Mailing List Archive

weird kind of spam
Hi

I received the following message, it's not really surprising SA didn't
catch it: it's not empty but there's no content either...

Is there any way to mark this as spam?

--- spam message ---
>>From robinsteptoe@earthlink.net Tue Mar 9 18:48:08 2004
Return-Path: <robinsteptoe@earthlink.net>
X-XS4ALL-To: <xxxxx@maildrop.xs4all.be>
Received: from mx2.xs4all.be (mx2.xs4all.be [195.144.64.130]) by
maildrop1.xs4all.be (8.12.10/8.12.10) with ESMTP id i29Hm8AJ023875 for
<xxxx@maildrop.xs4all.be>; Tue, 9 Mar 2004 18:48:08 +0100
Received: from more.aliens.be ([217.71.123.170]) by mx2.xs4all.be
(8.12.9/8.12.9) with SMTP id i29Hm6a3001152 for <xxxx@xs4all.be>; Tue,
9 Mar 2004 18:48:06 +0100
Received: (qmail 15369 invoked by uid 508); 9 Mar 2004 17:48:36 -0000
Delivered-To: xxxx@linux.be
Received: (qmail 15363 invoked from network); 9 Mar 2004 17:48:35 -0000
Received: from mallard.mail.pas.earthlink.net (207.217.120.48) by
more.aliens.be with SMTP; 9 Mar 2004 17:48:35 -0000
Received: from user237.net432.lv.sprint-hsd.net ([65.40.117.237]
helo=computer) by mallard.mail.pas.earthlink.net with smtp (Exim 3.33
#1)
id 1B0lKj-0003mk-00 for xxxx@linux.be; Tue, 09 Mar 2004 09:48:01
-0800
Message-ID: <000801c405ff$546dd520$0201a8c0@computer>
From: "Robin Steptoe" <robinsteptoe@earthlink.net>
To: <xxxx@linux.be>
Subject:
Date: Tue, 9 Mar 2004 09:52:34 -0800
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0005_01C405BC.411E1EA0"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.00.2615.200
X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2615.200
X-Evolution-Source: pop://xxxx@pop.xs4all.be

This is a multi-part message in MIME format.

------=_NextPart_000_0005_01C405BC.411E1EA0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit



------=_NextPart_000_0005_01C405BC.411E1EA0
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content="text/html; charset=iso-8859-1" http-equiv=Content-Type>
<META content="MSHTML 5.00.2614.3500" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV>&nbsp;</DIV></BODY></HTML>

------=_NextPart_000_0005_01C405BC.411E1EA0--
--- spam message ---
--
# Mertens Bram "M8ram" <bram-mertens@linux.be> Linux User #249103 #
# SuSE Linux 8.2 (i586) kernel 2.4.20-4GB i686 256MB RAM #
# 8:24pm up 1 day 3:32, 3 users, load average: 0.03, 0.09, 0.07 #
RE: weird kind of spam [ In reply to ]
> -----Original Message-----
> From: Bram Mertens [mailto:bram-mertens@linux.be]
> Sent: Tuesday, March 09, 2004 2:31 PM
> To: spamassassin
> Subject: weird kind of spam
>
>
> Hi
>
> I received the following message, it's not really surprising SA didn't
> catch it: it's not empty but there's no content either...
>
> Is there any way to mark this as spam?
>
> --- spam message ---
*snip*

The following BLs list this IP:
DSBL/dsbl.org: 553 DSBL Multistage Relay; DSBL Unconfirmed [Remove]
NOMORE/moensted.dk: 553 NOMORE 2 - 1075639389 [Remove]
BLARS/block.blars.org: INET 127.1.0.9

So there is one way.

Or you could BL :
65.40/16 SPRINTDSL02 Winter Park, Florida :-)

or
header MY_WINTERPARK Received =~ /from
user\d{1,3}\.net\d{1,3}\.lv\.sprint-hsd.net/

or look at "helo=computer" that seems fishy! :)

or right a body rule to look for "<DIV>&nbsp;</DIV></BODY>" but I'm not sure
on its S/O.

Just some things to look at.

HTH,
--Chris