I've been tagging a lot of mdpillsource.com spam. They don't hit bigevil
because there is no URI in the text format. However the spam hits a ton of
other rules. One thing I noticed is this spammer must be using trojaned
machines. THe last one came in from:

dhcp-v53-89.cudenver.edu [132.194.53.89])

and a bunch more from possible open relays. This guy is sending from all
over and at a good rate. I suggest a seperate (raw)?body rule for him. 

body MY_PILLSOURCE /mdpillsource\.com/
describe MY_PILLSOURCE Log on Ventures Dirtbag.
score MY_PILLSOURCE 4.0 # Because no one rule should make it spam. 


More info:

Registrant:
   Log On Ventures Inc.
   28 Regent St.
   Belize City 00000
   Belize

   Registered through: International Global Media
   Domain Name: MDPILLSOURCE.COM
      Created on: 24-Nov-03
      Expires on: 24-Nov-04
      Last Updated on: 12-Dec-03

   Administrative Contact:
      Ventures Inc., Log On  [EMAIL PROTECTED]
      28 Regent St.
      Belize City 00000
      Belize
      4156341323      Fax -- 4156341323
   Technical Contact:
      Ventures Inc., Log On  [EMAIL PROTECTED]
      28 Regent St.
      Belize City 00000
      Belize
      4156341323      Fax -- 4156341323

   Domain servers in listed order:
      NS0O01.GOODWEBRX.COM
      NS0O01.MYEFUTURE.NET


Chris Santerre 


-------------------------------------------------------
The SF.Net email is sponsored by EclipseCon 2004
Premiere Conference on Open Tools Development and Integration
See the breadth of Eclipse activity. February 3-5 in Anaheim, CA.
http://www.eclipsecon.org/osdn
_______________________________________________
Spamassassin-talk mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/spamassassin-talk

Reply via email to