File: //proc/self/root/home/awaldron/mail/.spam/new/1285702066.H12312P9735.www2.pit.tblive.com,S=3951
Return-path: <protonks78@rdzeng.com>
Envelope-to: billing@alanwaldron.com
Delivery-date: Tue, 28 Sep 2010 15:27:46 -0400
Received: from [92.255.145.167] (helo=173.193.223.134-static.reverse.softlayer.com)
by www2.pit.tblive.com with esmtp (Exim 4.69)
(envelope-from <protonks78@rdzeng.com>)
id 1P0fq4-0002Wq-HM
for billing@alanwaldron.com; Tue, 28 Sep 2010 15:27:45 -0400
Received: from [173.193.223.134] (port=6006 helo=izumi)
by mail.rdzeng.com with asmtp
id 766B07-0004E0-38
for <billing@alanwaldron.com>; Wed, 29 Sep 2010 01:27:39 +0500
Message-ID: <CC7EF35F2E0F45AD8969E95191FDDA2E@izumi>
From: "Ila Lyles" <protonks78@rdzeng.com>
To: <billing@alanwaldron.com>
Date: Wed, 29 Sep 2010 01:27:39 +0500
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0011_01CB5F43.36DAFD40"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Windows Mail 6.0.6001.18000
X-MimeOLE: Produced By Microsoft MimeOLE V6.0.6001.18049
X-Spam: Not detected
X-Mras: Ok
X-Spam-Status: Yes, score=17.9
X-Spam-Score: 179
X-Spam-Bar: +++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "www2.pit.tblive.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD> <META http-equiv=Content-Type content="text/html; = charset=iso-8859-1">
<META content="MSHTML 6.00.6001.18099" name=GENERATOR> </HEAD> <BODY bgColor=#ffffff>
</head> <body> </p>My friend!</p> </p>On our website there is any porn! New
45665 video!</p> <a href="http://www.revillapromotions.com/images/se">Enter
bravely</a> </p> [...]
Content analysis details: (17.9 points, 6.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
3.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100%
[score: 1.0000]
4.4 HELO_DYNAMIC_IPADDR2 Relay HELO'd using suspicious hostname (IP addr
2)
3.5 HELO_DYNAMIC_SPLIT_IP Relay HELO'd using suspicious hostname (Split
IP)
0.9 RCVD_IN_PBL RBL: Received via a relay in Spamhaus PBL
[92.255.145.167 listed in zen.spamhaus.org]
2.1 RCVD_NUMERIC_HELO Received: contains an IP address used for HELO
1.5 URIBL_WS_SURBL Contains an URL listed in the WS SURBL blocklist
[URIs: revillapromotions.com]
2.0 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URIs: kmu.edu.tw]
0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS
X-Spam-Flag: YES
Subject: ***SPAM*** A lesbian couple with an age difference from Mike
This is a multi-part message in MIME format.
------=_NextPart_000_0011_01CB5F43.36DAFD40
Content-Type: multipart/alternative;
boundary="----=_NextPart_001_0012_01CB5F43.36DAFD40"
------=_NextPart_001_0012_01CB5F43.36DAFD40
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =3D
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.6001.18099" name=3DGENERATOR>
</HEAD>
<BODY bgColor=3D#ffffff>
</head>
<body>
</p>My friend!</p>
</p>On our website there is any porn! New 45665 video!</p>
<a href=3D"http://www.revillapromotions.com/images/se">Enter bravely</a> </=
p>
More Pron - here!!! =3D> http://d95.kmu.edu.tw/as/</BODY></HTML>
------=_NextPart_001_0012_01CB5F43.36DAFD40--
------=_NextPart_000_0011_01CB5F43.36DAFD40
Content-Type: ;
name=""
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="dittburn.jpg"
Content-ID: <7acf0788$21e9833e$6c822ecf>
c2F2ZQ==
------=_NextPart_000_0011_01CB5F43.36DAFD40--