blob: da5695c144b82ef29a956c05618193576e1ef67c [file] [log] [blame]
# Using score set 0 logs for revision 1891844 from:
# ham-darxus.r1891844.log ham-ena-week0.r1891844.log ham-ena-week1.r1891844.log ham-ena-week2.r1891844.log ham-ena-week3.r1891844.log ham-ena-week4.r1891844.log ham-giovanni-ham.r1891844.log ham-giovanni-spammy.r1891844.log ham-giovanni-spam.r1891844.log ham-grenier.r1891844.log ham-hege.r1891844.log ham-llanga.r1891844.log ham-mmiroslaw-mails-ham.r1891844.log ham-mmiroslaw-mails-spam.r1891844.log ham-pds.r1891844.log ham-spamsponge.r1891844.log ham-thendrikx.r1891844.log ham-tsz-spam-corpus.r1891844.log spam-darxus.r1891844.log spam-ena-week0.r1891844.log spam-ena-week1.r1891844.log spam-ena-week2.r1891844.log spam-ena-week3.r1891844.log spam-ena-week4.r1891844.log spam-giovanni-ham.r1891844.log spam-giovanni-spammy.r1891844.log spam-giovanni-spam.r1891844.log spam-grenier.r1891844.log spam-hege.r1891844.log spam-llanga.r1891844.log spam-mmiroslaw-mails-ham.r1891844.log spam-mmiroslaw-mails-spam.r1891844.log spam-pds.r1891844.log spam-spamsponge.r1891844.log spam-thendrikx.r1891844.log spam-tsz-spam-corpus.r1891844.log
score ACCT_PHISHING_MANY 2.996
score AC_BR_BONANZA 0.001
score AC_DIV_BONANZA 0.001
score AC_FROM_MANY_DOTS 2.996
score AC_HTML_NONSENSE_TAGS 1.897
score ADMITS_SPAM 3.595
score ADVANCE_FEE_2_NEW_FORM 0.001
score ADVANCE_FEE_2_NEW_FRM_MNY 2.497
score ADVANCE_FEE_2_NEW_MONEY 1.997
score ADVANCE_FEE_3_NEW 3.066
score ADVANCE_FEE_3_NEW_FRM_MNY 1.811
score ADVANCE_FEE_3_NEW_MONEY 2.083
score ADVANCE_FEE_4_NEW 2.696
score ADVANCE_FEE_4_NEW_FRM_MNY 2.464
score ADVANCE_FEE_4_NEW_MONEY 0.488
score ADVANCE_FEE_5_NEW 2.796
score ADVANCE_FEE_5_NEW_FRM_MNY 1.578
score ADVANCE_FEE_5_NEW_MONEY 0.001
score AD_PREFS 0.095
score ALIBABA_IMG_NOT_RCVD_ALI 2.497
score AMAZON_IMG_NOT_RCVD_AMZN 1.645
score APP_DEVELOPMENT_NORDNS 1.997
score AXB_XMAILER_MIMEOLE_OL_024C2 0.001
score AXB_XMAILER_MIMEOLE_OL_1ECD5 1.812
score BEBEE_IMG_NOT_RCVD_BB 1.656
score BIGNUM_EMAILS_FREEM 2.996
score BIGNUM_EMAILS_MANY 2.996
score BITCOIN_MALF_HTML 3.497
score BITCOIN_ONAN 2.996
score BITCOIN_SPAM_02 1.857
score BITCOIN_SPAM_03 2.497
score BITCOIN_SPAM_07 3.497
score BITCOIN_XPRIO 0.001 # force non-zero
score BITCOIN_YOUR_INFO 2.996
score BOGUS_MIME_VERSION 3.496
score BOGUS_MSM_HDRS 1.300
score BULK_RE_SUSP_NTLD 0.998
score CK_HELO_GENERIC 0.249
score CONTENT_AFTER_HTML 2.497
score CTE_8BIT_MISMATCH 0.998
score DEAR_BENEFICIARY 3.096
score DETAILS_OF_PRODUCT 1.248
score DX_TEXT_03 0.899
score EBAY_IMG_NOT_RCVD_EBAY 0.882
score ENCRYPTED_MESSAGE -0.898
score FACEBOOK_IMG_NOT_RCVD_FB 1.997
score FAKE_REPLY_A1 3.995
score FAKE_REPLY_B 3.895
score FILL_THIS_FORM 1.198
score FONT_INVIS_DIRECT 2.395
score FONT_INVIS_DOTGOV 3.497
score FONT_INVIS_HTML_NOHTML 2.996
score FONT_INVIS_LONG_LINE 2.996
score FONT_INVIS_MSGID 2.497
score FONT_INVIS_NORDNS 2.123
score FORM_FRAUD_5 0.001
score FOUND_YOU 3.246
score FREEMAIL_FORGED_FROMDOMAIN 0.249
score FROMSPACE 3.096
score FROM_2_EMAILS_SHORT 2.568
score FROM_IN_TO_AND_SUBJ 2.498
score FROM_MISSPACED 1.891
score FROM_MISSP_DYNIP 0.001
score FROM_MISSP_EH_MATCH 0.001
score FROM_MISSP_FREEMAIL 2.500
score FROM_MISSP_MSFT 0.001
score FROM_MISSP_PHISH 3.496
score FROM_MISSP_USER 0.001
score FROM_MULTI_NORDNS 0.353
score FROM_NAME_EQ_TO_G_DRIVE 0.402
score FROM_NTLD_REPLY_FREEMAIL 1.579
score FROM_SUSPICIOUS_NTLD 0.498
score FROM_SUSPICIOUS_NTLD_FP 1.998
score FSL_CTYPE_WIN1251 0.001 # force non-zero
score FSL_HELO_FAKE 3.096
score FSL_NEW_HELO_USER 0.001
score FUZZY_AMAZON 2.497
score GB_FREEMAIL_DISPTO 0.499
score GB_FREEMAIL_DISPTO_NOTFREEM 0.498
score GOOGLE_DOC_SUSP 2.495
score GOOG_REDIR_NORDNS 3.399
score GOOG_STO_EMAIL_PHISH 2.293
score GOOG_STO_HTML_PHISH 2.061
score GOOG_STO_HTML_PHISH_MANY 3.216
score GOOG_STO_IMG_HTML 2.996
score GOOG_STO_NOIMG_HTML 2.996
score HAS_X_OUTGOING_SPAM_STAT 1.997
score HDRS_LCASE_IMGONLY 0.098
score HDRS_MISSP 1.693
score HDR_ORDER_FTSDMCXX_DIRECT 1.348
score HDR_ORDER_FTSDMCXX_NORDNS 0.001
score HEADER_FROM_DIFFERENT_DOMAINS 0.249
score HELO_NO_DOMAIN 0.001 # force non-zero
score HK_NAME_FM_MR_MRS 1.498
score HK_NAME_MR_MRS 0.998
score HK_RANDOM_ENVFROM 0.998
score HK_RANDOM_FROM 0.998
score HK_RANDOM_REPLYTO 0.998
score HK_SCAM 0.483
score HOSTED_IMG_DIRECT_MX 1.768
score HOSTED_IMG_FREEM 3.497
score HOSTED_IMG_MULTI 1.092
score HOSTED_IMG_MULTI_PUB_01 2.997
score HTML_ENTITY_ASCII 2.999
score HTML_OFF_PAGE 2.996
score HTML_TAG_BALANCE_CENTER 2.097
score HTML_TEXT_INVISIBLE_STYLE 2.083
score IMG_ONLY_FM_DOM_INFO 1.275
score JH_SPAMMY_HEADERS 3.496
score LINKEDIN_IMG_NOT_RCVD_LNKN 2.497
score LONG_HEX_URI 2.996
score LONG_IMG_URI 0.890
score LONG_INVISIBLE_TEXT 1.735
score LOTS_OF_MONEY 0.010
score LOTTO_AGENT 0.986
score LOTTO_DEPT 1.997
score MALWARE_NORDNS 2.103
score MANY_SPAN_IN_TEXT 2.397
score MILLION_HUNDRED 3.196
score MILLION_USD 0.216
score MIMEOLE_DIRECT_TO_MX 0.553
score MIXED_AREA_CASE 1.547
score MIXED_CENTER_CASE 1.630
score MIXED_ES 2.997
score MIXED_FONT_CASE 1.342
score MIXED_HREF_CASE 1.896
score MIXED_IMG_CASE 2.570
score MONEY_ATM_CARD 1.911
score MONEY_FORM 0.001
score MONEY_FORM_SHORT 1.239
score MONEY_FRAUD_3 0.001
score MONEY_FRAUD_5 0.657
score MONEY_FRAUD_8 0.785
score MONEY_FREEMAIL_REPTO 2.996
score MONEY_FROM_41 1.997
score MONEY_FROM_MISSP 0.001
score MONEY_NOHTML 1.671
score MSGID_WSP_TRAIL 1.062
score MSMAIL_PRI_ABNORMAL 0.314
score NAME_EMAIL_DIFF 1.917
score NA_DOLLARS 0.829
score NEW_PRODUCTS 1.248
score NICE_REPLY_A -0.246
score NOT_SPAM 3.296
score NO_FM_NAME_IP_HOSTN 0.288
score NSL_RCVD_FROM_USER 0.001
score NSL_RCVD_HELO_USER 0.001
score NUMBEREND_LINKBAIT 0.999
score OBFU_TEXT_ATTACH 0.001
score ODD_FREEM_REPTO 2.996
score OFFER_ONLY_AMERICA 1.650
score ONLINE_MKTG_CNSLT 2.596
score ORDER_TODAY 1.569
score PDS_BTC_ID 0.498
score PDS_BTC_MSGID 0.001
score PDS_BTC_NTLD 1.923
score PDS_DBL_URL_TNB_RUNON 1.997
score PDS_FRNOM_TODOM_DBL_URL 1.499
score PDS_FRNOM_TODOM_NAKED_TO 1.498
score PDS_FROM_2_EMAILS_SHRTNER 1.013
score PDS_FROM_NAME_TO_DOMAIN 1.997
score PDS_HP_HELO_NORDNS 0.998
score PDS_OTHER_BAD_TLD 1.997
score PDS_PHP_EVAL 1.498
score PDS_RDNS_DYNAMIC_FP 0.001 # force non-zero
score PDS_SHORTFWD_URISHRT_FP 1.498
score PDS_TINYSUBJ_URISHRT 1.499
score PDS_TONAME_EQ_TOLOCAL_FREEM_FORGE 1.997
score PDS_TO_EQ_FROM_NAME 3.196
score PHP_ORIG_SCRIPT 2.249
score PHP_ORIG_SCRIPT_EVAL 2.996
score PHP_SCRIPT 2.497
score PP_MIME_FAKE_ASCII_TEXT 0.998
score RAND_HEADER_LIST_SPOOF 2.996
score RAND_MKTG_HEADER 1.997
score RATWARE_NO_RDNS 1.892
score RDNS_NUM_TLD_XM 1.628
score READY_TO_SHIP 1.248
score REPLYTO_EMPTY 2.397
score REPTO_419_FRAUD 2.938
score REPTO_419_FRAUD_GM 2.996
score REPTO_419_FRAUD_GM_LOOSE 0.998
score RISK_FREE 3.096
score SCC_NEWBIE_HASBEENS 1.717
score SENDGRID_REDIR 1.498
score SERGIO_SUBJECT_VIAGRA01 3.095
score SHOPIFY_IMG_NOT_RCVD_SFY 2.497
score SHORTENER_SHORT_IMG 0.973
score SHORT_SHORTNER 1.997
score STATIC_XPRIO_OLE 1.552
score TAGSTAT_IMG_NOT_RCVD_TGST 1.997
score TARINGANET_IMG_NOT_RCVD_TN 1.999
score THIS_AD 1.298
score THIS_IS_ADV_SUSP_NTLD 1.477
score TO_EQ_FM_DIRECT_MX 0.001 # force non-zero
score TO_IN_SUBJ 0.098
score TO_NO_BRKTS_FROM_MSSP 2.497
score TO_NO_BRKTS_HTML_IMG 1.997
score TO_NO_BRKTS_HTML_ONLY 1.997
score TO_NO_BRKTS_NORDNS_HTML 1.997
score TO_NO_BRKTS_PCNT 2.498
score TRANSFORM_LIFE 2.497
score TVD_PH_BODY_META 3.096
score TVD_RCVD_SPACE_BRACKET 2.797
score UNDISC_FREEM 3.096
score UNDISC_MONEY 3.396
score URI_DEOBFU_INSTR 4.395
score URI_DOTEDU 1.997
score URI_DQ_UNSUB 2.497
score URI_FIREBASEAPP 2.996
score URI_GOOGLE_PROXY 3.096
score URI_GOOG_STO_SPAMMY 2.996
score URI_LONG_REPEAT 2.497
score URI_PHISH 3.995
score URI_PHP_REDIR 3.496
score URI_TRY_3LD 1.937
score URI_WPADMIN 2.596
score URI_WP_HACKED_2 2.497
score VFY_ACCT_NORDNS 2.516
score WALMART_IMG_NOT_RCVD_WAL 1.681
score WANT_TO_ORDER 2.746
score WORD_INVIS_MANY 2.399
score XFER_LOTSA_MONEY 0.741
score XM_DIGITS_ONLY 0.551
score XM_RANDOM 2.497
score XM_RECPTID 2.996
score XPRIO_URL_SHORTNER 0.998
score YOUR_DELIVERY_ADDRESS 0.034
score YOU_INHERIT 2.514
score AC_POST_EXTRAS 1.000
score AC_SPAMMY_URI_PATTERNS1 1.000
score AC_SPAMMY_URI_PATTERNS10 1.000
score AC_SPAMMY_URI_PATTERNS11 1.000
score AC_SPAMMY_URI_PATTERNS12 1.000
score AC_SPAMMY_URI_PATTERNS2 1.000
score AC_SPAMMY_URI_PATTERNS3 1.000
score AC_SPAMMY_URI_PATTERNS4 1.000
score AC_SPAMMY_URI_PATTERNS8 1.000
score AC_SPAMMY_URI_PATTERNS9 1.000
score ADULT_DATING_COMPANY 10.001 # force non-zero
score APP_DEVELOPMENT_FREEM 1.000
score BITCOIN_BOMB 1.000
score BITCOIN_DEADLINE 1.000
score BITCOIN_EXTORT_01 1.000
score BITCOIN_EXTORT_02 1.000
score BITCOIN_IMGUR 1.000
score BITCOIN_MALWARE 1.000
score BITCOIN_OBFU_SUBJ 1.000
score BITCOIN_PAY_ME 1.000
score BITCOIN_SPAM_01 1.000
score BITCOIN_SPAM_04 1.000
score BITCOIN_SPAM_06 1.000
score BITCOIN_SPAM_08 1.000
score BITCOIN_SPAM_09 1.000
score BITCOIN_SPAM_10 1.000
score BITCOIN_SPAM_11 1.000
score BITCOIN_SPAM_12 1.000
score BODY_URI_ONLY 1.000
score BOMB_FREEM 1.000
score BOMB_MONEY 1.000
score BTC_ORG 1.000
score CANT_SEE_AD 1.000
score COMMENT_GIBBERISH 1.000
score COMPENSATION 1.000
score DAY_I_EARNED 1.000
score DOTGOV_IMAGE 1.000
score DYNAMIC_IMGUR 1.000
score END_FUTURE_EMAILS 1.000
score ENVFROM_GOOG_TRIX 1.000
score FBI_MONEY 1.000
score FBI_SPOOF 1.000
score FONT_INVIS_POSTEXTRAS 1.000
score FORM_FRAUD 1.000
score FORM_LOW_CONTRAST 1.000
score FREEM_FRNUM_UNICD_EMPTY 1.000
score FRNAME_IN_MSG_XPRIO_NO_SUB 1.000
score FROM_ADDR_WS 1.000
score FROM_MISSP_REPLYTO 1.000
score FROM_NTLD_LINKBAIT 1.000
score FROM_NUMERIC_TLD 1.000
score GAPPY_SALES_LEADS_FREEM 1.000
score GB_FAKE_RF_SHORT 1.000
score GB_FORGED_MUA_POSTFIX 1.000
score GB_GOOGLE_OBFUR 0.750
score GOOGLE_DOCS_PHISH 1.000
score GOOGLE_DOCS_PHISH_MANY 1.000
score GOOGLE_DRIVE_REPLY_BAD_NTLD 1.000
score GOOG_MALWARE_DNLD 1.000
score GOOG_STO_IMG_NOHTML 1.000
score HAS_X_NO_RELAY 1.000
score HDRS_LCASE 0.100
score HEXHASH_WORD 1.000
score HK_CTE_RAW 1.000
score HK_RCVD_IP_MULTICAST 1.000
score HK_WIN 1.000
score HOSTED_IMG_DQ_UNSUB 1.000
score HTML_ENTITY_ASCII_TINY 1.000
score HTML_SHRT_CMNT_OBFU_MANY 1.000
score HTML_SINGLET_MANY 1.000
score HTML_TEXT_INVISIBLE_FONT 1.000
score JH_SPAMMY_PATTERN01 1.000
score JH_SPAMMY_PATTERN02 1.000
score KHOP_HELO_FCRDNS 0.400
score LIST_PRTL_PUMPDUMP 1.000
score LIST_PRTL_SAME_USER 1.000
score LUCRATIVE 1.000
score MALF_HTML_B64 1.000
score MALWARE_PASSWORD 1.000
score MANY_HDRS_LCASE 0.100
score MIME_NO_TEXT 1.000
score MONERO_DEADLINE 1.000
score MONERO_EXTORT_01 1.000
score MONERO_MALWARE 1.000
score MONERO_PAY_ME 1.000
score MSGID_DOLLARS_URI_IMG 1.000
score MSGID_HDR_MALF 1.000
score MSM_PRIO_REPTO 1.000
score NEWEGG_IMG_NOT_RCVD_NEGG 1.000
score OBFU_BITCOIN 1.000
score PHISH_AZURE_CLOUDAPP 3.500
score PHISH_FBASEAPP 1.000
score PHOTO_EDITING_DIRECT 1.000
score PHOTO_EDITING_FREEM 1.000
score PHP_NOVER_MUA 1.000
score PHP_SCRIPT_MUA 1.000
score PP_TOO_MUCH_UNICODE02 0.500
score PP_TOO_MUCH_UNICODE05 1.000
score PUMPDUMP 1.000
score PUMPDUMP_MULTI 1.000
score RAND_HEADER_MANY 1.000
score RCVD_DOTEDU_SHORT 1.000
score RCVD_DOTEDU_SUSP_URI 1.000
score RDNS_NUM_TLD_ATCHNX 1.000
score REPTO_419_FRAUD_AOL 1.000
score REPTO_419_FRAUD_AOL_LOOSE 1.000
score REPTO_419_FRAUD_CNS 1.000
score REPTO_419_FRAUD_HM 1.000
score REPTO_419_FRAUD_OL 1.000
score REPTO_419_FRAUD_PM 1.000
score REPTO_419_FRAUD_QQ 1.000
score REPTO_419_FRAUD_YH 1.000
score REPTO_419_FRAUD_YH_LOOSE 1.000
score REPTO_419_FRAUD_YJ 1.000
score REPTO_419_FRAUD_YN 1.000
score SENDGRID_REDIR_PHISH 1.000
score SEO_SUSP_NTLD 1.000
score SHORT_IMG_SUSP_NTLD 1.000
score SPOOFED_FREEMAIL_NO_RDNS 1.000
score SPOOF_GMAIL_MID 1.000
score STOCK_LOW_CONTRAST 1.000
score STOCK_TIP 1.000
score SUBJ_BRKN_WORDNUMS 1.000
score SYSADMIN 1.000
score TONLINE_FAKE_DKIM 1.000
score TO_NAME_SUBJ_NO_RDNS 1.000
score TO_NO_BRKTS_MSFT 1.000
score TVD_SPACE_ENCODED 1.000
score TVD_SPACE_RATIO_MINFP 1.000
score TW_GIBBERISH_MANY 1.000
score UC_GIBBERISH_OBFU 1.000
score UNICODE_OBFU_ASC 1.000
score UNICODE_OBFU_ZW 1.000
score URI_ADOBESPARK 1.000
score URI_AZURE_CLOUDAPP 1.000
score URI_DASHGOVEDU 1.000
score URI_DATA 1.000
score URI_DOTEDU_ENTITY 1.000
score URI_HEX_IP 1.000
score URI_IMG_WP_REDIR 1.000
score URI_ONLY_MSGID_MALF 1.000
score URI_OPTOUT_3LD 1.000
score URI_TRY_USME 1.000
score URI_WP_DIRINDEX 1.000
score URI_WP_HACKED 1.000
score USB_DRIVES 1.000
score VPS_NO_NTLD 1.000
score WORD_INVIS 1.000
score XPRIO 1.000
score XPRIO_SHORT_SUBJ 1.000
# in active.list but have no hits in recent corpus
score BITCOIN_SPAM_05 0.001 # force non-zero
score BITCOIN_SPF_ONLYALL 0.001 # force non-zero
score DKIMWL_BL 0.001 # force non-zero
score DKIMWL_BLOCKED 0.001 # force non-zero
score DKIMWL_WL_HIGH 0.001 # force non-zero
score DKIMWL_WL_MED 0.001 # force non-zero
score DKIMWL_WL_MEDHI 0.001 # force non-zero
score FROM_BANK_NOAUTH 0.001 # force non-zero
score FROM_FMBLA_NDBLOCKED 0.001 # force non-zero
score FROM_FMBLA_NEWDOM 0.001 # force non-zero
score FROM_FMBLA_NEWDOM14 0.001 # force non-zero
score FROM_FMBLA_NEWDOM28 0.001 # force non-zero
score FROM_GOV_DKIM_AU 0.001 # force non-zero
score FROM_GOV_REPLYTO_FREEMAIL 0.001 # force non-zero
score FROM_GOV_SPOOF 0.001 # force non-zero
score FROM_MISSP_SPF_FAIL 0.001 # force non-zero
score FROM_NEWDOM_BTC 0.001 # force non-zero
score FROM_NUMBERO_NEWDOMAIN 0.001 # force non-zero
score FROM_PAYPAL_SPOOF 0.001 # force non-zero
score FSL_BULK_SIG 0.001 # force non-zero
score PDS_HELO_SPF_FAIL 0.001 # force non-zero
score RCVD_IN_MSPIKE_BL 0.001 # force non-zero
score RCVD_IN_MSPIKE_H2 0.001 # force non-zero
score RCVD_IN_MSPIKE_H3 0.001 # force non-zero
score RCVD_IN_MSPIKE_H4 0.001 # force non-zero
score RCVD_IN_MSPIKE_H5 0.001 # force non-zero
score RCVD_IN_MSPIKE_L2 0.001 # force non-zero
score RCVD_IN_MSPIKE_L3 0.001 # force non-zero
score RCVD_IN_MSPIKE_L4 0.001 # force non-zero
score RCVD_IN_MSPIKE_L5 0.001 # force non-zero
score RCVD_IN_MSPIKE_WL 0.001 # force non-zero
score RCVD_IN_MSPIKE_ZBI 0.001 # force non-zero
score SPOOFED_FREEMAIL 0.001 # force non-zero
score SPOOFED_FREEM_REPTO 0.001 # force non-zero
score SPOOFED_FREEM_REPTO_CHN 0.001 # force non-zero
score SPOOFED_FREEM_REPTO_RUS 0.001 # force non-zero
score SURBL_BLOCKED 0.001 # force non-zero
score TO_EQ_FM_DOM_SPF_FAIL 0.001 # force non-zero
score TO_EQ_FM_SPF_FAIL 0.001 # force non-zero
score USER_IN_DKIM_WELCOMELIST 0.001 # force non-zero