drug_spam 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408
  1. # -*- mode: spamassassin -*-
  2. # various drugs match these rules
  3. # blarson, 2004-05-10 -> lists --pasc 04/05/11
  4. body DRUGSPAM /(\b|_|\d)(c.?(i|\?|\=ed|\xed).?a.?l.?[ig].?s|v.?(i|1|=ed|\xed|l).?(?:a|\@|\/\\).?g.?r.?(?:a|\@|\/\\)|v.?i.?c.?o.?d.?i.?n|h.?y.?d.?r.?o.?c.?o.?d.?o.?n.?e|[xz].?a.?n.?a.\?x|p.?r.?o.?z.?a.?c|hgh)(\b|_\d)/i
  5. describe DRUGSPAM drug spam
  6. score DRUGSPAM 3
  7. # blarson, 2004-05-10 -> lists --pasc 04/05/11
  8. header DRUGSPAM2 subject =~ /(\b|_|\d)(c.?(i|\?|\=ed|\xed).?a.?l.?[ig].?s|v\.?(i|1|=ed).?(?:a|\@|\/\\).?g.?r.?(?:a|\/\\)|v.?i.?c.?o.?d.?i.?n|h.?y.?d.?r.?o.?c.?o.?d.?o.?n.?e|\[xz].?a.?n.?a.?x|p.?r.?o.?z.?a.?c|hgh)(\d|\b|_)/i
  9. describe DRUGSPAM2 more drug spam
  10. score DRUGSPAM2 3
  11. # More drugs! --pasc 2003-05-13 blarson 2007-09-12
  12. body DRUGSPAM3 /\b(v.?i.?o.?x|x.?a.?n.?(a|@).?x|p.?h.?e.?n.?t.?r.?e.?m.?i.?n.?e|v.?i.?a.?g.?r.?a)/i
  13. describe DRUGSPAM3 yet more drugs
  14. score DRUGSPAM3 1.5
  15. # blarson 2007-09-13
  16. full MURPHY_DRUGS1 /\bv.?i.?a+.?[gdk]+.?r+.?a+\b/i
  17. describe MURPHY_DRUGS1 Viagra
  18. score MURPHY_DRUGS1 1.5
  19. body MURPHY_DRUGS2 /v.?i.?o.?x/i
  20. describe MURPHY_DRUGS2 Viox
  21. score MURPHY_DRUGS2 0.5
  22. body MURPHY_DRUGS3 /F.?i.?o.?r.?i.?c.?e.?e.?t/i
  23. describe MURPHY_DRUGS3 Fioriceet
  24. score MURPHY_DRUGS3 0.5
  25. body MURPHY_DRUGS4 /P.?h.?e.?n.?t.?(r.?e|e.?r).?m.?i.?n.?e/i
  26. describe MURPHY_DRUGS4 Phentremine
  27. score MURPHY_DRUGS4 0.5
  28. body MURPHY_DRUGS5 /v.?a.?l.?i.?u.?m/i
  29. describe MURPHY_DRUGS5 Valium
  30. score MURPHY_DRUGS5 0.5
  31. body MURPHY_DRUGS6 /x.?(a|@).?n.?a.?x/i
  32. describe MURPHY_DRUGS6 Xanax
  33. score MURPHY_DRUGS6 0.5
  34. body MURPHY_DRUGS7 /v.?i.?c.?o.?d.?i.?n/i
  35. describe MURPHY_DRUGS7 Vicodin
  36. score MURPHY_DRUGS7 0.5
  37. body MURPHY_DRUGS8 /h.?y.?d.?r.?o.?c.?o.?d.?o.?n.?e/i
  38. describe MURPHY_DRUGS8 Hydrocodone
  39. score MURPHY_DRUGS8 0.5
  40. body MURPHY_DRUGS_REL1 /medication/i
  41. score MURPHY_DRUGS_REL1 0.5
  42. body MURPHY_DRUGS_REL2 /P.?r.?e.?s.?c.?r.?i.?p.?t.?i.?o.?n/i
  43. score MURPHY_DRUGS_REL2 0.5
  44. body MURPHY_DRUGS_REL3 /health product/i
  45. score MURPHY_DRUGS_REL3 0.5
  46. body MURPHY_DRUGS_REL4 /drug.*expensive/i
  47. score MURPHY_DRUGS_REL4 0.5
  48. body MURPHY_DRUGS_REL5 /p.?h.?a.?r.?m.?a.?c.?e.?u.?t.?i.?c.?a.?l/i
  49. score MURPHY_DRUGS_REL5 0.5
  50. body MURPHY_DRUGS_REL6 /formula/i
  51. score MURPHY_DRUGS_REL6 0.2
  52. body MURPHY_DRUGS_REL7 /dosing/i
  53. score MURPHY_DRUGS_REL7 0.2
  54. body MURPHY_DRUGS_REL8 /patch/i
  55. score MURPHY_DRUGS_REL8 0.02
  56. body MURPHY_DRUGS_REL9 /\bpills?\b/i
  57. score MURPHY_DRUGS_REL9 1
  58. body MURPHY_DRUGS_REL10 /bacteria/i
  59. score MURPHY_DRUGS_REL10 0.1
  60. body MURPHY_DRUGS_REL11 /antidote/i
  61. score MURPHY_DRUGS_REL11 0.1
  62. meta MURPHY_DRUGS_META1 (MURPHY_DRUGS1 + MURPHY_DRUGS2 + MURPHY_DRUGS3 + MURPHY_DRUGS4 + MURPHY_DRUGS5 + MURPHY_DRUGS6 + MURPHY_DRUGS7 + MURPHY_DRUGS8 + MURPHY_DRUGS_REL1 + MURPHY_DRUGS_REL2 + MURPHY_DRUGS_REL3 + MURPHY_DRUGS_REL4 + MURPHY_DRUGS_REL5 + MURPHY_DRUGS_REL9 + MURPHY_DRUGS_REL10 + MURPHY_DRUGS_REL11) > 1
  63. score MURPHY_DRUGS_META1 3.0
  64. meta MURPHY_DRUGS_META2 (MURPHY_DRUGS1 + MURPHY_DRUGS2 + MURPHY_DRUGS3 + MURPHY_DRUGS4 + MURPHY_DRUGS5 + MURPHY_DRUGS6 + MURPHY_DRUGS7 + MURPHY_DRUGS8 + MURPHY_DRUGS_REL1 + MURPHY_DRUGS_REL2 + MURPHY_DRUGS_REL3 + MURPHY_DRUGS_REL4 + MURPHY_DRUGS_REL5 + MURPHY_DRUGS_REL11 + MURPHY_DRUGS_REL10 + MURPHY_DRUGS_REL9) > 2
  65. score MURPHY_DRUGS_META2 4.0
  66. meta MURPHY_DRUGS_META3 (MURPHY_DRUGS_REL6 + MURPHY_DRUGS_REL7 + MURPHY_DRUGS_REL8 + MURPHY_DRUGS_REL9) > 1
  67. score MURPHY_DRUGS_META3 2.0
  68. meta DRUGS_STOCK_MIMEOLE (__MIMEOLE_1106 && __MAILER_OL_5510)
  69. header __MIMEOLE_1106 X-MimeOLE =~ /^Produced By Microsoft MimeOLE V6.00.2800.1106$/
  70. header __MAILER_OL_5510 X-Mailer =~ /^Microsoft Office Outlook, Build 11.0.5510$/
  71. describe DRUGS_STOCK_MIMEOLE Stock-spam forged headers found (5510)
  72. score DRUGS_STOCK_MIMEOLE 3
  73. # More penis enlargement --pasc 061012
  74. body M_BIGGER1 /gain \d inches/i
  75. score M_BIGGER1 5
  76. # cjwatson, 2003/02/26
  77. body AMAZINGHEALTHGROUP /www\.amazinghealthgroup\.com/
  78. describe AMAZINGHEALTHGROUP Amazing Spam Group
  79. score AMAZINGHEALTHGROUP 4.0
  80. # joy, 2003-09-16
  81. body PHARMACYSPAM1 /http:\/\/www.pharmacy[^\.]+.biz/i
  82. describe PHARMACYSPAM1 pharmacy spam 1
  83. score PHARMACYSPAM1 4
  84. header PHARMACYSPAM2 Subject =~ /Best Discount Online Drugs/i
  85. describe PHARMACYSPAM2 pharmacy spam 2
  86. score PHARMACYSPAM2 4
  87. # joy, 2003-11-09
  88. body PRESCRIPTION /prescription/i
  89. describe PRESCRIPTION pharmacy spam
  90. score PRESCRIPTION 2
  91. body PHARMACY /pharmacy/i
  92. describe PHARMACY pharmacy spam
  93. score PHARMACY 1
  94. body FDAAPPROVEDB /(USA?|FDA)( official)?[ -]approved/
  95. describe FDAAPPROVEDB US FDA approved pharmacy spam
  96. score FDAAPPROVEDB 2
  97. header FDAAPPROVEDS Subject =~ /(USA?|FDA)( official)?[ -]approved/
  98. describe FDAAPPROVEDS US FDA approved pharmacy spam
  99. score FDAAPPROVEDS 3
  100. # cjwatson, 2004-01-16
  101. body MYPILLSOURCE /mypillsource\.com/
  102. describe MYPILLSOURCE mypillsource.com spam
  103. score MYPILLSOURCE 4
  104. # cjwatson, 2004-02-18
  105. body HGH_PROVEN /HGH is proven to help/
  106. describe HGH_PROVEN Yeah, sure
  107. score HGH_PROVEN 3
  108. # cjwatson, 2004-02-22
  109. header CIALGS Subject =~ /sug?per viagrga/
  110. describe CIALGS Viagra derivative spam
  111. score CIALGS 4
  112. # cjwatson, 2004-03-01, 2004-03-05
  113. body LAY_THE_PIPE /the next (chick|girl) you (screw|bang)/
  114. describe LAY_THE_PIPE Viagra spam
  115. score LAY_THE_PIPE 4
  116. # blarson 2004-04-13
  117. body SPERM /\bsperm/i
  118. describe SPERM fertility spam
  119. score SPERM 3
  120. # blarson 2005-06-04
  121. header MED subject =~ /\b(?:doctor|health|medic(?:al|ine))$/
  122. describe MED medical spam
  123. score MED 2
  124. # blarson 2006-09-25 2007-09-18
  125. body HOODIA /\bh.?oo+dia/i
  126. describe HOODIA weight loss scam
  127. score HOODIA 3
  128. # dla 2007-02-27
  129. header PHARRMACY subject =~ /Can+adian\s+Fami+ly\s+Phar+macy/i
  130. describe PHARRMACY pharrmacy can't spell
  131. score PHARRMACY 3
  132. # don 2007-05-20
  133. body MALEENHANCE /male\s+enhan[c\(]e/i
  134. describe MALEENHANCE Enhanced males
  135. score MALEENHANCE 2
  136. # blarson 2007-05-20
  137. body SIZEMAT /\b(?:Does Size|size does) Matter\b/i
  138. describe SIZEMAT size matters spam
  139. score SIZEMAT 2
  140. # blarson 2007-08-30
  141. body SIZEMAT /\bsizematters\.cn\b/i
  142. describe SIZEMAT size matters
  143. score SIZEMAT 4
  144. # blarson 2007-06-19
  145. body ENLARGEPL /\benlargeplus\b/
  146. describe ENLARGEPL more penis spam
  147. score ENLARGEPL 3
  148. # blarson 2007-07-19
  149. body PHYSCONS /^After this we will require a physician consultation/
  150. describe PHYSCONS more php spam
  151. score PHYSCONS 3
  152. # blarson 2007-08-12
  153. body GETABIG /\bwww\.getabiggercock\.net\b/i
  154. describe GETABIG cock spam
  155. score GETABIG 4
  156. # blarson 2007-09-11
  157. body PHYLET /\bphysician (?:letter|questions?)\b/i
  158. describe PHYLET physician letter
  159. score PHYLET 3.5
  160. # blarson 2007-09-11
  161. body PEN1S /\bpen1s\b/i
  162. describe PEN1S pen1s
  163. score PEN1S 3
  164. # blarson 2007-09-12
  165. body PILLS /\bx\s+\d+\s+pills\b/
  166. describe PILLS pills spam
  167. score PILLS 3.5
  168. # blarson 2007-09-13
  169. body PFIZER /\bP\W?f\W?i\W?z\W?e\W?r\b/i
  170. describe PFIZER Pfizer
  171. score PFIZER 3
  172. # blarson 2007-09-19
  173. body WONDERCUM /\bwondercum\b/i
  174. describe WONDERCUM more drug spam
  175. score WONDERCUM 4
  176. # blarson 2007-09-21
  177. body DRUGSTORE /\bdrug store\b/i
  178. describe DRUGSTORE drug store
  179. score DRUGSTORE 3
  180. # zobel 2007-10-11
  181. header LETACCOUNT subject =~ /LET\:account,password,shop/i
  182. describe LETACCOUNT Random Let:account spam
  183. score LETACCOUNT 7
  184. # blarson 2007-10-16
  185. body HGH /\bh(?:uman)?g(?:rowth)?h(?:ormone)?\b/i
  186. describe HGH hgh
  187. score HGH 2
  188. # blarson 2007-10-23
  189. body BRACKVIAG /\b\[V(?:\]\w\[)?I(?:\]\w\[)?A(?:\]\w\[)?G(?:\]\w\[)?R(?:]\w\[)?A\]\b/i
  190. describe BRACKVIAG [viagra]
  191. score BRACKVIAG 4
  192. # blarson 2007-11-09
  193. header PHARMORD subject =~ /\bPharmacy\b.*\border\b/i
  194. describe PHARMORD Pharmacy order
  195. score PHARMORD 4
  196. # blarson 2007-11-12
  197. body XTRASIZE /\bXtra\s*Size\b/i
  198. describe XTRASIZE more penis spam
  199. score XTRASIZE 2
  200. # blarson 2007-11-14
  201. header BIGORGAN subject =~ /\b(?:macro|sizeable|bouffant|colossal|elephantin|largish|gargantuan|vast|ample|broad|huge|size|significant|oversized?|monolithic|hulky|voluminous|whopping|enormous|titanic|large|extended|bulky|humongous|outsize|puffy|prodigious|extended|sized|monstrous|wide|thumping|stupendous|gigantic|big|important|mountainous|immense|extended|plumping|tremendous|extensive|massive|sizable|conspicuous|prodigious|jumbo|monster|greatest|scale|immence|spacious|ranging|giant|biggish|outsized|whacking|fat|capacious|grand|intense|monumental|rangy|prominent|cosmic|bigger|muscular|obvious|overlarge|enlarged|super|larger|increase|stronger|sized?|your|great|longest|true|harder|tiny|small|gaining|ultimate|amazing|long|huge)\s+(?:body part|member|phallus|fuckstick|sc?hlong|d[il]c?\W?k|shaft|p\W?e\W?n[i!l]s|erectile|organ|c[o0]ck[s5]?|rods?|ejaculation|erections?|in\sgirth|one-eyed|penile|w[i1][l1]+y|magic wand|masculinity|PE|pleasure machine|herbal|stick|male|d\Wi\Wc\Wk|boner|pecker)\b/i
  202. describe BIGORGAN big body part
  203. score BIGORGAN 3
  204. # blarson 2007-12-02
  205. header BKWORD subject =~ /\b\{word\}\b/
  206. describe BKWORD {word}
  207. score BKWORD 3
  208. # blarson 2007-12-10
  209. header MEDS subject =~ /\bmed(?:ication)?s?\b/i
  210. describe MEDS meds
  211. score MEDS 2
  212. # blarson 2007-12-10
  213. header STEROIDS subject =~ /\bsteroids?\b/i
  214. describe STEROIDS steroids
  215. score STEROIDS 3
  216. # blarson 2007-12-11
  217. header HEALTH subject =~ /\bhealth\b/i
  218. describe HEALTH health
  219. score HEALTH 0.2
  220. # blarson 2007-12-18
  221. body MEDS2 /\bmed\W?s?\b/
  222. describe MEDS2 meds
  223. score MEDS2 2
  224. # blarson 2007-12-21
  225. full VPXL /\bVPXL\b/
  226. describe VPXL VPXL
  227. score VPXL 3
  228. # blarson 2007-12-22
  229. full TRIBULUS /\b(?:Tribulus terrestris|Albizzia lebbeck|Argyrerin speciosa|Valeriana wallichii|Soya protein)\b/i
  230. describe TRIBULUS Tribulus terrestris|Albizzia lebbeck
  231. score TRIBULUS 3
  232. # blarson 2007-12-24
  233. body VITAMINE /\bVitamin E\b/
  234. describe VITAMINE Vitamin E
  235. score VITAMINE 3
  236. # blarson 2007-12-24
  237. full PENISSIZE /\b(?:penis|dick|cock)\s+(?:size|enlargement|width|girth)\b/i
  238. describe PENISSIZE penis size
  239. score PENISSIZE 3
  240. # blarson 2007-12-24
  241. full INVOICE /\bPharmacy Invoice\b/i
  242. describe INVOICE Pharmacy Invoice
  243. score INVOICE 3
  244. # blarson 2008-01-01
  245. header S_E_X subject =~ /\bs\W?e\W?(?:x|[>)]\W?[<(])(?:\b|u)/i
  246. describe S_E_X s.e.x
  247. score S_E_X 3
  248. # blarson 2008-01-11
  249. header EDSET subject =~ /\bEDSET\b/
  250. describe EDSET EDSET
  251. score EDSET 4
  252. # blarson 2008-01-12
  253. full CANADIAN /\bCanadian.*pharmacy\b/i
  254. describe CANADIAN Canadian pharmacy
  255. score CANADIAN 3
  256. # blarson 2008-01-14
  257. header INVOICE subject =~ /\b(?:Invoice|order)\s+.?\s*\d+/i
  258. describe INVOICE invoice number
  259. score INVOICE 3
  260. # blarson 2008-02-02
  261. header PHARMA subject =~ /\bpharm/i
  262. describe PHARMA pharma
  263. score PHARMA 2
  264. # blarson 2008-02-18
  265. full UITRAM /\bUItram\b/i
  266. describe UITRAM UItram
  267. score UITRAM 3
  268. # blarson 2008-02-19
  269. full ANTIED /\banti(?:-|\s*)EDs?\b/i
  270. describe ANTIED anti-ED
  271. score ANTIED 4
  272. # blarson 2008-02-19
  273. full BUYDRUGS /\bbuydrugs\b/i
  274. describe BUYDRUGS buydrugs
  275. score BUYDRUGS 4
  276. # blarson 2008-02-21
  277. body POPTHIS /\bpop\s+this\b/i
  278. describe POPTHIS pop this
  279. score POPTHIS 3
  280. # blarson 2008-02-24
  281. full BLUEPILL /\bblue?.?(?:pil+|med)/i
  282. describe BLUEPILL blue pill
  283. score BLUEPILL 3
  284. # blarson 2008-02-26
  285. full NAKEDWOM /\bNaked\s*Wom[ae]n/i
  286. describe NAKEDWOM Naked Woman
  287. score NAKEDWOM 2
  288. # blarson 2008-02-26
  289. full HERBALSUP /\bherbal supplement/i
  290. describe HERBALSUP herbal supplement
  291. score HERBALSUP 3
  292. # blarson 2008-02-06
  293. full VIA4 /viagra/i
  294. describe VIA4 viagra in the middle of a word
  295. score VIA4 3
  296. # blarson 2008-03-14
  297. full LEGALWEED /\bLegal WEED\b/
  298. describe LEGALWEED Legal WEED
  299. score LEGALWEED 4
  300. # blarson 2008-03-21
  301. header PUSSY subject =~ /\b\_?(?:pussy|cum|naked|g(?:-|\s*)?spot|nipple|manhood|one(?:-|\s+)eyed\s+monster|orgasm|breast|vibrator|p[e3]n[il]s|porno|Tittie|flaccid|shagging|stripping|hottie|orgasmic|capsule|climax|lace|horny|Pink|wet|foreplay|Playboy|playmate|bares|blowing|sucking|Embrace|courtship|love|bosom|exposed|freaky|motel|credit card|pleasure|Ejaculation|herba[l1]|dosage|\d+\s+mg|escort|Penetration|orgie|pecker|crotch|Pocket Rocket|Sports Illustrated|RAMBO|bees|Corpora Cavernosa|rod|luv|see-through|College|jetsetting|Shaven|1\d and|inches|lovemaking|bedroom|Purchase|kung fu|saucy|Buy|laid|Obama|dementia|No weight|pill|Pacify|screening|regret|brad pitt|undressed|freebie|Discount|wonderdrug|Rock|diet|racy|boob|ramming|Loving|bang|coming|tablet|customer|highs|limited edition|Shock attack|topless|CS\s*3|babe|kinky|clothes|bed(?:ding)?|fame|hurt her|LOTTERY|year old|hot action|Ladies man|\d+ inche?|creamy|Click Here|wicked|Shy|touch herself|Shopping|timepiece|Shop|Dealer|watches|luxury|flaunting|dressed|brand|Popular|bling|luxuries|order processing|hobbies|wealth|lucky|draw|thi\b|flesh|Bacheelor|Doctoraate|Exquisite|bottle|money|millionaire|price|famous|branded|Affordable|bucks|Grape Seed|Antioxidant|fashion|Antiox|Free Radical|wonder power|Paris Hilton|wrist|Pamper|Red hot|Nicolas Cage|sale|blood|scientist|sin|Steve Jobs|hot girl|Lordly|dosage|Prada|shoes|pilz|che+ap|babymaker|pornstar|chixx|shed|pound|Investment|E-gold|swagger|LNH|weener|shipping|billing|oem|PhD|university|accredited|degree|hi|from me|monster\.com|discreet|hey|Maxim|Erection|Webmaster|sell|Career|xxx\w*|medicine|medication|health|buying|Rx|pharm|medicinal|Perscription|debt|Cam|Medical|foto|Narcotic|meddiscount|crazy|japanese|Chat|babe|winner|sure cure|European|agency|vocanc(?:ie|y)|CareerBuilder|pilule|CorelDRAW|shag|cumming|Employer|jobseeker|NoPrescripiton|remedy|cheaper|SpaB|fedex|luksus)s?\_?\b/i
  302. describe PUSSY various spammy words in subject
  303. score PUSSY 2
  304. # blarson 2008-03-25
  305. header FDA subject =~ /\bFDA\b/
  306. describe FDA FDA
  307. score FDA 3
  308. # blarson 2008-09-05
  309. body CANADIANRX /\bCanadian(?:\s|_)+(?:Rx|med)/i
  310. describe CANADIANRX Canadian RxMedz
  311. score CANADIANRX 4
  312. # blarson 2009-06-19
  313. # don da30 is a subtype of m68k; don't match it.
  314. body MEDS35 /\b(?:meds?|shop|pill|gen|ca|via|cu|ko|me|ba|bu|ku|ma)\d\d\b/
  315. describe MEDS35 meds35
  316. score MEDS35 4