// MailWasher Pro filter rules #3, compiled by "Wiz" Feinberg, from www.wizcrafts.net. // Can be used to replace the default rules, saved to your MWP profile data folders as filters.txt. // This page is a child of: http://www.wizcrafts.net/mailwasher.html and http://www.wizcrafts.net/mwp-filters.html where you can get MailWasher Pro, or learn more about it. // // If these rules prove beneficial to you, please make a donation, at: http://www.wizcrafts.net/donations/ // Thanks :-) // // READ THESE NOTES // // Indicates a comment, and is not parsed. // // IMPORTANT READ THE FOLLOWING! // If you make changes to this file while MailWasher Pro is running, the changes will be overwritten when MailWasher Pro is closed. // To be safe, close MailWasher first,then edit the filters. Or, edit them within MailWasher using the Filter Sidebar (Control + F7). // I have had reports about corruption when copying and pasting my filters into existing filters.txt files. Most of the time this is caused because the text editor you are using is allowing a mixture of Unicode and Ascii entries to be copied. // If you experience MailWasher wiping out the pasted in filters, after you re-open it (assuming it was not running at all when you saved the changes), do this. // When copying and pasting some or all of these filters into your own "filters.txt," if you are using a text editor that is unicode-aware, you should not just SAVE the file. Rather you should use the "Save AS" feature to save the file as either all ASCII or all UNICODE. MailWasher will accept either, but can only deal with one at a time. // // Personally identifiable rules have been deleted from this list. You should create your own rules to deal with your domain name or email address in the Subject or From fields. // Sample rule for spam sent to an non-existent account on your Domain server, - contacts@yourDomain ... // (ex:) [enabled],"contacts@YourDomain.com","Contacts Spam",16711680,OR,Hidden,Delete,Automatic,To,contains,contacts@YourDomain.com,EntireHeader,contains,contacts@YourDomain.com,Subject,contains,contacts@YourDomain.com,From,contains,contacts@yourDomain // The following are actual, functional rules, ready to drop in to your existing Mailwasher Filters. There may be duplicates because some are from common rules sources. // There must not be any blank lines from the start of the list to the end. Each rule must be on one continuous line, with a linefeed between rules. The last rule must end at the end of it's line, without a linefeed! // Turn off word wrap to view these rules. // Be sure you add your friends and contacts to your Friends List, or the image spam filter rules may delete email you wanted. // Removed undesirable "Bounce" directives on August 8, 2007. Bouncing no longer works for modern spam as the Return To and From field is always forged and is sent from zombie botnetted home or office computers. // WARNING! This version of my filters contains Hidden and Automatic deletion actions when an email is identified as spam by some of these rules. You should review these filters and change these actions if you prefer to see all flagged messages and delete them manually. // You should definitely turn on "Allow deleted email to be restored from the summary screen," then set your SMTP server and logon credentials, and set the scanning size to at least 250 lines or more (300+ lines is better). // Rearranged filters according to my own usage; most current rules nearest the top; catch-alls near bottom. // December 2, 2007: (Split Pharmaceuticals and Male Enhancement filters into separate detections for Subject [S] and Body [B] word matches. Merged Canadian Pharmacy filter into Pharmaceuticals.) // January 3, 2008, I have begun anchoring the starting characters on new lines with ^ to improve rule processing. Many rules are getting updated to include this, as is appropriate. // January 17, 2008, I added a new filter to detect the same domain name on both sides of @ sign, in "From:" field. Removed part of .info sender filter to speed up processing. // March 8, 2008, made HTML Tricks filter automatically delete, afer a deluge of spam matching it's rules, with no false positives. // Recently disabled and moved to bottom: Fake CNN and MSN Breaking news alerts leading to Trojan video codec downloads. // Removed most of the image spam filters because this type of spam is rarely used now. Only Image Spam #11 remains. // Recent additions: Added SquirrelMail, Canadian Pharmacy, Fake Fox News Canadian Pharmacy, Fake ABCNews Canadian Pharmacy, Bank Phishing, Known Spam Subjects #3, Thunderbird mailer, Yahoo Calendar and Yahoo Search spam filters. // Last Updated on October 12, 2008, (Updated Known Spam [From or Body] filter to block new Canadian Pharmacy spam) // All of these comments will be erased as soon as you save this file as filters.txt and activate MailWasher Pro. Keep a copy of this file on hand. [enabled],"AVG Returned Email","AVG Bounces",16711680,OR,Delete,Body,contains,"This is the AVG E-mail Scanner program.",Body,contains,"I'm sorry to inform you that the message",Subject,contains,"Undelivered Mail Returned to Sender" [enabled],"Restored by MWP","Restored by MWP",26112,AND,Legitimate,TakesPrecedence,EntireHeader,contains,"Resent-From: ""MailWasher Pro recycle bin""" [enabled],"Mailwasher Reports","MWP Report",26112,AND,Legitimate,Subject,contains,"MailWasher Pro summary" [enabled],"Multiple Forwarded Messages","Multiple Forwarded Messages",16711680,AND,To,containsRE,"(.+@.+,\s){5,}",Subject,contains,FW: [enabled],XdomainY@domain,BlackList,0,AND,Delete,Automatic,EntireHeader,containsRE,"^Received: from.*@(([\w\d]*)\.\w{2,4}).*^From:.*<\w{2,}\2\w+?@\1" [enabled],"Angelina Jolie Video Trojan","Angelina Jolie Video Trojan",255,AND,Delete,TakesPrecedence,Automatic,Subject,containsRE,"An[gj]elina\s{1,2}(Jolie\s)?(Free|naked|nude|XXX)?\s(movie|Video)|Jolie\ naked" [enabled],"Fake Windows Update","Exploit Link",16711680,AND,Delete,TakesPrecedence,Subject,contains,"Official Update",Body,containsRE,"/.+\.exe"">" [enabled],"Trojan Video Link [S]","Trojan Video Link",16711680,OR,Delete,Automatic,Subject,containsRE,(Kick-up|News)\s-.+-\svideo,Subject,contains,"video without cowards",Subject,contains,"Re: Delivery Protection",Subject,is,"BREAKING news",Subject,is,"Weekly top news",Subject,containsRE,"(BBC:|CNN:|Breaking\ news:|Hot\ news:)" [enabled],"Trojan Video Link [B]","Trojan Video Link",16711680,OR,Delete,Automatic,Body,containsRE,"(Kick-up|New|Shocking)\s(presentation|video)|video\ without\ cowards|mp3\ is\ shocking|Interesting\ (cd|mp3|mpeg4)|Stunning\ (mpeg4|porno|video)|porno\ dvd",Body,containsRE,"Download\ and\ watch|Download\ (it\s)?now\!|get\ this\ kick-up\ cd|Look\ (at\s)?it\ now\!",Body,containsRE,"/(play(er)?|mov|stream|vid|video_?\d?|watchit)\.exe"">",Body,contains,"Download VIDEO",Body,contains,"Open video",Body,contains,/paris_hilton,Body,contains,"PUSH TO WATCH",Body,contains,"Shocking movie",Body,containsRE,"/index[0-9]{1,2}\.html"">",Body,contains,"Video attached" [enabled],"Trojan Video Link [S&B]","Trojan Video Link",16711680,AND,Delete,Automatic,Subject,containsRE,"Britney\ Spears|(Paris|Barron)\ Hilton",Body,containsRE,"\.exe"">|/index_?\d{1,2}\.html"">" [enabled],"Exploit Link","Exploit Link",16711680,OR,Delete,Automatic,Body,contains,"Please read the attachment to get the message",Body,contains,"Please read the attachment.",Body,contains,"have attached your document.",Body,containsRE,http://.+/(begin|checkit|default|first|fresh|index1|gowatch|live(streaming)?|lol|main|news|r|showvideo|start|stream(ing)?|topnews|up|viewmovie|watch|watchit|whatsup)\.html(
)?(\r\n)?,Body,contains,/viewmovie.html,Body,containsRE,"/(install|msvideoc)\.exe"">",Body,containsRE,".(avi|mpg).exe"">",Body,containsRE,"/(best|index1|up)(\.|=2E)php""",Body,contains,"American soldiery",Body,containsRE,"(?-s)^Content-Transfer-Encoding:\ quoted-printable\r\n\r\n^.+http://.+/.+\.html$\r\n^------=_NextPart_" [enabled],"Known Spam Subjects #1","Known Spam Subjects",16711680,OR,Delete,Automatic,Subject,containsRE,"^\d\d% discount$",Subject,contains,"Can you tell me what's wrong, and how we can fix it?",Subject,contains,"No more embarrassment",Subject,contains,"New size for Men",Subject,contains,"U on board",Subject,contains,"huge dignity",Subject,contains,"Won't forget last night",Subject,contains,"Realize all of her dreams",Subject,contains,"re:Nobody will know bout your problems",Subject,contains,"Get on this right away",Subject,is,"Batteries included",Subject,containsRE,(?-i)^Mego\s.+,Subject,containsRE,^(?-i)(MSG\s)?ID:\d{5}\s.+ [enabled],"Known Spam Subjects #2","Known Spam Subjects",16711680,OR,Delete,Automatic,Subject,contains,"For every men of different ages unique decision",Subject,is,"What time is okay for you",Subject,contains,"We provide for you a real advantage to turn her on",Subject,contains,"Our best decision is suitable for every age",Subject,contains,"She will call you Macho",Subject,contains,"Legendary Hero of rumors",Subject,contains,"Extend your possibilities in your private life",Subject,contains,"Know her from the sexual side how is she inside exactly",Subject,containsRE,"(guys|Mens?)\ (Love|Need)\ This|Are\ you\ ...\?|XXX\ Video",Subject,containsRE,"size\ increase|(luck|pleasure)\ in\ love|\b(?-i)[GH]uu\w{2,}|virility|bikini\s.*shoot",Subject,contains,"The most powerful weapon for your battles",Subject,contains,"Fast Shipping WorldWide",Subject,containsRE,"(Best|Finest|Good)\ ([a-z]{3,}\ )?(propos(al|ition)|solution|suggestion)" [enabled],"Known Spam Subjects #3","Known Spam Subjects",16711680,OR,Delete,Automatic,Subject,is,"Bring back time when girls were yours.",Subject,is,"Solution for your sexual life",Subject,is,"You can do anything with it",Subject,is,"you have nothing to lose, just a lot to gain!",Subject,contains,"Proven Effective",Subject,contains,"Make your lady w",Subject,contains,"Relax. Take a Deep Breath",Subject,contains,"Buy now, you won't regret!",Subject,containsRE,"^\d\d%\ off\ for\ [a-z0-9]{3,}$",Subject,containsRE,"(?-i)^from\s[A-Z][a-z]{2,}\s[A-Z][a-z]{3,}$" [enabled],"Known 1-word spam subject","Known Spam Subjects",16711680,OR,Delete,Automatic,Subject,is,Enlarge,Subject,is,Rwd:,Subject,is,Vulcan!,Subject,containsRE,^[0-9]{4}$,Subject,containsRE,^(Best|Electronics|Finest|Good(iest)?|Super)$,Subject,containsRE,^(attehuor|fumerent|herkapit|Hermes|idaza|atiohar|Mego|ne-gnorw|nidnalad)$ [enabled],"Known Spam [From or Body]","Known Spam [F or B]",16711680,OR,Delete,Automatic,Body,contains,"The most powerful weapon for your battles",Body,containsRE,"SpamIt\.com|best-kept\ secret\ for\ Men|^peascod|^(?-i)Severtieth|Healthcare\ Management\ Inc",Body,containsRE,"\b(show\ woman\ you(rself)?\ care|(many|Your)\ w[eo]men)\b",Body,contains,"The finest of products, at the lowest of prices:",EntireHeader,containsRE,"(^From:\s{1,3}(ph[ra]{2}macy|(?-i)E-STORE|\{|\}|""=\?ISO-8859-1\?Q\?))|(^X-Mailer:\ PHPMailer\ \[version 1\.73\]\r\n^X-Mailer:\ phplist\ v2\.10\.4$)",Body,contains,"Your tool can only get BIGGER",From,containsRE,"^i?Ci?a.?li?s\b|(?-i)(Express\ Newsletter|WWW\ News|Healthcare\ Management\ Inc)",Body,containsRE,"^Satisfy\ (your\ (girl|wom[ae]n)|her\b)|^Best\ offers\.\ \(c\)\ 200[89]",Body,contains,"gift for your lover",Body,contains,"Make her worship you",Body,contains,"pleasure in bed",Body,contains,"(c) 2008. To unsubscribe press )?$",Body,contains,"URGENT AND CONFIDENTIAL",Body,containsRE,"Bank\ of\ (Nigeria|Benin|(South\s)?Africa)|Benin\ Republic|Republic\ of\ Benin|Director,\ United\ Nations",Body,containsRE,"unclaimed\ (benefits|funds)",Body,contains,"contacting you based on Trust",Body,containsRE,"(Kind\s)?Attn:\s?Beneficiary|^(Hello\s)?(MY\s)?(DEAR\s)?(GOOD\s)?FRIEND[,.]|^Atte?n:Dear\ Friend,|^(Attn,\s)?My Dear\ (Beloved|Friend)[,.]$|^ATTENTION\s?:\s?BENEFICIARY.?$|(?-i)Kind\ Attn:\s?|(?-i)Beneficiary",Body,containsRE,"demurrage|dumourage|Clearance\ Certificate\ (\r\n)?Fee|keeping\ fees|(?-i)IMMEDIATE\ RELEASE\ OF\ YOUR\ PAYMENT|(I\ am|My\ name\ is)\ Barrister" [enabled],"  Spam","  Spam",16711680,AND,Delete,Body,contains,"",Body,contains, ,Body,contains," ",Body,containsRE,"\.(com|net)"">Click here

" [enabled],"Postcard Trojan Scam","Postcard Scam",16711680,AND,Delete,Automatic,Subject,containsRE,"\b(e-?)?(card|greeting|postcard|new\ year|Happy\ 2008!|New\ Hope\ and\ New\ Beginnings|new\s.*year)",Body,containsRE,"\b((e-?)?(post|greeting\s)?card)|new\ year\b",Body,containsRE,"^http://(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}/|(.*postcards?.*|newyearwithlove|.+2008|happy.+cards?|happy2008.*?)\.com/?)" [enabled],"Numeric IP Link","Numeric IP Link",16711680,AND,Delete,Automatic,Body,containsRE,"^.*http://\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}/",EntireHeader,doesn'tContainRE,"^Message-ID:\ <.+@mail.gmail.com>" [enabled],"Image Spam #11","Image Spam #11",16711680,OR,Delete,TakesPrecedence,Body,containsRE,"^<(center|/style)>\r\n^\r\n^ds)\b,Body,containsRE,"""http://(www\.)?(prescription|drug).+\.c(om|n)/?"">" [enabled],"Pills Spam","Pills Spam",16711680,OR,Delete,Automatic,Subject,contains,P|\\S,Subject,contains,pills,Subject,containsRE,"BE$T|PILL.?S|Plills|p[i1l|!][1l|!]{2,3}s|pill\ that\ (.*)?works",Subject,contains,MEDS,Subject,contains,generic,Body,containsRE,generics|pillz,Body,contains,"these pills ",Body,containsRE,"\b(buy|cheap|herbal|wonder)\ (drugs|pills|remed(y|ies)|solutions?)\b|pills\ at\ (dirt\s|the\s)?cheap(est)?\ prices?|medicines",Body,containsRE,^http://.*pills.*\.com,Body,containsRE,"^" [enabled],"HGH Spam","HGH Spam",16711680,OR,Delete,Automatic,Body,contains,"HGH ",Body,contains,Regenisis,Body,containsRE,H\s{2}G\s{2}H,Body,contains,"Rediscover your youth with ",Body,contains,"Who wouldn't want to feel younger and stronger?",Body,contains,"The Fountain of Youth today!",Body,contains,"Tighten and Increase skin vitality",Subject,contains,"Experience the feeling of youth again",Body,contains,"Feel young again today!" [enabled],"Bank Phishing Scam","Phishing Scam",16711680,OR,Delete,Subject,contains,"Online Banking Verification Process",Subject,contains,"Please visit our Client Verification Form using the link below",Body,contains,/OSL.htm?LOB=3D [enabled],"Casino Spam","Casino Spam",16711680,OR,Delete,Automatic,Subject,contains,"YOU play we PAY",Subject,containsRE,"\b(Cas[i1]n[o0]|club\s?world|No\ Deposit\ Required|Gambling|roulette|black.?jack|poker|slot\ machines)\b",Body,containsRE,".*Casino",Body,containsRE,"(Big\ Dollars?|Free|Golden\ Gate|online|no\ deposit|the)\ Casino",From,containsRE,(?-i)Gambl(e|ing)|Casino|Casnio|Cazino,Subject,contains,"Sign up & collect $500!",Body,contains,"Sign up & collect $500!",Body,containsRE,"\b(poker|jackpot)|poker\ blackjack\ slots\b",Body,containsRE,"Club\s?World|casino\ (games|members)|(Bet|Gamble)\s{1,2}On\s{0,2}(line|credit)|^\s{1,2}Win\s{1,2}\$",Body,containsRE,"Gambling\s{1,2}(chips|credit|from\ home|online)" [enabled],"Lottery Scam","Lottery Scam",16711680,OR,Blacklist,Delete,Automatic,Subject,contains,"WINNING NUMBER:",Subject,contains,"Microsoft Lottery",Subject,contains,"GO FOR CLAIM VERIFICATION FORM",From,contains,LOTTERY,From,contains,"Department of National Lotteries",Body,contains,"Attn: Lucky Winner",Body,contains,"ATTENTION: DEAR WINNER",Body,contains,"YOUR E-MAIL ADDRESS WON ",Body,contains,"please contact your fudiciary agent",Body,contains,"International Program Online Co-ordinator",Body,containsRE,"(?-i)WINNING\ NUMBER:|LOTTERY|RE:\ LOTTO",Body,containsRE,"(jackpot|International|Microsoft|National)\ Lottery|fiduciary|The\ Kings\ Charity|weekly\ sweepstakes",Body,containsRE,"You\ are\ advised\ to\ keep\ this\ winning\ (.+\s)?confidential" [enabled],"Money Transfer Scam","$ Xfer Scam",16711680,OR,Delete,Automatic,Subject,contains,"SWIFT CREDIT CARD",Body,contains,AWARD/INHERITANCE/CONTRACT,Body,contains,"Promptitude in sending the payment",Body,contains,"We redirect the client's payment to you",Body,contains,"after you'll keep our(and yours) earnings, ",Body,contains,"it is your obligation to transfer the rest",Body,contains,"Basic knowledge in Acconting and payment transactions.",Body,containsRE,"^My\ dear\ friend,$|Dear\ good\ friend\s?,|modalities|money\ transfer\ system|I\ will\ give\ you\ \d\d%\ for\ your\ kind\ assistance to me",Body,contains,CONTRACT/INHERITANCE,Subject,contains,"TRANSFER ASSISTANCE" [enabled],"Weight Loss Drugs","Weight Loss Drugs",16711680,OR,Delete,Automatic,Subject,containsRE,"Loo?s(e|ing)\ (your\ )?(pounds|weight)",Subject,contains,"weight loss",Subject,containsRE,Hoodia|Gordonii|Anatrim,Body,containsRE,Hoodia|Gordonii|Fatblaster|anatrim,Subject,contains,"Are you satisfied with the size of your ",Body,containsRE,"herbal\ (capsules|components)",Body,contains,"lose weight",Body,contains,"Amazing weight loss ",Body,contains,"your weight." [enabled],"Quit Smoking Spam","Quit Smoking",16711680,OR,Delete,Automatic,Subject,contains,"Live longer life without cigarettes",Subject,contains,"quit smoking",Subject,contains,"Stop Smoking ",Body,contains,"Break free from Nicotine",Body,contains,"break the nasty habit",Body,contains,LIVEFREE,Body,contains,"quit smoking once and for all.",Body,containsRE,"(quit|stop)\ smoking\." [enabled],"Counterfeit Goods","Counterfeit Goods",16711680,OR,Delete,Automatic,Subject,containsRE,designer\s(brands|footwear|shoes),Subject,containsRE,\b(gucci|prada|chanel|chloe|dior|(?-i)UGG)\b,Subject,contains,repl!c@,Subject,containsRE,Cartier|Gucci|Versace,Subject,containsRE,(?-i)SHOES,Subject,contains,"luxury footwear",Subject,containsRE,"Branded\ (footwear|shoes)",Subject,contains,"Clad your feet",Body,contains,"~ Gucci",From,contains,Gucci [enabled],"Get Laid Spam","Get Laid Spam",16711680,OR,Hidden,Delete,Automatic,Body,contains,"Best of all: it is free...",Body,contains," get laid",Body,contains,"% of members have already gotten laid using our system!",Body,contains,"Are you interested in hooking up with people who live just minutes from you?",Body,contains,"Are you interested in getting laid with locals?",Body,contains,"We have the power to make this happen!",Body,containsRE,fuck.?(buddy|friend),Body,containsRE,".*(It's\ all\ here|Here\ it\ is|Check\ it\!)(\!)?",Body,contains,"want more sex" [enabled],"Dating Spam","Dating Spam",16711680,OR,Hidden,Delete,Automatic,Subject,containsRE,\bdating\b|single.?ladies,Body,contains,"Greetings! I wish to get acquainted with you",Body,contains,flirting,Body,contains,"dating system",Body,containsRE,"\d\d%\ of\ our\ members\ .*hooked\ up\ (using|with)\ our\ .*system",Body,contains,"I read your profile online and I was int",Body,contains,"Please write me a letter here http://",Body,contains,"Do you like beautiful girls?",Body,contains,"good looking girl who is looking to chat with you",Body,contains,"looking for a nice guy to chat with" [enabled],"The Bat Image Spam","The Bat Image Spam",16711680,AND,Delete,Automatic,EntireHeader,contains,"X-Mailer: The Bat!",Body,containsRE,"^(?-i)\r\n^\r\n^

.+

",Body,contains,"Content-Type: image/gif;" [enabled],"Re [digits] Spammer","Re [digits]",16711680,AND,Hidden,Delete,Automatic,Subject,containsRE,^re.?,Subject,containsRE,"\[\d{1,3}\]:?" [enabled],"Re: or FW: Spam","Re: or Fw:",16711680,OR,Hidden,Delete,Subject,is,Re:,Subject,is,Fw: [enabled],"Loans Spam",Loans/Bankrupcy,16711680,OR,Delete,Automatic,Body,contains,"Bad credit",Body,contains,Bankruptcy,Body,containsRE,"low(est)?\ rate(s)?|payday\ advance|(Equity|short-term)\ loan",Body,contains,"fixed low rate",Body,contains,"You have been pre-approved",Subject,containsRE,"consolidat(e|ion)|debt|lenders|loan|mortgage|refinan?c(e|ing|ment)|Your\ Life\ Insurance",Body,containsRE,"^C[o0]ngra[dt]ulati[o0]ns.*you('ll|\scan)\ get\ (.*\ )?\$""?\d\d\d.+""?\ loan\ for\ ",Body,contains,"Refinance ",Body,contains,loans,Body,contains,"Are your premiums payments too high" [enabled],"HTML Spam Tricks","HTML Tricks",16711680,OR,Delete,Automatic,Subject,containsRE,.*\$.*\$|.*@.*@|(?-i)\$REPSBJ,Body,contains,=2Ecom/,Body,containsRE,(?-i)\$REP(BODY|LINK),Body,containsRE,"font\ size=""?0""?",Body,containsRE,"(()([\w\s,\.\-]){1,10}){3,}",Body,containsRE,((�*(3[3-9]|[4-9]\d|1[01]\d|12[0-6]);).*?){6},Body,containsRE,"(/[a-z0-9]/[a-z0-9]){5,}",Body,contains,






,Body,containsRE,<\![^-D],Body,contains,Unsubscribe,Body,contains,"",Body,contains,"" [enabled],"Ebay Phishing Scams","Ebay Phishing Scam",16711680,AND,Delete,EntireHeader,doesn'tContainRE,"^Received:\ from\ .+\..+ebay\.com\ .+\ helo=.+\.ebay\.com",Subject,contains,eBay,Body,containsRE,"^Dear\ eBay\ (Customer|Member),",Body,contains,"eBay Confirmation Request" [enabled],"PayPal Scams #1","PayPal Scam #1",16711680,AND,Delete,TakesPrecedence,EntireHeader,doesn'tContainRE,"^Received:\ from\ [a-z0-9.-]+\.paypal\.com\s",From,containsRE,.+@(intl\.)?paypal(-us)?.com [enabled],"PayPal Scams #2","PayPal Scam #2",16711680,AND,Delete,TakesPrecedence,Body,containsRE,"^Dear\ PayPal\ (User|Member|Customer)",EntireHeader,doesn'tContain,nix.paypal.com [enabled],"Diploma Spam","Diploma Spam",16711680,OR,Delete,Subject,containsRE,(\b(diplomas?|dip1omas?|DIMPLOMAS?|Degree)\b)|(?-i)Bacheelor|Masteer|MBA/|Doctoraate,Body,contains,"No classes!",Body,contains,"your Graduation is a phone call away",Body,contains,"UNIVERSITY DIPLOMA",Body,containsRE,"Diiploma|DIMPLOMA|(?-i)D\ I\ P\ L\ O\ M\ A\sS?",Body,contains,"Obtain the_degree you deserve",Body,containsRE,"^(For US:\s)?1[-,'\.\*\s\~](206|267|501|781)[-,'\.\*\s\~]\d{3}[-,'\.\*\s\~]\d{4}|Call\ Today|call(ing)?\ this\ number:",Body,containsRE,"your\ (degree|diploma)",Body,containsRE,"(diplomas|(?-i)Bachelors,?|(?-i)Masters,?|PhD's)",Body,contains,non-accredited [enabled],"Russian Sender","Russian Sender",16711680,OR,Delete,Automatic,EntireHeader,containsRE,"^Received:\ from\ .*85\.140\.\d{1,3}\.\d{1,3}",EntireHeader,containsRE,"^Received:\ from\ .*80\.85\.1([7][6-9]|[8[0-9]|9[01])\.\d{1,3}(\]\))?",EntireHeader,contains,"charset=""koi8-r"";",EntireHeader,contains,"Subject: =?koi8-r",Body,contains,charset=3Dkoi8-r [enabled],"Hitman Scam","Hitman Scam",16711680,AND,Blacklist,Delete,Automatic,Subject,contains,"BE MORE CAREFUL",From,contains,"BE MORE CAREFUL" [enabled],Pornography,Porn,16711680,OR,Delete,Automatic,Subject,containsRE,"((wet\ )?puss(ies|y))|nympho|porno?s?\b|Live\ Girls",Body,contains,nymphos,From,contains,"webcam ",Body,contains,"Porniest Home Videos" [enabled],"Malformed Link Spam","Malformed Link",16711680,AND,Delete,Body,containsRE,"^\s?http://.+\ \.\ (com|cn|info|org|net|ru)/?$" [enabled],"Google Phishing Scam","Google Phishing Scam",16711680,AND,Delete,TakesPrecedence,Automatic,Subject,contains,Please,From,contains,Google-AdWords,EntireHeader,doesn'tContainRE,"Received:\ from\ [a-z0-9-\.]+\.google\.com",Body,contains,"Dear Advertiser," [enabled],"Google Redirect Exploit","Google Redirect Exploit",255,AND,Delete,Automatic,Body,contains,"href=3D""http://www.google.com/pagead/iclk?",Body,contains,durl=3Dhttp:// [enabled],"Underscore/Dash Sender","_- Sender",16711680,OR,Delete,EntireHeader,containsRE,"(envelope-from\ <-[a-z0-9]+@.+\..+>)",From,containsRE,".*<_[a-z1-9-]+@.+\.\w{2,3}>$" [enabled],"Zip attachment","Zip, Rar, Gz Attachment",255,AND,TakesPrecedence,Body,containsRE,"^Content-disposition:\ attachment;$|^Content-Type:\ application/zip;$",Body,containsRE,"(^\s?filename|\tname)="".+\.(zip|rar|t?gz)""" [enabled],"Apple Mail Spam","Apple Mail Spam",16711680,AND,Delete,Automatic,EntireHeader,contains,"X-Mailer: Apple Mail (2.924)",Body,containsRE,"^Content-transfer-encoding:\s7BIT\r\n\r\n^[a-z0-9-'""\s\.,\?]+(\r\n)?http://.+\..{2,3}/(.+\.html)?\r\n",Body,containsRE,"
http://.+/.*
$" [enabled],"Opera Mail Spam","Opera Mail Spam",16711680,AND,Delete,Automatic,EntireHeader,containsRE,"^Content-Type: text/plain; format=flowed; delsp=yes; charset=(koi8-r|ISO-8859-1)",EntireHeader,contains,"Content-Transfer-Encoding: 7bit",EntireHeader,contains,"User-Agent: Opera Mail/9.50 (Win32)",Body,containsRE,"^[a-z3-9,’'\.-\s\?]+(\s|\r\n)http://(www\.)?.+\.(c(om|n)|net|org)/",Body,contains,"Using Opera's revolutionary e-mail client: http://www.opera.com/mail/" [enabled],"SquirrelMail Spam","SquirrelMail Spam",16711680,AND,Delete,EntireHeader,contains,"User-Agent: SquirrelMail/1.4.12" [enabled],"Base 64 Encoded Body","Base 64 Encoded",16711680,AND,Delete,Body,contains,"Content-Transfer-Encoding: base64",Body,doesn'tContain,"Content-Type: image/",Body,doesn'tContainRE,"^Content-Disposition:\ (inline|attachment);",Body,contains,"Content-Type: text/plain;" [enabled],"X-Mailer: The Bat!","X-Mailer: The Bat!",16711680,OR,Delete,Automatic,EntireHeader,contains,"X-Mailer: The Bat! " [enabled],"1 Word Subject","1 Word Subject",16711680,OR,Delete,Subject,containsRE,"^[a-z'""\|\{\}\[\]]{7,8}$",Subject,containsRE,"^\d{7,8}$" [enabled],"Subject All Caps","Subject All Caps",33023,AND,Delete,Subject,doesn'tContainRE,(?-i)[a-z],Subject,containsRE,. [enabled],"No Subject","No Subject",16711680,AND,Delete,Subject,doesn'tContainRE,. [enabled],"Flash Link Spam","Flash Link Spam",16711680,AND,Delete,Body,containsRE,http://.+/.+\.swf [enabled],"Geocities Link","Geocities Link",16711680,AND,Delete,Body,contains,http://www.geocities.com/ [enabled],"Job Scams","Job Scams",16711680,OR,Delete,Subject,containsRE,"(jobs|work)\ (at|from)\ home",Subject,containsRE,"(earn|Make)\ Money\ (at|From)\ (Your\s)?Home",Body,contains,"looking for representatives in the US" [enabled],"Worm - Double Extension Attachment","WORM >Double Extension!!",255,AND,Delete,TakesPrecedence,noreport,Body,contains,"Content-disposition: attachment; filename=",Body,containsRE,"(file)?name="".+\.(gif|jpg)\.(scr|pif|exe|cmd|com)""" [enabled],"Dangerous Attachment Extension","Dangerous Attachment Extension!",255,AND,Delete,TakesPrecedence,noreport,Body,contains,"Content-disposition: attachment;",Body,containsRE,"^\s?filename="".+\.(pif|scr|hta|cmd|bat|vbs|com|cpl|hlp)""" [enabled],"Exe Attachment",".exe attachment",255,AND,TakesPrecedence,noreport,Body,contains,"Content-disposition:\ attachment;",Body,containsRE,"^\s?filename="".+\.exe""" [enabled],".info sender",".info sender",16711680,AND,Delete,From,containsRE,.+@.+\.info [enabled],"Consecutive digits or consonants",digits-consnts,16711680,OR,Hidden,Delete,From,containsRE,\d{4}[\w\.\-]*@,From,containsRE,[bcdfghjklmnpqrstvwxz]{5}[\w\.\-]*@,Subject,containsRE,^[bcdfghjklmnpqrstvwxz]{5}[\w\.\-]* [enabled],"Software Spam","Software Spam",16711680,OR,Delete,Subject,is,Software,Subject,containsRE,"\$oftware|software\ price\$",Subject,containsRE,"(cheap(est)?|downloadable|oem|office|quality).*soft(wares?)|Soft(ware)?\ in\ many\ languages|software\ at\ (amazingly|surprisingly)\ low\ prices|perfectly\ working\ software|software\ immediately\ after\ purchase|ado6e|Vista\ Microsoft\ SP1\ and\ XP\ Cracked|Office\ (Enterprise\ 200[789]|200[789]\ Enterprise)|(?-i)(Access|Communicator|PowerPoint)\ 200[789]|Auto([cC]ad|desk)\ 200[789]",Body,contains,"European languages",Body,contains,"you can download them right after pur",Body,contains,"The best software products at the best prices.",Body,contains,"Microsoft Office Enterprise 2008 includes:",Body,containsRE,"^Retail Price:?\s{1,10}\$\d{3,4}\.[0-9]{2}\r\n^Our Price:?\s{1,10}\$\d{3,4}\.[0-9]{2}",Body,containsRE,"Operational\ systems|newsoft|softwares|Cheap.*soft(ware)?|oem\ssoftware|software\ (you\s)?needs?",Body,containsRE,"SSoftwarr?e|down.?lo.?ad(d?able)?\ (legal\ )?s?so.?ft(ware)?|(Best|cheapest|lowest)\ software\ prices",Body,containsRE,http://.*software.*\.(com|cn|net|org|php|html?),Body,containsRE,^(type|vis[il]t)\s'?.+soft.*\s\.\scom'?\sin\syour\s.nternet\sExplorer,Body,containsRE,"(?-i)Office\ (Enterprise\ 200[789]|200[789]\ Enterprise)|(Access|Communicator|PowerPoint)\ 200[789]|Auto([cC]ad|desk)\ 200[789]" [enabled],"Blocked Countries","Blocked Country",16711680,OR,Delete,EntireHeader,containsRE,"^Received:\ from\ .+\.(ar|br|cn|hinet\.net|kr|my|tpnet\.pl|ro|ru|jp|ng|th|tr)\b\s?" [enabled],Spain,Spain,16711680,OR,Delete,EntireHeader,containsRE,"Received:\ from\ .*\[84\.12[0-3]\.\d{1,3}\.\d{1,3}\]",EntireHeader,contains,".ono.com " [enabled],Turkey,Turkey,16711680,OR,Delete,EntireHeader,containsRE,"^Received:\ from\ (\[(85.10[56]\.\d{1,3}\.\d{1,3}|88\.234\..+\..+|194\.27\.\d{1,3}\.\d{1,3}|195.175\.\d{1,3}\.\d{1,3})\])|.+\.tr\)",EntireHeader,containsRE,"88\.255\.\d{1,3}\.\d{1,3}" [enabled],"Hong Kong Spam","Hong Kong Spam",16711680,OR,Delete,Automatic,Body,containsRE,^http://.+\.hk/\?.+ [enabled],"APNIC (Asia-Pacific)",APNIC,16711808,OR,Delete,EntireHeader,containsRE,"^Received: from [^[]*?\[(6[01]|20[23]|21[01]|21[89]|22[0-2])(\.[1-2]?\d?\d?){3}\]",EntireHeader,containsRE,"^Received: from [^[]*?\[(\[58|\[59]|6[01]|20[23]|21[01]|21[89]|22[0-2])(\.[1-2]?\d?\d?){3}\]" [enabled],"RIPE (Europe)",RIPE,16711808,AND,Delete,EntireHeader,containsRE,"^Received: from [^[]*?\[(62|8[0-2]|19[345]|21[237])(\.[1-2]?\d?\d?){3}\]" [enabled],"LACNIC (Latin America)",LACNIC,16711808,OR,Delete,EntireHeader,containsRE,"^Received: from [^[]*?\[20[01](\.[1-2]?\d?\d?){3}\]",EntireHeader,containsRE,(\.fibertel\.com\.ar|\.cable\.net\.co)\b [enabled],"Thunderbird Spam","Thunderbird Spam",16711680,AND,Delete,EntireHeader,contains,"User-Agent: Thunderbird 2.0.0.16 (Windows/20080708)",EntireHeader,contains,"MIME-Version: 1.0" [enabled],"Yahoo Calendar Invite Spam",filtered,16711680,AND,Delete,EntireHeader,contains,"X-Yahoo-Newman-Property: calendar-invite",EntireHeader,contains,X-Yahoo-Calendar-Iid: [enabled],"Yahoo Search Spam","Search Engine Spam",16711680,AND,Delete,CC,contains,@yahoo.com,Body,contains,http://www.yahoo.com/////////////////////////////,Body,contains,"" [enabled],"Credit Report Spam","Credit Report Spam",16711680,OR,Blacklist,Delete,From,contains,MemberValueChoice,Subject,contains,"your Credit Report",EntireHeader,containsRE,(rhino|rhbino|rhmino)yellow\.com [enabled],"Illegal Drugs","Illegal Drugs",16711680,OR,Hidden,Delete,Automatic,Subject,contains,"legal buds",Body,containsRE,"legal\ buds?\ online" [enabled],"Spam Domains in Header","Spam Domain (H)",16711680,OR,Delete,EntireHeader,containsRE,"^http-x-forwarded-for\ 065\.110\.05[4-5]\.+|sender\@mail1\.unlist\.net|64\.46\.114\.161|\.unlist\.net|codec\.ro|marshall\.cc|matrix\.net|tomparker\@another\-world\.com|mail\.bsbx\.net|bruffner\.com|pretension\.com",EntireHeader,contains,mail2world.com,EntireHeader,contains,dyn.optonline.net,EntireHeader,contains,dsl.brasiltelecom.net.br,EntireHeader,containsRE,^canada\.com$,EntireHeader,containsRE,(prod-infinitum|pongimmediate|vsteals)\.com,EntireHeader,containsRE,(fibertel|freedoomsat)\.com\.ar,EntireHeader,containsRE,"^Received: from (boardermail\.com|bolt\.com|moxmail16|sleepyseed\.com|boardermail\.com|email\.com|eadvertizing|bobolink|hkgolden\.com|1million2006\.com|saurabh\.info|lists\.aikiri\.com)",EntireHeader,containsRE,"Natalee\ Almonte|maintec\.com|Robin\ Keyes|Richard\ K\.\ Lee|ezagenda\.com|thefreesite\.com|hotpop\.com|minnietheminx\.com|malaysia\.net|prod-infinitum\.com|di-ve\.com|playful\.com|mc\.videotron\.ca|mozartmail\.com|adsl\.tele\.dk|routerhoster\.com|mchsi\.com|pollcadot|wise-expectations\.com|westcoastnovelty\.com|authenticinternetpromotions\.com|cliffordwindows\.com|mail4him\.com|bestbidding\.com|KINGCOOLER\.COM\.CN|mixmail\.com|freeoffers4you\.com|hotwireindia\.com|forex\ profits|proper\.com|blackburnmail\.com|andreaeberl\.de|worldnetcams\.com|tvsatbg\.net|online.*bid\.info|hooters" [enabled],"SiteProtect Ebay Phishing Scam","Phishing Scam",255,AND,Delete,TakesPrecedence,ReturnPath,contains,.siteprotect.com,EntireHeader,contains,siteprotect.com,From,contains,"eBay Gifts" [enabled],"Screensaver Trojan","Screensaver Trojan",255,OR,Delete,Subject,is,"Life is beautiful",Subject,is,"Life will be better",Subject,is,"Good summer",Subject,is,"help you",Body,contains,"filename=""bsaver.zip""",Body,contains,"cool screensaver in your attachment!",Body,contains,"Wanna more? Welcome to our site" [enabled],"Stocks spam #1","Stocks spam #1",16711680,OR,Delete,Automatic,Body,containsRE,"^H.?ot\ st.?ock\ ale.?rt",Body,containsRE,"breaking\ mark.?et\ n.?ews",Body,containsRE,"Watc.?h\ this\ sto.?ck\ go\ higher\ and\ higher",Body,containsRE,^((Symbol|Stock)(\s)?:\s){1}([A-Z].?[A-Z].?[A-Z].?),Body,containsRE,"(financial|fina\ ncial|fin\ ancial|fi\ nancial)\sadvice",Body,containsRE,"^Price:?\ \$?\d{0,2}\.\d{2,3}",Body,contains,"within the meaning of Section 27a of the Securities act of 1933",Body,contains,"Information within this email contains ""forward looking",Body,contains,"Expected: This one is going to grow at a rapid rate",Subject,containsRE,"^Read\ this\ before\ .+day" [enabled],"Stocks spam #2","Stocks spam #2",16711680,OR,Delete,Automatic,Subject,containsRE,"^Trade\ Noti(ce|fication)",Subject,containsRE,"g.?oing\ to\ e.?xplode\ on\ (mon|tues|wednes|thurs|fri)day",Subject,containsRE,invest(or|ment)|Dividends,Body,containsRE,stock.?exchange,Body,containsRE,"^U.?RGENT S.?TOCK A.?LERT",Body,contains,"Big News Expected",Body,contains,"Easy walk in price",Body,contains,"MARKET WIRE",Body,contains,"Opening bell message",Subject,containsRE,"\b(Big\ Market|(Market|Trader)\ Alert)\b" [enabled],"Stocks Spam #3","Stocks Spam #3",16711680,OR,Delete,Automatic,Body,contains,"This Is Going To Explode!",Body,containsRE,^(target|current).?price,Body,contains,"stock watch notices",Body,contains,"Stock reporting sites",Body,containsRE,^Sym(bol)?.?:\s[A-Z],Body,containsRE,c.?h.?i.?n.?a\s\w,Body,containsRE,"^j?.u.?m.?p\ o.?n\ t.?h.?i.?s\ f.?i.?r.?s.?t\ t.?h.?i.?n.?g\s",Body,containsRE,"^H.?E.?R.?E\ W.?E\ G.?O\ A.?G.?A.?I.?N\!",Body,containsRE,"^T.?i.{1,2}k.{1,2}:\ \w.?\w.?\w.?\w\s?$",Body,containsRE,"^(S|\$).?y.?m.?b.{0,4}\W?:\ \w.?\w.?\w.?\w\s?$" [enabled],"Stocks Spam #4","Stocks Spam #4",16711680,OR,Hidden,Delete,Body,containsRE,"read\ (up|the)\ (news|release)?",Body,containsRE,"and\ (get\ (all\ over|on))|(move\ on|jump\ on)|(be\ ready\ to)",Body,containsRE,"\bget\ (all\ over|on)\ [A-Z]{4}\ first\ thing\ .+day\b",Body,contains,"Beat the news to the market",Body,containsRE,"^Price\ up\ .{1,4}%",Body,containsRE,"^5.*day\ price: ",Body,contains,"Emergency report. Check",Body,containsRE,"pushed\ share\ prices\ up\ over\ \d{1,3}%",Body,contains,"The Gold Watcher",Body,contains,"is climbing hard. UP" [disabled],"Fake Daily Top 10","Exploit Link",16711680,AND,Delete,Subject,contains,"CNN.com Daily Top 10",From,contains,"Daily Top 10",From,doesn'tContain,cnn.com [disabled],"Fake CNN Alerts","Exploit Link",16711680,AND,Delete,Automatic,Subject,contains,"CNN Alerts: ",From,doesn'tContain,cnn.com,EntireHeader,doesn'tContainRE,"^Received:\ from\ .+\.cnn\.com\ \(\[64\.236\.31\.[0-9]+\]\)$" [disabled],"Fake Msnbc Alerts","Exploit Link",16711680,AND,Delete,Automatic,Subject,contains,"msnbc.com - BREAKING NEWS:",From,doesn'tContain,msnbc.com,EntireHeader,doesn'tContain,"Received: from lists.msnbc.com" [disabled],"Example filter - Mail sent to ""Undisclosed recipients"" (ie not specifically me)","undisclosed recipients",16711680,AND,Delete,To,contains,undisclosed,To,contains,recipients