# 419 Spam header __FSL_HELO_USER_1 X-Spam-Relays-External =~ / helo=user /i header __FSL_HELO_USER_2 Received =~ /from User(?:\s+by|\s*\(|$)/i header __FSL_HELO_USER_3 Received =~ /helo(?:=|\s)User/i meta FSL_NEW_HELO_USER (__FSL_HELO_USER_1 || __FSL_HELO_USER_2 || __FSL_HELO_USER_3) # score FSL_NEW_HELO_USER 2.0 # axb 2012-09-27 Disabled to avoid overlap with autogenerated rules # 419 Spam # header FSL_XM_419 X-Mailer =~ /\s+6\.00\.2600\.0000$/ # describe FSL_XM_419 Old OE version in X-Mailer only seen in 419 spam # score FSL_XM_419 2.0 # 419 Spam header FSL_CTYPE_WIN1251 Content-Type =~ /charset="Windows-1251"/ describe FSL_CTYPE_WIN1251 Content-Type only seen in 419 spam # score FSL_CTYPE_WIN1251 2.0 # 419 Spam header FSL_MID_419 MESSAGE-ID =~ /\@User>$/ describe FSL_MID_419 Spam signature in Message-ID # score FSL_MID_419 2.0 meta FSL_MISSP_REPLYTO (__FROM_MISSPACED && __HAS_REPLY_TO) describe FSL_MISSP_REPLYTO Mis-spaced from and Reply-to # score FSL_MISSP_REPLYTO 2.0 # http://groups.yahoo.com/group/oftajscns/message uri FSL_YHG_ABUSE /groups\.yahoo\.com\/group\/\S+\/message/ describe FSL_YHG_ABUSE URI pointing to a message in an abused Yahoo Group # score FSL_YHG_ABUSE 2.0 # Bot spew rawbody FSL_BOTSPAM_1 /^[^\n]+\nhttp:\/\/[^\n]+\.ru\/\n$/s describe FSL_BOTSPAM_1 Two-line spam with URI pointing to .ru domain # score FSL_BOTSPAM_1 2.0 # Mainsleaze body FSL_THIS_IS_ADV /This is an advertisement\./ describe FSL_THIS_IS_ADV This is an advertisement # score FSL_THIS_IS_ADV 3.0 # Bot spew rawbody FSL_BOTSPAM_2 /alt="Click here to show image"/ # score FSL_BOTSPAM_2 0.01 rawbody FSL_BOTSPAM_3 /