blob: 018ad153472ea6dcf48f65c242b4afa51ca61321 [file] [log] [blame]
# Using score set 1 logs for revision 1925604 from:
# ham-net-ena-week0.r1925604.log ham-net-ena-week1.r1925604.log ham-net-ena-week4.r1925604.log ham-net-giovanni-ham.r1925604.log ham-net-giovanni-spam.r1925604.log ham-net-grenier.r1925604.log ham-net-jhardin.r1925604.log ham-net-llanga.r1925604.log ham-net-mmiroslaw-mails-ham.r1925604.log ham-net-mmiroslaw-mails-spam.r1925604.log ham-net-spamsponge.r1925604.log ham-net-tsz-corpus.r1925604.log ham-net-whyscream.r1925604.log spam-net-ena-week0.r1925604.log spam-net-ena-week1.r1925604.log spam-net-ena-week4.r1925604.log spam-net-giovanni-ham.r1925604.log spam-net-giovanni-spam.r1925604.log spam-net-grenier.r1925604.log spam-net-jhardin.r1925604.log spam-net-llanga.r1925604.log spam-net-mmiroslaw-mails-ham.r1925604.log spam-net-mmiroslaw-mails-spam.r1925604.log spam-net-spamsponge.r1925604.log spam-net-tsz-corpus.r1925604.log spam-net-whyscream.r1925604.log
score ACCT_PHISHING_MANY 2.999
score AC_BR_BONANZA 0.001
score AC_DIV_BONANZA 0.001
score AC_FROM_MANY_DOTS 2.500
score AC_HTML_NONSENSE_TAGS 1.200
score ADMITS_SPAM 1.999
score ADVANCE_FEE_2_NEW_FORM 0.725
score ADVANCE_FEE_2_NEW_FRM_MNY 0.001
score ADVANCE_FEE_2_NEW_MONEY 0.508
score ADVANCE_FEE_3_NEW 3.499
score ADVANCE_FEE_3_NEW_FRM_MNY 2.450
score ADVANCE_FEE_3_NEW_MONEY 1.398
score ADVANCE_FEE_4_NEW 2.699
score ADVANCE_FEE_4_NEW_FRM_MNY 2.399
score ADVANCE_FEE_4_NEW_MONEY 0.001
score ADVANCE_FEE_5_NEW 2.337
score ADVANCE_FEE_5_NEW_FRM_MNY 0.001
score ADVANCE_FEE_5_NEW_MONEY 1.389
score AMAZON_IMG_NOT_RCVD_AMZN 2.499
score AXB_XMAILER_MIMEOLE_OL_1ECD5 2.081
score BIGNUM_EMAILS_FREEM 2.999
score BIGNUM_EMAILS_MANY 1.366
score BITCOIN_DEADLINE 2.999
score BITCOIN_EXTORT_01 0.001
score BITCOIN_MALF_HTML 2.934
score BITCOIN_MALWARE 1.686
score BITCOIN_SPAM_02 2.499
score BITCOIN_SPAM_03 0.001
score BITCOIN_SPAM_05 2.499
score BITCOIN_SPAM_07 3.260
score BITCOIN_TOEQFM 3.499
score BITCOIN_VISTA 0.537
score BITCOIN_XPRIO 0.455
score BITCOIN_YOUR_INFO 1.462
score BODY_URI_ONLY 0.001
score BOGUS_MIME_VERSION 0.001
score BOGUS_MSM_HDRS 0.867
score COMPENSATION 1.499
score CONTENT_AFTER_HTML_WEAK 1.499
score CTE_8BIT_MISMATCH 0.001
score DATE_IN_FUTURE_Q_PLUS 2.309
score DEAR_BENEFICIARY 0.246
score DKIMWL_BL 1.211
score DKIMWL_WL_HIGH -0.287
score DKIMWL_WL_MED -0.498
score DKIMWL_WL_MEDHI -0.001
score DOS_BODY_HIGH_NO_MID 3.496
score DSN_NO_MIMEVERSION 1.999
score DYNAMIC_IMGUR 3.999
score ENCRYPTED_MESSAGE -0.998
score END_FUTURE_EMAILS 2.105
score EXCUSE_24 1.703
score FACEBOOK_IMG_NOT_RCVD_FB 1.999
score FBI_SPOOF 0.001
score FILL_THIS_FORM 0.001
score FONT_INVIS_LONG_LINE 1.669
score FONT_INVIS_MSGID 2.497
score FONT_INVIS_NORDNS 1.214
score FONT_INVIS_POSTEXTRAS 1.391
score FORGED_SPF_HELO 1.528
score FORM_FRAUD 1.000
score FORM_FRAUD_3 0.001
score FORM_FRAUD_5 0.001
score FREEMAIL_FORGED_FROMDOMAIN 0.001
score FROM_ADDR_WS 0.533
score FROM_FMBLA_NEWDOM 0.248
score FROM_FMBLA_NEWDOM14 0.999
score FROM_FMBLA_NEWDOM28 0.798
score FROM_GOV_DKIM_AU -0.345
score FROM_GOV_SPOOF 0.998
score FROM_IN_TO_AND_SUBJ 2.599
score FROM_LONG_DOM 0.312
score FROM_LONG_DOM_MINFP 2.497
score FROM_MISSP_FREEMAIL 0.001
score FROM_MISSP_MSFT 0.001
score FROM_MISSP_REPLYTO 0.001
score FROM_MISSP_SPF_FAIL 0.001
score FROM_MISSP_USER 0.001
score FROM_NTLD_LINKBAIT 1.999
score FROM_NTLD_REPLY_FREEMAIL 0.044
score FROM_SUSPICIOUS_NTLD 0.498
score FROM_SUSPICIOUS_NTLD_FP 1.997
score FROM_UNBAL1 2.445
score FROM_UNBAL2 2.799
score FROM_WSP_TRAIL 2.899
score FSL_BULK_SIG 0.001
score FSL_NEW_HELO_USER 0.001
score FUZZY_BITCOIN 1.578
score FUZZY_DR_OZ 0.947
score FUZZY_IMPORTANT 3.180
score FUZZY_PRIVACY 2.152
score FUZZY_SECURITY 2.399
score FUZZY_WALLET 0.240
score GAPPY_HTML 2.699
score GB_BITCOIN_NH 0.001
score GB_CUSTOM_HTM_URI 1.499
score GB_FREEMAIL_DISPTO 0.165
score GB_FREEMAIL_DISPTO_NOTFREEM 0.499
score GB_HASHBL_BTC 4.166
score GOOG_REDIR_FRAUD 1.499
score GOOG_REDIR_HTML_ONLY 0.001
score GOOG_REDIR_NORDNS 0.001 # force non-zero
score GOOG_REDIR_NOTRDNS 1.499
score GOOG_REDIR_STATICRDNS 1.498
score GOOG_STO_EMAIL_PHISH 1.977
score GOOG_STO_IMG_HTML 2.999
score GOOG_STO_IMG_NOHTML 2.499
score GOOG_STO_NOIMG_HTML 2.996
score HDRS_LCASE 0.099
score HDRS_MISSP 2.499
score HDR_ORDER_FTSDMCXX_DIRECT 0.360
score HDR_ORDER_FTSDMCXX_NORDNS 0.835
score HEADER_FROM_DIFFERENT_DOMAINS 0.001
score HELO_NO_DOMAIN 0.001
score HK_LOTTO 1.000
score HK_NAME_FM_MR_MRS 0.001
score HK_NAME_MR_MRS 0.857
score HK_RANDOM_ENVFROM 0.001
score HK_RANDOM_FROM 0.998
score HK_RANDOM_REPLYTO 0.999
score HK_RCVD_IP_MULTICAST 1.999
score HK_SCAM 0.001
score HK_WIN 0.943
score HOSTED_IMG_DIRECT_MX 3.499
score HOSTED_IMG_FREEM 0.001
score HOSTED_IMG_MULTI_PUB_01 0.142
score HREF_EMPTY_NORDNS 0.001
score HTML_BADATTR 0.999
score HTML_ENTITY_ASCII 0.001
score HTML_FONT_TINY_NORDNS 0.001
score HTML_SINGLET_MANY 2.499
score HTML_TEXT_INVISIBLE_FONT 1.112
score HTML_TEXT_INVISIBLE_STYLE 0.001 # force non-zero
score IMG_ONLY_FM_DOM_INFO 0.236
score KHOP_HELO_FCRDNS 0.399
score LIST_PARTIAL 0.998
score LIST_PARTIAL_SHORT_MSG 0.830
score LONGLN_LOW_CONTRAST 2.499
score LONG_IMG_URI 0.001
score LONG_INVISIBLE_TEXT 1.151
score LOTS_OF_MONEY 0.010
score LOTTO_AGENT 0.001
score LOTTO_DEPT 1.999
score MALFORMED_FREEMAIL 2.409
score MALWARE_PASSWORD 2.717
score MALW_ATTACH 2.499
score MANY_SPAN_IN_TEXT 0.002
score MANY_SUBDOM 3.099
score MILLION_HUNDRED 0.001
score MILLION_USD 1.250
score MIMEOLE_DIRECT_TO_MX 0.001 # force non-zero
score MIXED_CENTER_CASE 2.499
score MIXED_ES 2.476
score MIXED_HREF_CASE 0.001
score MIXED_IMG_CASE 2.999
score MONEY_ATM_CARD 0.001
score MONEY_FORM 0.001
score MONEY_FORM_SHORT 0.001
score MONEY_FRAUD_3 3.099
score MONEY_FRAUD_5 0.001
score MONEY_FRAUD_8 0.001
score MONEY_FREEMAIL_REPTO 0.978
score MONEY_FROM_41 0.001
score MONEY_FROM_MISSP 0.001
score NA_DOLLARS 1.499
score NEW_PRODUCTS 1.249
score NICE_REPLY_A -0.633
score NO_FM_NAME_IP_HOSTN 0.001
score NSL_RCVD_FROM_USER 0.001
score NSL_RCVD_HELO_USER 0.001
score OBFU_BITCOIN 2.551
score ODD_FREEM_REPTO 1.846
score ORDER_TODAY 1.657
score PAYPAL_PHISH_07 0.001 # force non-zero
score PDS_BAD_THREAD_QP_64 0.542
score PDS_BTC_ID 0.498
score PDS_BTC_MSGID 0.001
score PDS_FRNOM_TODOM_DBL_URL 1.498
score PDS_HELO_SPF_FAIL 0.001
score PDS_NAKED_TO_NUMERO 1.999
score PDS_OTHER_BAD_TLD 1.997
score PDS_PRO_TLD 0.998
score PHISH_ATTACH 2.499
score PHP_SCRIPT 2.499
score POSSIBLE_PAYPAL_PHISH_10 0.001
score PP_MIME_FAKE_ASCII_TEXT 0.001
score RATWARE_NO_RDNS 0.001
score RCVD_IN_IADB_ESP -0.001
score RCVD_IN_VALIDITY_CERTIFIED_BLOCKED 0.001
score RCVD_IN_VALIDITY_RPBL_BLOCKED 0.001
score RCVD_IN_VALIDITY_SAFE_BLOCKED 0.001
score REPTO_419_FRAUD_GM 0.379
score REPTO_419_FRAUD_GM_LOOSE 0.999
score RISK_FREE 0.944
score SCC_CANSPAM_2 2.455
score SCC_ISEMM_LID_1B 1.499
score SHOPIFY_IMG_NOT_RCVD_SFY 2.497
score SHORTENER_SHORT_IMG 2.120
score SHORT_IMG_SUSP_NTLD 1.164
score SPOOFED_FREEMAIL 0.001
score SPOOFED_FREEMAIL_NO_RDNS 0.001
score SPOOFED_FREEM_REPTO 2.497
score SPOOF_GMAIL_MID 0.412
score STATIC_XPRIO_OLE 1.997
score SUBJ_ATTENTION 0.001
score SUBJ_BROKEN_WORD 1.131
score SUSP_UTF8_WORD_COMBO 2.309
score SUSP_UTF8_WORD_FROM 1.999
score SUSP_UTF8_WORD_SUBJ 1.412
score TEQF_USR_POLITE 1.369
score THIS_AD 2.497
score TO_EQ_FM_DIRECT_MX 0.001
score TO_EQ_FM_DOM_HTML_ONLY 0.700
score TO_EQ_FM_DOM_SPF_FAIL 0.001 # force non-zero
score TO_EQ_FM_SPF_FAIL 0.001
score TO_IN_SUBJ 0.099
score TO_NAME_SUBJ_NO_RDNS 1.607
score TO_NO_BRKTS_HTML_IMG 0.001
score TO_NO_BRKTS_HTML_ONLY 1.997
score TO_NO_BRKTS_MSFT 0.001
score TO_NO_BRKTS_NORDNS_HTML 0.001
score TO_NO_BRKTS_PCNT 2.499
score TVD_SPACE_ENCODED 2.499
score TVD_SPACE_RATIO_MINFP 2.497
score UNDISC_FREEM 2.899
score UNDISC_MONEY 2.634
score UNICODE_OBFU_ASC 2.499
score UNICODE_OBFU_ZW_MANY 0.001
score UPPERCASE_URI 3.699
score URIBL_CT_SURBL 2.097
score URI_BUFFLY 1.999
score URI_DOTEDU 0.001
score URI_DWEBIPFS 1.749
score URI_EXCESS_SLASHES 2.497
score URI_FIREBASEAPP 2.999
score URI_GOOGDRAWPREVIEW 2.160
score URI_GOOGLE_PROXY 0.001
score URI_GOOG_STO_SPAMMY 2.996
score URI_IMG_CWINDOWSNET 2.291
score URI_IPFS 0.001
score URI_IPFSIO 1.012
score URI_PHISH 0.207
score URI_TRY_3LD 1.997
score URI_WPADMIN 0.001
score URI_WP_DIRINDEX 0.001
score URI_WP_HACKED 0.001
score URI_WP_HACKED_2 2.499
score VFY_ACCT_NORDNS 1.602
score WIKI_IMG 1.770
score WORD_INVIS_MANY 1.437
score XFER_LOTSA_MONEY 0.001
score XM_RANDOM 2.499
score XPRIO 0.001
score XPRIO_VISTA 2.301
score YOUR_DELIVERY_ADDRESS 1.249
score YOU_INHERIT 2.609
score AC_POST_EXTRAS 1.000
score AC_SPAMMY_URI_PATTERNS1 1.000
score AC_SPAMMY_URI_PATTERNS10 1.000
score AC_SPAMMY_URI_PATTERNS11 1.000
score AC_SPAMMY_URI_PATTERNS12 1.000
score AC_SPAMMY_URI_PATTERNS2 1.000
score AC_SPAMMY_URI_PATTERNS3 1.000
score AC_SPAMMY_URI_PATTERNS4 1.000
score AC_SPAMMY_URI_PATTERNS8 1.000
score AC_SPAMMY_URI_PATTERNS9 1.000
score ADULT_DATING_COMPANY 10.000
score AD_PREFS 0.250
score ALIBABA_IMG_NOT_RCVD_ALI 1.000
score APP_DEVELOPMENT_FREEM 1.000
score APP_DEVELOPMENT_NORDNS 1.000
score BEBEE_IMG_NOT_RCVD_BB 1.000
score BITCOIN_BOMB 1.000
score BITCOIN_EXTORT_02 1.000
score BITCOIN_IMGUR 1.000
score BITCOIN_OBFU_SUBJ 1.000
score BITCOIN_ONAN 1.000
score BITCOIN_PAY_ME 1.000
score BITCOIN_SPAM_01 1.000
score BITCOIN_SPAM_04 1.000
score BITCOIN_SPAM_06 1.000
score BITCOIN_SPAM_08 1.000
score BITCOIN_SPAM_09 1.000
score BITCOIN_SPAM_10 1.000
score BITCOIN_SPAM_11 1.000
score BITCOIN_SPAM_12 1.000
score BITCOIN_SPF_ONLYALL 1.000
score BOMB_FREEM 1.000
score BOMB_MONEY 1.000
score BTC_ORG 1.000
score BULK_RE_SUSP_NTLD 1.000
score CANT_SEE_AD 1.000
score COMMENT_GIBBERISH 1.000
score CONTENT_AFTER_HTML 1.000
score DAY_I_EARNED 1.000
score DKIMWL_BLOCKED 0.001
score DOTGOV_IMAGE 1.000
score EBAY_IMG_NOT_RCVD_EBAY 1.000
score ENVFROM_GOOG_TRIX 1.000
score FBI_MONEY 1.000
score FONT_INVIS_DIRECT 1.000
score FONT_INVIS_DOTGOV 1.000
score FONT_INVIS_HTML_NOHTML 1.000
score FOUND_YOU 1.000
score FREEM_FRNUM_UNICD_EMPTY 1.000
score FRNAME_IN_MSG_XPRIO_NO_SUB 1.000
score FROM_BANK_NOAUTH 1.000
score FROM_FMBLA_NDBLOCKED 0.001
score FROM_GOV_REPLYTO_FREEMAIL 1.000
score FROM_NEWDOM_BTC 1.000
score FROM_NUMBERO_NEWDOMAIN 1.000
score FROM_PAYPAL_SPOOF 1.000
score GAPPY_SALES_LEADS_FREEM 1.000
score GB_FAKE_RF_SHORT 1.000
score GB_FORGED_MUA_POSTFIX 1.000
score GB_GOOGLE_OBFUR 0.750
score GOOGLE_DOCS_PHISH 1.000
score GOOGLE_DOCS_PHISH_MANY 1.000
score GOOGLE_DOC_SUSP 1.000
score GOOGLE_DRIVE_REPLY_BAD_NTLD 1.000
score GOOG_MALWARE_DNLD 1.000
score GOOG_REDIR_SHORT 1.000
score GOOG_STO_HTML_PHISH 1.000
score GOOG_STO_HTML_PHISH_MANY 1.000
score HAS_X_NO_RELAY 1.000
score HAS_X_OUTGOING_SPAM_STAT 1.000
score HEXHASH_WORD 1.000
score HK_CTE_RAW 1.000
score HOSTED_IMG_DQ_UNSUB 1.000
score HOSTED_IMG_MULTI 1.000
score HREF_EMPTY_PHPMAIL 1.000
score HREF_EMPTY_XANTIABUSE 1.000
score HREF_EMPTY_XAUTHED 1.000
score HTML_ENTITY_ASCII_TINY 1.000
score HTML_OFF_PAGE 1.000
score HTML_SHRT_CMNT_OBFU_MANY 1.000
score JH_SPAMMY_HEADERS 1.000
score JH_SPAMMY_PATTERN01 1.000
score JH_SPAMMY_PATTERN02 1.000
score LINKEDIN_IMG_NOT_RCVD_LNKN 1.000
score LIST_PRTL_PUMPDUMP 1.000
score LIST_PRTL_SAME_USER 1.000
score LONG_HEX_URI 1.000
score LUCRATIVE 1.000
score MALF_HTML_B64 1.000
score MALWARE_NORDNS 1.000
score MIME_NO_TEXT 1.000
score MIXED_AREA_CASE 1.000
score MIXED_FONT_CASE 1.000
score MONERO_DEADLINE 1.000
score MONERO_EXTORT_01 1.000
score MONERO_MALWARE 1.000
score MONERO_PAY_ME 1.000
score MSGID_DOLLARS_URI_IMG 1.000
score MSGID_HDR_MALF 1.000
score MSM_PRIO_REPTO 1.000
score NEWEGG_IMG_NOT_RCVD_NEGG 1.000
score PHISH_AZURE_CLOUDAPP 3.500
score PHISH_FBASEAPP 1.000
score PHP_NOVER_MUA 1.000
score PHP_ORIG_SCRIPT 1.000
score PHP_SCRIPT_MUA 1.000
score POSSIBLE_PAYPAL_PHISH_02 1.000
score POSSIBLE_PAYPAL_PHISH_04 1.000
score PP_TOO_MUCH_UNICODE02 0.500
score PP_TOO_MUCH_UNICODE05 1.000
score PUMPDUMP 1.000
score PUMPDUMP_MULTI 1.000
score RAND_HEADER_LIST_SPOOF 1.000
score RAND_HEADER_MANY 1.000
score RAND_MKTG_HEADER 1.000
score RCVD_DOTEDU_SHORT 1.000
score RCVD_DOTEDU_SUSP_URI 1.000
score RDNS_NUM_TLD_ATCHNX 1.000
score RDNS_NUM_TLD_XM 1.000
score REPTO_419_FRAUD 1.000
score REPTO_419_FRAUD_AOL 1.000
score REPTO_419_FRAUD_AOL_LOOSE 1.000
score REPTO_419_FRAUD_CNS 1.000
score REPTO_419_FRAUD_HM 1.000
score REPTO_419_FRAUD_OL 1.000
score REPTO_419_FRAUD_OL_LOOSE 1.000
score REPTO_419_FRAUD_PM 1.000
score REPTO_419_FRAUD_QQ 1.000
score REPTO_419_FRAUD_YH 1.000
score REPTO_419_FRAUD_YH_LOOSE 1.000
score REPTO_419_FRAUD_YJ 1.000
score REPTO_419_FRAUD_YN 1.000
score SCC_ISEMM_LID_1 1.000
score SENDGRID_REDIR_PHISH 1.000
score SEO_SUSP_NTLD 1.000
score SHY_OBFU_EXPIRE 1.000
score SHY_OBFU_PASSWORD 1.000
score SPOOFED_FREEM_REPTO_CHN 1.000
score SPOOFED_FREEM_REPTO_RUS 1.000
score STOCK_TIP 1.000
score SUBJ_BRKN_WORDNUMS 1.000
score SYSADMIN 1.000
score TAGSTAT_IMG_NOT_RCVD_TGST 1.000
score TARINGANET_IMG_NOT_RCVD_TN 1.000
score THIS_IS_ADV_SUSP_NTLD 1.000
score TONLINE_FAKE_DKIM 1.000
score TW_GIBBERISH_MANY 1.000
score UC_GIBBERISH_OBFU 1.000
score UNICODE_OBFU_ZW 1.000
score UNSUB_GOOG_FORM 1.000
score URI_ADOBESPARK 1.000
score URI_AZURE_CLOUDAPP 1.000
score URI_CLOUDFLAREIPFS 1.000
score URI_DASHGOVEDU 1.000
score URI_DATA 1.000
score URI_DOTEDU_ENTITY 1.000
score URI_FLKIPFSXYZIPFS 1.000
score URI_GLITCHME 1.000
score URI_GOOGDRAWPREVIEW_MINFP 1.000
score URI_HEX_IP 1.000
score URI_IMG_WP_REDIR 1.000
score URI_INFURAIPFSIO 1.000
score URI_LONG_REPEAT 1.000
score URI_ONLY_MSGID_MALF 1.000
score URI_OPTOUT_3LD 1.000
score URI_PHP_REDIR 1.000
score URI_TRY_USME 1.000
score USB_DRIVES 1.000
score VISTA_COST 1.000
score VISTA_TONOM_EQ_TOLOC 1.000
score VPS_NO_NTLD 1.000
score WALMART_IMG_NOT_RCVD_WAL 1.000
score WORD_INVIS 1.000
score XM_DIGITS_ONLY 1.000
score XPRIO_SHORT_SUBJ 1.000
# in active.list but have no hits in recent corpus
score SENDGRID_REDIR 0.001 # force non-zero