This problem was posted to the list a few weeks back. This regex seems to
work well for that. It is in the latest FILTER-SPAM.
(?i:(http://|www).+\.(com|info|net)/[a-f0-9]{30,40})
<http://|www).+/.(com|info|net)/%5ba-f0-9%5d%7b30,40%7d)>
From: [email protected] [mailto:[email protected]] On Behalf Of Dave
Beckstrom
Sent: Monday, October 18, 2010 9:29 AM
To: [email protected]
Subject: [Declude.JunkMail] Good filter?
There is pervasive spammer who's uri pattern for the linked spam site is
pretty consistent. They all have a "/" followed by some kind of home-grown
obfuscation which his server recognizes:
<http://cja244.larickcoppas.com/6878d778dcffdc763118115082cc190a3c0343>
http://cja244.larickcoppas.com/6878d778dcffdc763118115082cc190a3c0343
Anyone come up with a clever filter for this?
Also, these spammers are using domainsite.com as their registrar for their
spamvertized domains. Has anyone worked on a solution where the URI can be
checked against the registrar and if its registered with domainsite.com then
weight can be added or it can be blocked?
---
[This E-mail was scanned by Declude]
---
This E-mail came from the Declude.JunkMail mailing list. To
unsubscribe, just send an E-mail to [email protected], and
type "unsubscribe Declude.JunkMail". The archives can be found
at http://www.mail-archive.com.
---
[This E-mail was scanned by Declude]
---
This E-mail came from the Declude.JunkMail mailing list. To
unsubscribe, just send an E-mail to [email protected], and
type "unsubscribe Declude.JunkMail". The archives can be found
at http://www.mail-archive.com.