I've been tagging a lot of mdpillsource.com spam. They don't hit bigevil because there is no URI in the text format. However the spam hits a ton of other rules. One thing I noticed is this spammer must be using trojaned machines. THe last one came in from:
dhcp-v53-89.cudenver.edu [132.194.53.89]) and a bunch more from possible open relays. This guy is sending from all over and at a good rate. I suggest a seperate (raw)?body rule for him. body MY_PILLSOURCE /mdpillsource\.com/ describe MY_PILLSOURCE Log on Ventures Dirtbag. score MY_PILLSOURCE 4.0 # Because no one rule should make it spam. More info: Registrant: Log On Ventures Inc. 28 Regent St. Belize City 00000 Belize Registered through: International Global Media Domain Name: MDPILLSOURCE.COM Created on: 24-Nov-03 Expires on: 24-Nov-04 Last Updated on: 12-Dec-03 Administrative Contact: Ventures Inc., Log On [EMAIL PROTECTED] 28 Regent St. Belize City 00000 Belize 4156341323 Fax -- 4156341323 Technical Contact: Ventures Inc., Log On [EMAIL PROTECTED] 28 Regent St. Belize City 00000 Belize 4156341323 Fax -- 4156341323 Domain servers in listed order: NS0O01.GOODWEBRX.COM NS0O01.MYEFUTURE.NET Chris Santerre ------------------------------------------------------- The SF.Net email is sponsored by EclipseCon 2004 Premiere Conference on Open Tools Development and Integration See the breadth of Eclipse activity. February 3-5 in Anaheim, CA. http://www.eclipsecon.org/osdn _______________________________________________ Spamassassin-talk mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/spamassassin-talk