> Only RBL (ip, url or hash), bayes from past phishing or some handmade rules
> can detect them, and their score may not sum up to the spam threshold (I
> have to review and rescore these handmade rules).

Nobody really doing any content analysis anymore in spam filtering these
At least the examples from A) group you mentioned should be caught by any
decent content analysis tool (like SpamAssassin for example). Even if they
are coming from otherwise trusted sites, the score from content analysis
should be big enough to mark them as spam.
The B) group, specifically tailored for your website, seem to be something
more sophisticated and may actually require some hand-crafted rules to catch
