Spam detection software, running on the system "freenetproject.org", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Click here! [...]
Content analysis details: (33.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
2.0 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URIs: tradecreate.ru]
0.0 MISSING_MID Missing Message-Id: header
3.3 TVD_RCVD_IP4 TVD_RCVD_IP4
1.6 TVD_RCVD_IP TVD_RCVD_IP
0.0 MISSING_DATE Missing Date: header
2.6 RCVD_NUMERIC_HELO Received: contains an IP address used for HELO
0.0 FUZZY_VPILL BODY: Attempt to obfuscate words in spam
0.0 HTML_MESSAGE BODY: HTML included in message
2.4 HTML_IMAGE_ONLY_08 BODY: HTML: images with 400-800 bytes of words
1.7 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
1.1 RCVD_IN_SORBS_WEB RBL: SORBS: sender is a abuseable web server
[213.144.112.172 listed in dnsbl.sorbs.net]
2.9 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL
[213.144.112.172 listed in zen.spamhaus.org]
1.6 URIBL_AB_SURBL Contains an URL listed in the AB SURBL blocklist
[URIs: tradecreate.ru]
2.1 URIBL_WS_SURBL Contains an URL listed in the WS SURBL blocklist
[URIs: tradecreate.ru]
2.9 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist
[URIs: tradecreate.ru]
2.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?213.144.112.172>]
1.3 SUBJECT_NEEDS_ENCODING SUBJECT_NEEDS_ENCODING
1.1 HTML_SHORT_LINK_IMG_1 HTML is very short with a linked image
2.1 DRUGS_ERECTILE_OBFU Obfuscated reference to an erectile drug
0.6 DRUGS_ERECTILE Refers to an erectile drug
0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS
2.2 TT_OBSCURED_VIAGRA Scora: obscured "VIAGRA" in subject
The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.
-------------- next part --------------
An embedded message was scrubbed...
From: [email protected]
Subject: freemail at freenetproject.org V|AGRA ? Official Seller -99%
Date: no date
Size: 1279
URL:
<https://emu.freenetproject.org/pipermail/freemail/attachments/20100828/09a23b62/attachment.mht>