Print Page | Close Window

weird spam emails

Printed From: LogSat Software
Category: Spam Filter ISP
Forum Name: Spam Filter ISP Support
Forum Description: General support for Spam Filter ISP
URL: https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5104
Printed Date: 13 January 2025 at 9:33pm


Topic: weird spam emails
Posted By: chinabee
Subject: weird spam emails
Date Posted: 16 March 2005 at 3:39pm
I received some weird spam emails. is there a way i can post it here?



Replies:
Posted By: LogSat
Date Posted: 16 March 2005 at 4:03pm
Yes, just copy and paste the full email source, headers included. Note that you need to have the *original* source, you can't copy and paste from MS Outlook for example because Outlook completely modifies the email's content.

-------------
Roberto Franceschetti

http://www.logsat.com" rel="nofollow - LogSat Software

http://www.logsat.com/sfi-spam-filter.asp" rel="nofollow - Spam Filter ISP


Posted By: chinabee
Date Posted: 16 March 2005 at 4:50pm
I can't. the weird stuff is in the body, not the header.


Posted By: LogSat
Date Posted: 16 March 2005 at 6:22pm
To have any chances of finding out the reason, we need to see the whole original email. If you're not able to do so there's nothing we can do. Please note that you can usually succeed in obtaining the original email by forwarding it as an attachment to an email account that uses a "clean" email client like Outlook Express to retrieve the email. 

-------------
Roberto Franceschetti

http://www.logsat.com" rel="nofollow - LogSat Software

http://www.logsat.com/sfi-spam-filter.asp" rel="nofollow - Spam Filter ISP


Posted By: chinabee
Date Posted: 17 March 2005 at 9:59am

Header

Microsoft Mail Internet Headers Version 2.0
Received: from ren.mycompany.com ([192.168.33.184]) by hou.mycompany.com with Microsoft SMTPSVC(5.0.2195.6713);
  Wed, 16 Mar 2005 08:30:11 -0600
Received: from bran.WED01 ([192.168.11.180])
 by ren.mycompany.com (SAVSMTP 3.0.0.44) with SMTP id M2005031608301015532
 for < mailto:dan@mycompany.com - dan@mycompany.com >; Wed, 16 Mar 2005 08:30:10 -0600
Received: (from webmail [192.168.11.20])
 by bran.WET01 (SMSSMTP 4.0.0.59) with SMTP id M2005031609220303359
 for < mailto:dan@mycompany.com - dan@mycompany.com >; Wed, 16 Mar 2005 09:22:03 -0500
Received: from 68.142.200.101 by  (LogSat Software SMTP Server) Wed, 16 Mar 2005 09:30:10 -0500
Received: (qmail 46453 invoked by uid 60001); 16 Mar 2005 14:29:58 -0000
Comment: DomainKeys? See http://antispam.yahoo.com/domainkeys - http://antispam.yahoo.com/domainkeys
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
  s=s1024; d=yahoo.com;
  b=AwhO3OIzoesaLplnrOzxQaJ5InI9WOxgUpaXUwFJJbUpoicBDY9Crny+bY Ns2py4L1P4dgvMs2etV1qDUWtMAdv2VPCxCsdeLj3Ajz/GjsUYBykGaS+ZJi BFfKf5AE9UBudt8KNpBGgXL8FxXTapEA5Cp2S+hRgMNG7B1Vb6p+4=  ;
Message-ID: < mailto:20050316142958.46451.qmail@web30308.mail.mud.yahoo.com - 20050316142958.46451.qmail@web30308.mail.mud.yahoo.com >
Received: from [12.119.21.244] by web30308.mail.mud.yahoo.com via HTTP; Wed, 16 Mar 2005 06:29:58 PST
Date: Wed, 16 Mar 2005 06:29:58 -0800 (PST)
From: Chinabee < mailto:chinabee@nowhere.com - chinabee@nowhere.com >
Reply-To: mailto:chinabee@nowhere.com - chinabee@nowhere.com
Subject: af
To: mailto:dan@mycompany.com - dan@mycompany.com
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-1297890435-1110983398=:46223"
X-Server: LogSat Software SMTP Server
X-SF-RX-Return-Path: < mailto:chinabee@nowhere.com - chinabee@nowhere.com >
Return-Path: mailto:chinabee@nowhere.com - chinabee@nowhere.com
X-OriginalArrivalTime: 16 Mar 2005 14:30:11.0296 (UTC) FILETIME=[A90F8600:01C52A34]

--0-1297890435-1110983398=:46223
Content-Type: text/plain; charset=us-ascii

--0-1297890435-1110983398=:46223
Content-Type: text/html; charset=us-ascii


--0-1297890435-1110983398=:46223--



Posted By: chinabee
Date Posted: 17 March 2005 at 9:59am

Body

<DIV>
<DIV>
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">Hello, </SPAN></FONT><A href="http://www.am.ox.com.starrinin.com/">http://www.am.ox.com.starrinin.com/"><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">VISlT Our Great PharmB.yMail Shop</SPAN></FONT></A><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial"> and SAVE 75%</SPAN></FONT><?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></P></DIV>
<DIV>
<TABLE class=MsoNormalTable cellSpacing=0 cellPadding=0 border=0>
<TBODY>
<TR>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in" vAlign=bottom rowSpan=2>
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">Vl<o:p></o:p></SPAN></FONT> ;</P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in" vAlign=bottom>
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial"><o:p>&nbsp;</o:p></SPAN>< /FONT></P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in" vAlign=bottom rowSpan=2>
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">RA&nbsp;VA<o:p></o:p></SPAN> </FONT></P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in" vAlign=bottom>
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial"><o:p>&nbsp;</o:p></SPAN>< /FONT></P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in" vAlign=bottom rowSpan=2>
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">UM&nbsp;AM<o:p></o:p></SPAN> </FONT></P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in" vAlign=bottom>
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial"><o:p>&nbsp;</o:p></SPAN>< /FONT></P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in" vAlign=bottom rowSpan=2>
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">EN&nbsp;Cl<o:p></o:p></SPAN> </FONT></P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in" vAlign=bottom>
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial"><o:p>&nbsp;</o:p></SPAN>< /FONT></P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in" vAlign=bottom rowSpan=2>
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">S<o:p></o:p></SPAN></FONT> </P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in" vAlign=bottom rowSpan=2>
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">,&nbsp;man<o:p></o:p></SPAN> </FONT></P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in" vAlign=bottom>
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial"><o:p>&nbsp;</o:p></SPAN>< /FONT></P></TD></TR>
<TR>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in">
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">AG<o:p></o:p></SPAN></FONT> ;</P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in">
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">Ll<o:p></o:p></SPAN></FONT> ;</P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in">
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">Bl<o:p></o:p></SPAN></FONT> ;</P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in">
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">ALl<o:p></o:p></SPAN></FONT&g t;</P></TD>
<TD style="PADDING-RIGHT: 0in; PADDING-LEFT: 0in; PADDING-BOTTOM: 0in; PADDING-TOP: 0in">
<P class=MsoNormal><FONT face=Arial size=4><SPAN style="FONT-SIZE: 13.5pt; FONT-FAMILY: Arial">y&nbsp;Other.<o:p></o:p></SPAN& gt;</FONT></P></TD></TR></TBODY&g t;</TABLE></DIV>
<DIV>
<P class=MsoNormal><FONT face="Times New Roman" size=3><SPAN style="FONT-SIZE: 12pt">&nbsp;<o:p></o:p></SPAN></ FONT></P></DIV>
<DIV>
<P class=MsoNormal><FONT face=Arial size=3><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: Arial">Have a good day.</SPAN></FONT><o:p></o:p></P& gt;</DIV>
<DIV>
<P class=MsoNormal><FONT face=Arial size=3><SPAN style="FONT-SIZE: 12pt; FONT-FAMILY: Arial">P.S. <EM><I><FONT face=Arial><SPAN style="FONT-FAMILY: Arial">You will be pIeasantIy surprised with our PRlCES </SPAN></FONT></I></EM>;-)</SPAN& gt;</FONT><o:p></o:p></P></DIV> ;</DIV><p>
  <hr size=1>Do you Yahoo!?<br>
Yahoo! Small Business - <a href="http://us.rd.yahoo.com/evt=31637/*http://smallbusiness.yahoo.com/resources/"> Try'>http://us.rd.yahoo.com/evt=31637/*http://smallbusiness. yahoo.com/resources/">Try our new resources site!</a> <p>
  <hr size=1>Do you Yahoo!?<br>
Yahoo! Small Business - <a href="http://us.rd.yahoo.com/evt=31637/*http://smallbusiness.yahoo.com/resources/"> Try'>http://us.rd.yahoo.com/evt=31637/*http://smallbusiness. yahoo.com/resources/">Try our new resources site!</a>



Posted By: chinabee
Date Posted: 17 March 2005 at 10:01am

This is what user sees:

 

Hello, http://www.am.ox.com.starrinin.com/ - and SAVE 75%

Vl

 

RA VA

 

UM AM

 

EN Cl

 

S

, man

 

AG

Ll

Bl

ALl

y Other.

 

Have a good day.

P.S. You will be pIeasantIy surprised with our PRlCES ;-)



Posted By: Desperado
Date Posted: 17 March 2005 at 12:19pm

Fractional Font sizes are not valid and are used to obscure / fool filters.

This is what I use:

Corrected Version:

((?i)(font\-size\:[\x20]{0,1}(\d){1,}\.[1-9]{1,}[\d]{0,1}((\")|(\;)|(p(t|x)))))

Dan



-------------
The Desperado
Dan Seligmann.
Work: http://www.mags.net
Personal: http://www.desperado.com



Posted By: chinabee
Date Posted: 17 March 2005 at 4:21pm

What do you mean? add this in keyword black list?

Would you mind sharing your keyword list with me? I think you are realllllly great at this!!!!



Posted By: Desperado
Date Posted: 17 March 2005 at 4:57pm

chinabee,

Yes, it would be placed in the keyword blacklist.  please email me at daseligmann at hotmail dot com   BUT, I usually only use this account for testing so it is not my general point of contact.

Dan S.



-------------
The Desperado
Dan Seligmann.
Work: http://www.mags.net
Personal: http://www.desperado.com



Posted By: chinabee
Date Posted: 17 March 2005 at 5:02pm
email sent. Dan, thanks again.


Posted By: Web123
Date Posted: 18 March 2005 at 2:29am

 Dan!

Could I have it too? (kim @ engberg.fi)

You seem to be "The Master" of the keywords-list.

Thanks,
Kim



Posted By: Desperado
Date Posted: 18 March 2005 at 11:18am

I am not the "Master" ... just persistant.

D



-------------
The Desperado
Dan Seligmann.
Work: http://www.mags.net
Personal: http://www.desperado.com




Print Page | Close Window