websecurity@lists.webappsec.org

The Web Security Mailing List

View all threads

***SPAM*** Re: where have you been?

YC
Yuri Cozzolino
Mon, Apr 10, 2017 12:52 PM

Spam detection software, running on the system "webappsec", has
identified this incoming email as possible spam.  The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email.  If you have any questions, see
@@CONTACT_ADDRESS@@ for details.

Content preview:  Hey friend, I've been looking for you, where have you been?
Just take a look on what I've found http://dumapanel.co.id/document.php?c3c1
Warmly, Yuri Cozzolino [...]

Content analysis details:  (7.5 points, 5.0 required)

pts rule name              description


0.0 FREEMAIL_FROM          Sender email is commonly abused enduser mail provider
(yuri.cozzolino[at]libero.it)
0.0 RCVD_IN_SORBS_DUL      RBL: SORBS: sent directly from dynamic IP address
[117.1.245.195 listed in dnsbl.sorbs.net]
1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see http://www.spamcop.net/bl.shtml?117.1.245.195]
2.7 RCVD_IN_PSBL          RBL: Received via a relay in PSBL
[117.1.245.195 listed in psbl.surriel.com]
0.6 URIBL_PH_SURBL        Contains an URL listed in the PH SURBL blocklist
[URIs: dumapanel.co.id]
1.2 URIBL_JP_SURBL        Contains an URL listed in the JP SURBL blocklist
[URIs: dumapanel.co.id]
0.0 HTML_MESSAGE          BODY: HTML included in message
0.8 BAYES_50              BODY: Bayes spam probability is 40 to 60%
[score: 0.5131]
0.8 RDNS_NONE              Delivered to internal network by a host with no rDNS

The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam.  If you wish to view
it, it may be safer to save it to a file and open it with an editor.

Spam detection software, running on the system "webappsec", has identified this incoming email as possible spam. The original message has been attached to this so you can view it (if it isn't spam) or label similar future email. If you have any questions, see @@CONTACT_ADDRESS@@ for details. Content preview: Hey friend, I've been looking for you, where have you been? Just take a look on what I've found http://dumapanel.co.id/document.php?c3c1 Warmly, Yuri Cozzolino [...] Content analysis details: (7.5 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (yuri.cozzolino[at]libero.it) 0.0 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP address [117.1.245.195 listed in dnsbl.sorbs.net] 1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net [Blocked - see <http://www.spamcop.net/bl.shtml?117.1.245.195>] 2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL [117.1.245.195 listed in psbl.surriel.com] 0.6 URIBL_PH_SURBL Contains an URL listed in the PH SURBL blocklist [URIs: dumapanel.co.id] 1.2 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist [URIs: dumapanel.co.id] 0.0 HTML_MESSAGE BODY: HTML included in message 0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60% [score: 0.5131] 0.8 RDNS_NONE Delivered to internal network by a host with no rDNS The original message was not completely plain text, and may be unsafe to open with some email clients; in particular, it may contain a virus, or confirm that your address can receive spam. If you wish to view it, it may be safer to save it to a file and open it with an editor.