Great work Matthew! 
Have seen this type of messages from the IP block 207.251.96.201 ... 204 in the last 
10 days.


So I've added
 
207.251.96.200/29 [207.251.96.200] - [207.251.96.207] # mckinseyquarterly.com 

to your pexicom-ipfile.

Anyone knows www.mckinseyquarterly.com ?
Looks legit...  ?


Looks like this guy has invested a lot to create a big "spam-engine"

Maybe some Declude Pro users should set up a filter file to identify the "X-JLH". So 
we could create gradually a more complete picture of this distributed spam processing 
tecnique.

PEXICOM-HEADER filter C:\IMail\Declude\filters\pexicom_header.txt x 5 0

And in the pexicom_header.txt file

HEADERS 0 CONTAINS X-JLH


---
Gufler Markus 
                 
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.JunkMail".  The archives can be found
at http://www.mail-archive.com.

Reply via email to