1396. meta SARE_HEAD_XCANIT2 __SARE_HEAD_XCANIT_H && !__SARE_HEAD_XCANIT_S
  1397. describe SARE_HEAD_XCANIT2 Incomplete anti-spam headers signifying spam
  1398. score SARE_HEAD_XCANIT2 0.555
  1399. #stype SARE_HEAD_XCANIT2 spamp
  1400. #hist SARE_HEAD_XCANIT2 Created by Bob Menschel Jan 29 2005 from information provided by RoaringPenguin
  1401. #counts SARE_HEAD_XCANIT2 0s/0h of 196688 corpus (96191s/100497h RM) 02/21/05
  1402. #max SARE_HEAD_XCANIT2 2s/0h of 96329 corpus (59684s/36645h RM) 02/04/05
  1403. #counts SARE_HEAD_XCANIT2 0s/0h of 54176 corpus (16997s/37179h JH-3.01) 02/01/05
  1404. #counts SARE_HEAD_XCANIT2 0s/0h of 20489 corpus (17189s/3300h MY) 01/30/05
  1405. #counts SARE_HEAD_XCANIT2 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1406. #counts SARE_HEAD_XCANIT2 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1407. header SARE_HEAD_XM4 ALL =~ /\nX-M-.{4}:/ # usually 4:28:12
  1408. describe SARE_HEAD_XM4 Contains spamsign header
  1409. score SARE_HEAD_XM4 1.111
  1410. #stype SARE_HEAD_XM4 spamp
  1411. #hist SARE_HEAD_XM4 Loren Wilton, June 2005
  1412. #counts SARE_HEAD_XM4 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1413. #max SARE_HEAD_XM4 80s/0h of 689155 corpus (348140s/341015h RM) 09/18/05
  1414. #counts SARE_HEAD_XM4 0s/0h of 47809 corpus (43224s/4585h MY) 07/27/05
  1415. #counts SARE_HEAD_XM4 0s/0h of 10629 corpus (5847s/4782h CT) 09/18/05
  1416. header SARE_HEAD_XMF_AUTHSNDR X-Message-flag =~ /Authentic Sender/i
  1417. describe SARE_HEAD_XMF_AUTHSNDR Headers contains spam sign
  1418. score SARE_HEAD_XMF_AUTHSNDR 1.666
  1419. #stype SARE_HEAD_XMF_AUTHSNDR spamp
  1420. #hist SARE_HEAD_XMF_AUTHSNDR Created by Bob Menschel Jan 29 2005 from idea submitted by Alex Broens
  1421. #counts SARE_HEAD_XMF_AUTHSNDR 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1422. #max SARE_HEAD_XMF_AUTHSNDR 726s/0h of 400432 corpus (178148s/222284h RM) 03/31/05
  1423. #counts SARE_HEAD_XMF_AUTHSNDR 67s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  1424. #counts SARE_HEAD_XMF_AUTHSNDR 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  1425. #max SARE_HEAD_XMF_AUTHSNDR 54s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  1426. #counts SARE_HEAD_XMF_AUTHSNDR 0s/0h of 13303 corpus (7429s/5874h CT) 05/14/06
  1427. #max SARE_HEAD_XMF_AUTHSNDR 89s/0h of 11052 corpus (6614s/4438h CT) 03/10/05
  1428. #counts SARE_HEAD_XMF_AUTHSNDR 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1429. header SARE_HEAD_XPRI_RNDNUM X-Priority =~ /PRIORITY_NUMBER/i
  1430. describe SARE_HEAD_XPRI_RNDNUM Spam passed through iswest.net relay
  1431. score SARE_HEAD_XPRI_RNDNUM 1.666
  1432. #stype SARE_HEAD_XPRI_RNDNUM spamg
  1433. #counts SARE_HEAD_XPRI_RNDNUM 0s/0h of 95112 corpus (59679s/35433h RM) 01/31/05
  1434. #counts SARE_HEAD_XPRI_RNDNUM 0s/0h of 54072 corpus (16898s/37174h JH-3.01) 02/18/05
  1435. #counts SARE_HEAD_XPRI_RNDNUM 0s/0h of 26184 corpus (22793s/3391h MY) 02/16/05
  1436. #counts SARE_HEAD_XPRI_RNDNUM 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1437. #counts SARE_HEAD_XPRI_RNDNUM 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1438. #####################################################################################
  1439. # SARE Rules which identify headers found in email bodies
  1440. ######## ###################### ##################################################
  1441. rawbody SARE_HEAD_BDY_BOUNCES /^Bounces_to: .{1,50}\@/
  1442. describe SARE_HEAD_BDY_BOUNCES Message header suggesting spam in body
  1443. score SARE_HEAD_BDY_BOUNCES 1.666
  1444. #note SARE_HEAD_BDY_BOUNCES Normally valid header currently very popular in spam. Presence in bounced emails strongly suggests bounced spam
  1445. #hist SARE_HEAD_BDY_BOUNCES Bob Menschel, Apr 10 2005
  1446. #counts SARE_HEAD_BDY_BOUNCES 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1447. #max SARE_HEAD_BDY_BOUNCES 433s/0h of 271461 corpus (129860s/141601h RM) 06/12/05
  1448. #counts SARE_HEAD_BDY_BOUNCES 0s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1449. #counts SARE_HEAD_BDY_BOUNCES 0s/1h of 15713 corpus (7767s/7946h FT) 05/14/06
  1450. #max SARE_HEAD_BDY_BOUNCES 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1451. #counts SARE_HEAD_BDY_BOUNCES 0s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  1452. #####################################################################################
  1453. # SARE Rules which examine multiple header types
  1454. ######## ###################### ##################################################
  1455. header __SARE_MULT_FROM_MRS From =~ /"Mrs[\. ][A-Z][a-z]+"/
  1456. header __SARE_MULT_HITHERE Subject =~ /^(?:HELLO|Hello|Hey|Hi)\w{0,8},?(?:Mrs\.)?/
  1457. body __SARE_MULT_PROFILE /(?:on-?line profile|profile (?:is )?on-?line)/
  1458. meta SARE_MULT_SEXCLUB __SARE_MULT_HITHERE && (__SARE_MULT_PROFILE || __SARE_MULT_FROM_MRS)
  1459. describe SARE_MULT_SEXCLUB Adult invitation spam
  1460. score SARE_MULT_SEXCLUB 1.666
  1461. #hist SARE_MULT_SEXCLUB Loren Wilton, Feb 22 2005
  1462. #counts SARE_MULT_SEXCLUB 0s/0h of 173032 corpus (99056s/73976h RM) 05/11/06
  1463. #max SARE_MULT_SEXCLUB 114s/0h of 283497 corpus (129933s/153564h RM) 03/08/05
  1464. #counts SARE_MULT_SEXCLUB 8s/0h of 54179 corpus (17002s/37177h JH-3.01) 03/01/05
  1465. #counts SARE_MULT_SEXCLUB 0s/0h of 22950 corpus (17237s/5713h MY) 05/14/06
  1466. #max SARE_MULT_SEXCLUB 59s/0h of 45478 corpus (41529s/3949h MY) 05/16/05
  1467. #counts SARE_MULT_SEXCLUB 0s/0h of 13303 corpus (7429s/5874h CT) 05/14/06
  1468. #max SARE_MULT_SEXCLUB 22s/0h of 10853 corpus (6391s/4462h CT) 05/16/05
  1469. #counts SARE_MULT_SEXCLUB 0s/0h of 2500 corpus (531s/1969h ft) 05/17/05
  1470. header SARE_MULT_SUBJ ALL =~ /\nSubject:.{10,150}\nSubject:.{10,150}\nSubject:/s
  1471. score SARE_MULT_SUBJ 0.777
  1472. describe SARE_MULT_SUBJ Many subject lines
  1473. #hist SARE_MULT_SUBJ Loren Wilton, June 2005
  1474. #counts SARE_MULT_SUBJ 0s/0h of 619677 corpus (318875s/300802h RM) 09/11/05
  1475. #max SARE_MULT_SUBJ 40s/0h of 271461 corpus (129860s/141601h RM) 06/12/05
  1476. #counts SARE_MULT_SUBJ 0s/0h of 5653 corpus (1019s/4634h ft) 06/04/05
  1477. #counts SARE_MULT_SUBJ 0s/0h of 47283 corpus (43206s/4077h MY) 06/05/05
  1478. #counts SARE_MULT_SUBJ 0s/0h of 55848 corpus (18671s/37177h JH-3.01) 06/10/05
  1479. #counts SARE_MULT_SUBJ 0s/0h of 10629 corpus (5847s/4782h CT) 09/18/05
  1480. # EOF