Great work Matthew!
Have seen this type of messages from the IP block 207.251.96.201 ... 204 in the last
10 days.
So I've added
207.251.96.200/29 [207.251.96.200] - [207.251.96.207] # mckinseyquarterly.com
to your pexicom-ipfile.
Anyone knows www.mckinseyquarterly.com ?
Looks legit... ?
Looks like this guy has invested a lot to create a big "spam-engine"
Maybe some Declude Pro users should set up a filter file to identify the "X-JLH". So
we could create gradually a more complete picture of this distributed spam processing
tecnique.
PEXICOM-HEADER filter C:\IMail\Declude\filters\pexicom_header.txt x 5 0
And in the pexicom_header.txt file
HEADERS 0 CONTAINS X-JLH
---
Gufler Markus
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.JunkMail mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.JunkMail". The archives can be found
at http://www.mail-archive.com.