url_spam 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579
  1. # -*- mode: spamassassin -*-
  2. # joy, 2003-06-29
  3. body ORIENTSKY /orient-sky\.com/
  4. describe ORIENTSKY Japanese spam
  5. score ORIENTSKY 4
  6. # joy, 2003-07-06
  7. body PACHETES /www\.pachetes\.com/
  8. describe PACHETES Spanish spam
  9. score PACHETES 4
  10. # cjwatson, 2003/07/12
  11. body NO_MORE_ACCENT /www\.no-more-accent\.com/
  12. describe NO_MORE_ACCENT No More Accent spam
  13. score NO_MORE_ACCENT 4
  14. # joy, 2003-08-15
  15. header FETHARD Subject =~ /fethard.biz/i
  16. describe FETHARD Spam from Fethard.biz
  17. score FETHARD 4
  18. # joy, 2003-10-21, 2003-10-31
  19. body PHARMACYSPAM3 /http:\/\/www\.rx(salenow|ville)\.biz/i
  20. describe PHARMACYSPAM3 pharmacy spam 3
  21. score PHARMACYSPAM3 4
  22. # cjwatson, 2004-01-13
  23. # blarson, any number 2004-04-01
  24. # blarson, more ajustmets 2004-04-03
  25. body HREF_NNNN /www\.\d{3,5}hosting\.com/
  26. describe HREF_NNNN www.NNNNhosting.com spam
  27. score HREF_NNNN 3
  28. # cjwatson, 2004-02-16
  29. body SOCCER_MOMS /www\.soccer-moms\.biz/
  30. describe SOCCER_MOMS Porn spam
  31. score SOCCER_MOMS 4
  32. # cjwatson, 2004-02-22
  33. body MRSM_TILO /mrsm-tilo\.com/
  34. describe MRSM_TILO Medical spam
  35. score MRSM_TILO 4
  36. # cjwatson, 2004-02-27
  37. body FAST_ACTING /fast-acting\.com/
  38. describe FAST_ACTING Viagra spam
  39. score FAST_ACTING 4
  40. # blarson 2004-04-04
  41. body COMCLICKPH /com-click\.com\.ph/
  42. describe COMCLICKPH PH spam gang
  43. score COMCLICKPH 4
  44. # blarson 2004-05-01
  45. body MEDS675 /(675meds|medsarergreat)\.com/i
  46. describe MEDS675 More drug spam
  47. score MEDS675 3
  48. # blarson 2004-04-30
  49. body ERHOME /erhome\.com/i
  50. describe ERHOME loan spammer
  51. score ERHOME 3
  52. # blarson 2005-04-27
  53. body CANDYHOS /\.(?:candyhos\.com|(?:mycountry|polty|make4u)\.cc|puchiphoto\.org|purepure\.org)\//i
  54. describe CANDYHOS spams from korea, hosts in japan
  55. score CANDYHOS 5
  56. # blarson 2005-12-08
  57. # don 2007-11-21 -- combine other rule; increment score
  58. # don 2009-02-17 -- increase score even more; ditch http
  59. uri GEOCITIES /geocities/i
  60. describe GEOCITIES geocities uri
  61. score GEOCITIES 3
  62. # blarson 2005-12-24
  63. body EMPTYURL /\bhttp:\/\/(?:www\.)?$/i
  64. describe EMPTYURL empty URL
  65. score EMPTYURL 1.5
  66. # blarson 2006-02-06
  67. body AMPRO /www\.amateurprovideo\.info/i
  68. describe AMPRO bug submitting spammer
  69. score AMPRO 5
  70. # blarson 2007-04-03
  71. body IMAGESHACK /\/img\d+\.imageshack\.us\//i
  72. describe IMAGESHACK shack attack
  73. score IMAGESHACK 3.5
  74. # dla 2007-04-03
  75. header MSOUTLOOK x-mailer =~ /Microsoft\s+Outlook/i
  76. describe MSOUTLOOK Microsoft Outlook
  77. score MSOUTLOOK 0
  78. meta SHACKOUTLOOK IMAGESHACK && MSOUTLOOK
  79. describe SHACKOUTLOOK shack'ed to outlook
  80. score SHACKOUTLOOK 2
  81. # blarson 2007-04-09
  82. body UNSUBG /\bwww\.guiaartistica\.com\.ar\b/
  83. describe UNSUBG spamming bts with unsubscribe messages
  84. score UNSUBG 14
  85. # blarson 2007-05-14
  86. body IMGCLOSET /\bhttp\:\/\/.*\b((image(closet|thrust|hosting)|mypicshare|tinypic|fileanchor|imgspot)\.com|bilder-hosting\.de|saunalahti\.fi|upload2\.net|imagehost\.ro)\b/i
  87. describe IMGCLOSET closet spammer
  88. score IMGCLOSET 3.5
  89. # blarson 2007-05-17
  90. body TROUBLEDE /\bhttp\:\/\/www\.TroubleAgent\.de\b/
  91. describe TROUBLEDE troubleagent.de spam
  92. score TROUBLEDE 3.5
  93. # don 2007-05-24
  94. body BESTLOANS /www.bestmortloans.com/i
  95. describe BESTLOANS Best loans url
  96. score BESTLOANS 2
  97. # blarson 2007-07-22 2007-09-12
  98. body PENPRO /\@(?:penmailpro|OnsetIng|openprotection|NearOut|SuperOnset|medicalgloveonline|YourOnset|GreatGloveCell|thegloveworks|asiafriendworld|NaturalImprove|charmshine|healthinsweb)\.info\b/i
  99. describe PENPRO penmailpro spam
  100. score PENPRO 3.5
  101. # blarson 2007-09-05 2007-09-11 2009-04-12
  102. body WWWCN /\b(?:www\.|https?\:.*)(\w|-|\.)+\.cn\b/i
  103. describe WWWCN chinese web site
  104. score WWWCN 3
  105. # cjwatson, 2002/04/04
  106. body EMAILOFFER /www\.emailoffer\.us/
  107. describe EMAILOFFER Gibberish HTML spammers
  108. score EMAILOFFER 4.0
  109. # cjwatson, 2002/04/08
  110. body JUSTYAK /www\.JustYak\.com/
  111. describe JUSTYAK JustSpam
  112. score JUSTYAK 4.0
  113. # blarson 2007-09-10
  114. body SIZMATZ /\bsize-matterz\.com\b/i
  115. describe SIZMATZ size matterz
  116. score SIZMATZ 3
  117. # blarson 2007-09-10
  118. body EMAGX /\bhttp\:\/\/emagx\.net\b/i
  119. describe EMAGX wondercum spammer
  120. score EMAGX 3.5
  121. # blarson 2007-09-13
  122. body FREENFL /\bhttp\:\/\/freeNFLtracker\.com\b/i
  123. describe FREENFL nfl spam
  124. score FREENFL 3
  125. # blarson 2007-09-13
  126. body SPAMARREST /\bhttp\:\/\/www\.spamarrest\.com\b/
  127. describe SPAMARREST forwards thier spam problem
  128. score SPAMARREST 4
  129. # blarson 2007-09-14
  130. body FROMAD /\bhttp\:\/\/(?:budhipps|fromad|conavel|cliensy|comnoe|mybudshop)\.com\b/i
  131. describe FROMAD more penis spam
  132. score FROMAD 4
  133. # blarson 2007-09-17
  134. body MYCHEAP /\b(?:my)?cheap(?:xp|adobe)?(?:oem|soft)+(?:now|ware)?(?:(?:4|for)?less)?\d*\s*\.\s*com\b/i
  135. describe MYCHEAP software spam
  136. score MYCHEAP 4
  137. # blarson 2007-09-16
  138. body WWWRU /\b(?:www\.|https?\:.*)\w+\.ru\b/i
  139. describe WWWRU russian web site
  140. score WWWRU 2
  141. # blarson 2007-09-24
  142. body VIPSMS /\bvipsms\.org\b/i
  143. describe VIPSMS vipsms.org
  144. score VIPSMS 4
  145. # don 2007-10-01
  146. header MAKEUP subject =~ /makeup\.com/i
  147. describe MAKEUP makeup.com url
  148. score MAKEUP 3
  149. # blarson 2007-10-04
  150. body SUBT /\bsubtracthold\.com\b/i
  151. describe SUBT subtracthold.com
  152. score SUBT 4
  153. body GRAPHICMAIL /\bhttp\:\/\/www\.graphicmail\.de\b/i
  154. describe GRAPHICMAIL graphicmail.de
  155. score GRAPHICMAIL 4
  156. body WWWRO /\b(?:www\.|https?\:.*)\w+\.ro\b/i
  157. describe WWWRO romanian web site
  158. score WWWRO 2
  159. # blarson 2007-10-10
  160. body CLEANDOM /http\:\/\/\{_clean_domains\}/
  161. describe CLEANDOM broken spamware
  162. score CLEANDOM 4
  163. # blarson 2007-10-11
  164. body SOFTNLSE /\bsoftnlse\s*\.\s*com\b/i
  165. describe SOFTNLSE softnlse.com
  166. score SOFTNLSE 4
  167. # blarson 2007-10-13
  168. body MUSVID /\b(?:MusicAndVideoWorld|usa-bestsellers)\.com/i
  169. describe MUSVID MusicAndVideoWorld.com
  170. score MUSVID 4
  171. # blarson 2007-10-16
  172. body PLATSOFT /\btheplatinumsoft\.com\b/i
  173. describe PLATSOFT theplatinumsoft.com
  174. score PLATSOFT 4
  175. # blarson 2007-10-22
  176. body BLOGSPOT /\bblogspot\.com\b/i
  177. describe BLOGSPOT spammers are hosting on blogspot
  178. score BLOGSPOT 3
  179. # blarson 2007-10-25
  180. body PILLUS /PILL-US\.COM\b/i
  181. describe PILLUS PILL-US spam
  182. score PILLUS 4
  183. # blarson 2007-10-25
  184. body BETWEENTO /\bhttp\:\/\/betweento\.com\b/i
  185. describe BETWEENTO betweento.com
  186. score BETWEENTO 4
  187. # don 2007-10-25
  188. body MASZON /mc?a(szon|yvidol|ttk)\.(com|org|net)/i
  189. describe MASZON pron spam
  190. score MASZON 4
  191. # blarson 2007-10-27
  192. body GMAIL /\@gmail\.com\b/i
  193. describe GMAIL @gmail.com
  194. score GMAIL 1
  195. # blarson 2007-10-28
  196. body MAILRU /\@mail\.ru\b/i
  197. describe MAILRU @mail.ru
  198. score MAILRU 3
  199. # blarson 2007-10-31
  200. body ADOBE4LESS /\b(?:adobe4less|realnewsoft|newmicrosoftdeals|kvaka-soft)\s*[.,]\s*com\b/i
  201. describe ADOBE4LESS adobe4less . com
  202. score ADOBE4LESS 4
  203. # blarson 2007-11-01
  204. body RMAPPLY /http\:\/\/rmapply\.com\b/i
  205. describe RMAPPLY http://rmapply.com
  206. score RMAPPLY 4
  207. # blarson 2007-11-04
  208. header HANOIFASH subject =~ /WWW\.HANOI-FASHION\.COM/i
  209. describe HANOIFASH WWW.HANOI-FASHION.COM
  210. score HANOIFASH 4
  211. # blarson 2007-11-06
  212. body ONLINEMED /\b(?:onlinemedicalkey|pharm\w*|webvinz|wendebay|webdcd|vowelstep|wclth|duringgear|broadbasic|instantsuffix|magnetdouble|drugsdirecteat)\s*\.\s*com\b/i
  213. describe ONLINEMED onlinemedicalkey.com
  214. score ONLINEMED 4
  215. # blarson 2007-11-15
  216. body GETUP /\bgetupgradednow\.com\b/i
  217. describe GETUP getupgradednow.com
  218. score GETUP 4
  219. # blarson (pusling's idea) 2007-11-16
  220. body SPACECOM /^[\w\d]+\s\.\scom\b/
  221. describe SPACECOM whatever . com
  222. score SPACECOM 3
  223. # don -- flowgoaway.com doesn't appear to be a working RBL anymore (if it ever was?)
  224. # blarson 2007-11-20
  225. # uridnsbl URIBL_FLO flowgoaway.com. A
  226. # body URIBL_FLO eval:check_uridnsbl('URIBL_FLO')
  227. # describe URIBL_FLO web site in flowgoaway.com
  228. # tflags URIBL_FLO net
  229. # score URIBL_FLO 1
  230. # blarson 2007-11-20
  231. body SOFTROU /\bwww\.softrou\.com\b/i
  232. describe SOFTROU www.softrou.com
  233. score SOFTROU 3
  234. # blarson 2007-11-20
  235. body GOOGLEPAGES /\bgooglepages\.com\b/i
  236. describe GOOGLEPAGES spammers use googlepages
  237. score GOOGLEPAGES 2
  238. # blarson 2007-12-07
  239. body SOFTBESTGRAND /\bsoft(?:bestgrand|wareonlinemuch)\.com\b/
  240. describe SOFTBESTGRAND softbestgrand.com
  241. score SOFTBESTGRAND 4
  242. # blarson 2007-12-10
  243. body PCSOFTCHEAP /\b(?:pcsoftcheap|cheapezsoft|cheapsoftxp|adobe4cheap|phonowa|saleonsoftware|bestdealoem|realcheapsoft|krasniyles|cheapxp4pc|supercheapoem|lowpriceoem|realcheapoem|cheapadobedeal|softwarefoundation|2008oem|xpxmas|cheap2008soft|snowysoftware|2008adobe|adobe2008|cheapgetsoftone|x(?:higher|main|prime)(?:soft|software|easy)|softonlinepc|andsoftware|softonlinedownload|kunchakoem|erhere\w|kiroemch|phonowd|cheap(?:soft|oem|software)here|softwarenowprox|xprosoftonlinedl|siniyglaz|popandosoem|xsoftprodepot|triudava|krasniynos|fastsoftnow|cheapeasy(soft|oem|software)|ezadobenow|softnowpromohere|primenetsofthe|nowinstantsoftieq|isktesoft|best(?:oem|soft|software)2008|new2008(?:soft|oem|software)|fastez(?:soft|oem|software)|ezfast(?:oem|soft|software)|2008(?:micro)?softdeals|oemfactorysale|nbuysoft|softnuhere|softsale2008|softwintersale|blatnoyoem|svedsoft|gsxoempromo|getmicrosoftfast|adobeoemsale|xp4(?:cheap|less)|xpoemnow|buycheapxp|alloem4less|lun(?:soft|oem|software)|(?:new|fast)xp(?:soft|oem|software)|frukanoka|softcheap(?:n[eo]w|xp)|adobe(?:web|blog|new)(?:soft|spot|deal))\s?\.\s?(?:com|net)\b/
  244. describe PCSOFTCHEAP pcsoftcheap. com
  245. score PCSOFTCHEAP 4
  246. # blarson 2007-12-11
  247. body GOLDGAME /\b(?:gamblingplacegold|goldgamesite|topgamingsite|richbestgaming|luxgoldgaming)\.(?:net|com)\b/
  248. describe GOLDGAME gambling sites
  249. score GOLDGAME 4
  250. # blarson 2007-12-14
  251. body ENLARGETW /\b(?:enlarge|0rz)\.tw\b/
  252. describe ENLARGETW enlarge.tw
  253. score ENLARGETW 4
  254. # blarson 2007-12-15
  255. body POSTTHROUGH /\b(?:postthrough|speedgrand|certaincoast)\.com\b/
  256. describe POSTTHROUGH postthrough.com
  257. score POSTTHROUGH 4
  258. # blarson 2007-12-25
  259. body UHAVE /\b(?:uhavepost|happy(?:santa)?|newyear|familypost|fresh|post)cards?-?(?:2008)?\.com\b/
  260. describe UHAVE uhavepostcard.com
  261. score UHAVE 4
  262. # blarson 2007-12-26
  263. body RUSSWIFE /\b(?:your|best|new|the|my)(?:russ[il]an?|address|russ)(?:wife|bride)\.info\b/
  264. describe RUSSWIFE yourrussianwife.info
  265. score RUSSWIFE 4
  266. # blarson 2007-12-31
  267. body HAPPY2008 /\b(?:happy2008toyou|hellosanta2008|hohoho2008|santawishes2008)\.com\b/
  268. describe HAPPY2008 happy2008toyou.com
  269. score HAPPY2008 4
  270. # blarson 2008-01-02
  271. body BONGHIT /\b(?:beaverbonghits|dobongworld)\.com\b/
  272. describe BONGHIT beaverbonghits.com
  273. score BONGHIT 4
  274. # blarson 2008-01-02
  275. body GOOGLESEARCH /\bgoo+gle\.(com|\w\w|com?\.\w\w)\/+(?:search|pagead)/i
  276. describe GOOGLESEARCH google search URL
  277. score GOOGLESEARCH 2
  278. # blarson 2008-01-02
  279. body SIGAS /\b(?:Sigashash|Reelhotsi|Erisgoonti|Erisgoners|Freesignsies|Rielhotties|Foredroons|Feeshoons|Erisgant|hapburge|wuimooed|jiuezdoo|goingoinghom|buloies|Poeshages|Rueshabesoo|clitoriseries|clitorina|glueplot|crumbtost|ideaputs)(?:\.|\=2E)com\b/
  280. describe SIGAS www.Sigashash.com
  281. score SIGAS 4
  282. # blarson 2008-01-05
  283. body RUSSIABRIDE /\bruss[il]an?(bride|wife)(?:home|live|blog|)\.info\b/
  284. describe RUSSIABRIDE russiabridehome.info
  285. score RUSSIABRIDE 4
  286. # blarson 2008-01-14
  287. body REDMEHS /\bwww\.(?:redmehs|feltas|barataslo|quasibot|tageshes|flessimo|spendhope|instrumentstart)\b/
  288. describe REDMEHS www.redmehs
  289. score REDMEHS 4
  290. # blarson 2008-01-15
  291. body MYURL /\bmyurl\.com\.tw\b/i
  292. describe MYURL myurl.com.tw
  293. score MYURL 3
  294. # blarson 2008-01-28
  295. body W0MEN /w0men\.info\b/i
  296. describe W0MEN hotw0men.info ukrw0men.info
  297. score W0MEN 3
  298. # blarson 2008-01-29
  299. body ACEMST /\bacemst\.com\b/
  300. describe ACEMST acemst.com
  301. score ACEMST 3
  302. # blarson 2008-02-01
  303. body GALSINFO /\b(?:foreigngals|californiaimprove)\.info\b/i
  304. describe GALSINFO foreigngals.info
  305. score GALSINFO 3
  306. # blarson 2008-02-06
  307. body RIDGEST /\bridgest\.com\b/
  308. describe RIDGEST ridgest.com
  309. score RIDGEST 4
  310. # blarson 2008-02-16
  311. body SOFTROI /\bsoft(?:roi|ove)\.com\b/
  312. describe SOFTROI softroi.com
  313. score SOFTROI 4
  314. # don 2008-02-23
  315. body FILEZONE /(file-zone.co.uk|File-Zone)/
  316. describe FILEZONE File-Zone
  317. score FILEZONE 2
  318. # blarson 2008-02-28
  319. body X2J1F /\b2j1f\.com\b/i
  320. descrIbe X2J1F 2j1f.com
  321. score X2J1F 4
  322. # blarson 2008-02-28
  323. body ILVE /\bilveant\.net\b/i
  324. describe ILVE www.ilveant.net
  325. score ILVE 4
  326. # don 2008-03-04
  327. body VIDEOFILBMS /www\.videofilbms\.cn/i
  328. describe VIDEOFILBMS video filbms url
  329. score VIDEOFILBMS 4
  330. # blarson 2008-03-05
  331. body ABESOFT /\bca.abesoft\.com\b/i
  332. describe ABESOFT www.cazabesoft.com etc.
  333. score ABESOFT 4
  334. # blarson 2008-03-06
  335. body STARLEYT /\bstarleyt\.com\b/i
  336. describe STARLEYT starleyt.com
  337. score STARLEYT 4
  338. # blarson 2008-03-07
  339. body URLOEM /\bhttp\:\/\/\{/
  340. describe URLOEM http://{urloem2}
  341. score URLOEM 3
  342. # blarson 2008-03-12
  343. body WILDERGO /\b(?:WilderGoLovan|golovable|BestGolova|SuperGolovaWorld)\.com\b/i
  344. describe WILDERGO WilderGoLovan.com
  345. score WILDERGO 4
  346. # don 2008-03-17
  347. body PROGOLD /\bprogold-inc\.com\b/i
  348. describe PROGOLD progold-inc.com
  349. score PROGOLD 4
  350. # blarson 2008-03-18
  351. body KMINU /\b(?:kminutte|rubstream)\.com\b/i
  352. describe KMINU kminutte.com
  353. score KMINU 4
  354. # don 2008-03-19
  355. body SCIJOURNALS /\bsciencejournals\.info\b/i
  356. describe SCIJOURNALS scientific journals
  357. score SCIJOURNALS 4
  358. # blarson 2008-03-19
  359. body JANEHOT /\bjane\d[\w\d]*\@hotmail\.com\s*$/
  360. describe JANEHOT jane*@hotmail.com
  361. score JANEHOT 3
  362. # blarson 2008-03-20
  363. rawbody BIFUTRA /\b(?:bifutra|veriapoli|xenifeao|toporaig|jieros|bifreca|werikine|incroomise|genbullenst|writeprovide)(?:\.|\=2E)com\b/
  364. describe BIFUTRA spammer web sites
  365. score BIFUTRA 4
  366. # don 2008-04-02
  367. body LONGLINEURL /^.{55,}\S\shttp:\/\/www\.\w+\.(?:com|net|org)\/\s*$/
  368. describe LONGLINEURL long line ending in a simple url
  369. score LONGLINEURL 2
  370. # don 2008-04-07
  371. uri MYTHANKYOUURI /www\.mythankyou\.com/i
  372. describe MYTHANKYOUURI www.mythankyou.com
  373. score MYTHANKYOUURI 5
  374. # blarson 2008-04-09
  375. uri SAMEAS /\bsupersameas\.com\b/
  376. describe SAMEAS supersameas.com
  377. score SAMEAS 3
  378. # blarson 2008-04-12
  379. body URIEXE /\bhttp:\S*\.exe\b/
  380. describe URIEXE .exe url
  381. score URIEXE 3
  382. # blarson 2008-04-24
  383. uri SANSATION /\b(?:sansationel|garmenys|iconaliste)\.com\b/i
  384. describe SANSATION sansationel.com
  385. score SANSATION 4
  386. # blarson 2008-05-04
  387. body EQMEDS /\beqmeds\b/i
  388. describe EQMEDS eqmeds
  389. score EQMEDS 4
  390. # blarson 2008-05-06
  391. uri MYLIVE /\bmylivegi\b/i
  392. describe MYLIVE mylivegirlx.com
  393. score MYLIVE 4
  394. # don 2008-05-26
  395. body BROKENURL /^\s*www((\s+\.\s*)|(\s*\.\+))\S+((\s+\.\s*)|(\s*\.\+))(com|net|org)\s*$/
  396. describe BROKENURL Broken url displayed
  397. score BROKENURL 4
  398. # don 2008-06-13
  399. body STUPIDURL /\w+\[\w+\](?:com|net|org)/
  400. describe STUPIDURL No one will guess that fooo[DOT]com is an URL!
  401. score STUPIDURL 2.5
  402. # blarson 2008-06-16
  403. body SUGARCOM /\b(?:indicatesugar|industryexpect|eset)\.com\b/
  404. describe SUGARCOM indicatesugar.com
  405. score SUGARCOM 4
  406. # blarson 2008-07-22
  407. body VIEWMOVIE /\/(?:(?:viewmovie|stream|watchit|topnews|hotnews|fresh|checkit|default|gowatch|showvideo|livestreaming|top|whatsup|tophot|lol|first|index1|1)\.html\b|(?:video|news2\/)\s*$)/
  408. describe VIEWMOVIE tabiloid style spam
  409. score VIEWMOVIE 3
  410. # blarson 2008-07-22
  411. uri OPERAMAIL /\bwww\.opera\.com\/mail\//
  412. describe OPERAMAIL opera.com mail
  413. score OPERAMAIL 1
  414. # blarson 2008-08-09
  415. body NOSITE /http:\/\/\//
  416. describe NOSITE http URL with no site
  417. score NOSITE 2
  418. # don 2008-09-04
  419. uri TIECORRECT /tiecorrect\.com/
  420. describe TIECORRECT Contains a tiecorrect.com uri
  421. score TIECORRECT 4
  422. # don 2009-02-04
  423. body FOURMINUTI /4minuti/
  424. describe FOURMINUTI Spam from 4 minuti
  425. score FOURMINUTI 3
  426. # don 2009-02-09
  427. uri CREDITREPORTURI /creditreport/
  428. describe CREDITREPORTURI Credit report in the url isn't good
  429. score CREDITREPORTURI 2
  430. uri YAARIURI /yaari.com/i
  431. describe YAARIURI Contains a yaari.com uri
  432. score YAARIURI 3
  433. uri MALADIRET /maladiretaemails/
  434. describe MALADIRET Contains a maladiret uri
  435. score MALADIRET 5
  436. uri DEBRICOLAJE /debricolaje/i
  437. describe DEBRICOLAJE Contains a debricolaje url
  438. score DEBRICOLAJE 6
  439. # blarson 2009-05-02
  440. uri ISUISSE /\bisuisse\.com/
  441. describe ISUISSE isuisse.com
  442. score ISUISSE 4
  443. # don 2010-03-16
  444. uri EMAILSPARKLE /emailsparkle.com/
  445. describe EMAILSPARKLE emailsparkle.com uri
  446. score EMAILSPARKLE 4
  447. # don 2011-10-3
  448. uri MULTIPLYCOM /multiply.com/
  449. describe MULTIPLYCOM multiply.com uri
  450. score MULTIPLYCOM 3
  451. # don 2012-1-9
  452. uri OROUNRU /oruon.ru/
  453. describe OROUNRU oruon.ru uri
  454. score OROUNRU 4
  455. # don 2012-03-07
  456. uri HALFTONESYSTEMS /halftonesystems.com/i
  457. describe HALFTONESYSTEMS Links to halftonesystems.com
  458. score HALFTONESYSTEMS 4
  459. uri VISITPAGE /visit-?page.(com|org|net)/i
  460. describe VISITPAGE Link to visit-page.com
  461. score VISITPAGE 4