// MailWasher Pro filter rules #3, compiled by "Wiz" Feinberg, from www.wizcrafts.net.
// Can be used to replace the default rules, saved to your MWP profile data folders as filters.txt.
// This page is a child of: http://www.wizcrafts.net/mailwasher.html and http://www.wizcrafts.net/mwp-filters.html where you can get MailWasher Pro, or learn more about it.
//
// If these rules prove beneficial to you, please make a donation, at: http://www.wizcrafts.net/donations/
// Thanks :-)
//
// READ THESE NOTES
// // Indicates a comment, and is not parsed.
//
// IMPORTANT READ THE FOLLOWING!
// If you make changes to this file while MailWasher Pro is running, the changes will be overwritten when MailWasher Pro is closed.
// To be safe, close MailWasher first,then edit the filters. Or, edit them within MailWasher using the Filter Sidebar (Control + F7).
// I have had reports about corruption when copying and pasting my filters into existing filters.txt files. Most of the time this is caused because the text editor you are using is allowing a mixture of Unicode and Ascii entries to be copied.
// If you experience MailWasher wiping out the pasted in filters, after you re-open it (assuming it was not running at all when you saved the changes), do this.
// When copying and pasting some or all of these filters into your own "filters.txt," if you are using a text editor that is unicode-aware, you should not just SAVE the file. Rather you should use the "Save AS" feature to save the file as either all ASCII or all UNICODE. MailWasher will accept either, but can only deal with one at a time.
//
// Personally identifiable rules have been deleted from this list. You should create your own rules to deal with your domain name or email address in the Subject or From fields.
// Sample rule for spam sent to an non-existent account on your Domain server, - contacts@yourDomain ...
// (ex:) [enabled],"contacts@YourDomain.com","Contacts Spam",16711680,OR,Hidden,Delete,Automatic,To,contains,contacts@YourDomain.com,EntireHeader,contains,contacts@YourDomain.com,Subject,contains,contacts@YourDomain.com,From,contains,contacts@yourDomain
// The following are actual, functional rules, ready to drop in to your existing Mailwasher Filters. There may be duplicates because some are from common rules sources.
// There must not be any blank lines from the start of the list to the end. Each rule must be on one continuous line, with a linefeed between rules. The last rule must end at the end of it's line, without a linefeed!
// Turn off word wrap to view these rules.
// Be sure you add your friends and contacts to your Friends List, or the image spam filter rules may delete email you wanted.
// Removed undesirable "Bounce" directives on August 8, 2007. Bouncing no longer works for modern spam as the Return To and From field is always forged and is sent from zombie botnetted home or office computers.
// WARNING! This version of my filters contains Hidden and Automatic deletion actions when an email is identified as spam by some of these rules. You should review these filters and change these actions if you prefer to see all flagged messages and delete them manually.
// You should definitely turn on "Allow deleted email to be restored from the summary screen," then set your SMTP server and logon credentials, and set the scanning size to at least 250 lines or more (300+ lines is better).
// Rearranged filters according to my own usage; most current rules nearest the top; catch-alls near bottom.
// December 2, 2007: (Split Pharmaceuticals and Male Enhancement filters into separate detections for Subject [S] and Body [B] word matches. Merged Canadian Pharmacy filter into Pharmaceuticals.)
// January 3, 2008, I have begun anchoring the starting characters on new lines with ^ to improve rule processing. Many rules are getting updated to include this, as is appropriate.
// January 17, 2008, I added a new filter to detect the same domain name on both sides of @ sign, in "From:" field. Removed part of .info sender filter to speed up processing.
// March 8, 2008, made HTML Tricks filter automatically delete, afer a deluge of spam matching it's rules, with no false positives.
// Recently disabled and moved to bottom: Fake CNN and MSN Breaking news alerts leading to Trojan video codec downloads.
// Removed most of the image spam filters because this type of spam is rarely used now. Only Image Spam #11 remains.
// Recent additions: UPS Scam, New User-Agent and X-Mailer filters, Fake Domain Renewals, Fake MSN Newsletter, Thunderbird 2-Line Spam, Canadian Pharmacy Fake Newsletter, Daily Top 10 Canadian Pharmacy, Controlled Drugs, Money Mule Scam, SquirrelMail, Canadian Pharmacy, Fake Fox News Canadian Pharmacy, Fake ABCNews Canadian Pharmacy, Bank Phishing, Known Spam Subjects #3, Thunderbird mailer, Yahoo Calendar and Yahoo Search spam filters.
// Previously updated on December 28, 2008: updated Pills, Known Spam Domains and Known User Agent spam filters.
// Last Updated on January 3, 2009: Updated Known Spam [From or Body] filter for Mr. Song Li(le) scams.
// All of these comments will be erased as soon as you save this file as filters.txt and activate MailWasher Pro. Keep a copy of this file on hand.
[enabled],"AVG Returned Email","AVG Bounces",16711680,OR,Delete,Body,contains,"This is the AVG E-mail Scanner program.",Body,contains,"I'm sorry to inform you that the message",Subject,contains,"Undelivered Mail Returned to Sender"
[enabled],"Restored by MWP","Restored by MWP",26112,AND,Legitimate,TakesPrecedence,EntireHeader,contains,"Resent-From: ""MailWasher Pro recycle bin"""
[enabled],"Mailwasher Reports","MWP Report",26112,AND,Legitimate,Subject,contains,"MailWasher Pro summary"
[enabled],"Multiple Forwarded Messages","Multiple Forwarded Messages",16711680,AND,To,containsRE,"(.+@.+,\s){5,}",Subject,contains,FW:
[enabled],XdomainY@domain,BlackList,0,AND,Delete,Automatic,EntireHeader,containsRE,"^Received: from.*@(([\w\d]*)\.\w{2,4}).*^From:.*<\w{2,}\2\w+?@\1"
[enabled],"Angelina Jolie Video Trojan","Angelina Jolie Video Trojan",255,AND,Delete,TakesPrecedence,Automatic,Subject,containsRE,"An[gj]elina\s{1,2}(Jolie\s)?(Free|naked|nude|XXX)?\s(movie|Video)|Jolie\ naked"
[enabled],"Fake Windows Update","Exploit Link",16711680,AND,Delete,TakesPrecedence,Subject,contains,"Official Update",Body,containsRE,"/.+\.exe"">"
[enabled],"Trojan Video Link [S]","Trojan Video Link",16711680,OR,Delete,Automatic,Subject,containsRE,(Kick-up|News)\s-.+-\svideo,Subject,contains,"video without cowards",Subject,contains,"Re: Delivery Protection",Subject,is,"BREAKING news",Subject,is,"Weekly top news",Subject,containsRE,"(BBC:|CNN:|Breaking\ news:|Hot\ news:)"
[enabled],"Trojan Video Link [B]","Trojan Video Link",16711680,OR,Delete,Automatic,Body,containsRE,"(Kick-up|New|Shocking)\s(presentation|video)|video\ without\ cowards|mp3\ is\ shocking|Interesting\ (cd|mp3|mpeg4)|Stunning\ (mpeg4|porno|video)|porno\ dvd",Body,containsRE,"Download\ and\ watch|Download\ (it\s)?now\!|get\ this\ kick-up\ cd|Look\ (at\s)?it\ now\!",Body,containsRE,"/(play(er)?|mov|stream|vid|video_?\d?|watchit)\.exe"">",Body,contains,"Download VIDEO",Body,contains,"Open video",Body,contains,/paris_hilton,Body,contains,"PUSH TO WATCH",Body,contains,"Shocking movie",Body,containsRE,"/index[0-9]{1,2}\.html"">",Body,contains,"Video attached"
[enabled],"Trojan Video Link [S&B]","Trojan Video Link",16711680,AND,Delete,Automatic,Subject,containsRE,"Barack\ Obama|Britney\ Spears|(Paris|Barron)\ Hilton",Body,containsRE,"\.exe"">|/index_?\d{1,2}\.html"">|video\ report|news\ page>>"
[enabled],"Exploit Link","Exploit Link",16711680,OR,Delete,Automatic,Body,contains,"Please read the attachment to get the message",Body,contains,"Please read the attachment.",Body,contains,"have attached your document.",Body,containsRE,http://.+/(begin|checkit|default|first|fresh|index1|gowatch|live(streaming)?|lol|main|news|r|showvideo|start|stream(ing)?|topnews|up|viewmovie|watch|watchit|whatsup)\.html(
)?(\r\n)?,Body,contains,/viewmovie.html,Body,containsRE,"/(install|msvideoc)\.exe"">",Body,containsRE,".(avi|mpg).exe"">",Body,containsRE,"/(best|index1|up)(\.|=2E)php""",Body,contains,"American soldiery",Body,containsRE,"(?-s)^Content-Transfer-Encoding:\ quoted-printable\r\n\r\n^.+http://.+/.+\.html$\r\n^------=_NextPart_"
[enabled],"Known Spam Subjects #1","Known Spam Subjects",16711680,OR,Delete,Automatic,Subject,containsRE,"^\d\d% discount$",Subject,contains,"Can you tell me what's wrong, and how we can fix it?",Subject,contains,"No more embarrassment",Subject,contains,"New size for Men",Subject,contains,"U on board",Subject,contains,"huge dignity",Subject,contains,"Won't forget last night",Subject,contains,"Realize all of her dreams",Subject,contains,"re:Nobody will know bout your problems",Subject,contains,"Get on this right away",Subject,is,"Batteries included",Subject,containsRE,(?-i)^Mego\s.+,Subject,containsRE,^(?-i)(MSG\s)?ID:\d{5}\s.+
[enabled],"Known Spam Subjects #2","Known Spam Subjects",16711680,OR,Delete,Automatic,Subject,contains,"For every men of different ages unique decision",Subject,is,"What time is okay for you",Subject,contains,"We provide for you a real advantage to turn her on",Subject,contains,"Our best decision is suitable for every age",Subject,contains,"She will call you Macho",Subject,contains,"Legendary Hero of rumors",Subject,contains,"Extend your possibilities in your private life",Subject,contains,"Know her from the sexual side how is she inside exactly",Subject,containsRE,"(guys|Mens?)\ (Love|Need)\ This|Are\ you\ ...\?|XXX\ Video",Subject,containsRE,"size\ increase|(luck|pleasure)\ in\ love|\b(?-i)[GH]uu\w{2,}|virility|bikini\s.*shoot",Subject,contains,"The most powerful weapon for your battles",Subject,contains,"Fast Shipping WorldWide",Subject,containsRE,"(Best|Finest|Good)\ ([a-z]{3,}\ )?(propos(al|ition)|solution|suggestion)"
[enabled],"Known Spam Subjects #3","Known Spam Subjects",16711680,OR,Delete,Automatic,Subject,is,"Bring back time when girls were yours.",Subject,is,"Solution for your sexual life",Subject,is,"You can do anything with it",Subject,is,"you have nothing to lose, just a lot to gain!",Subject,contains,"Proven Effective",Subject,contains,"Make your lady w",Subject,contains,"Relax. Take a Deep Breath",Subject,contains,"Buy now, you won't regret!",Subject,containsRE,"^\d\d%\ off\ for\ [a-z0-9]{3,}$",Subject,containsRE,"(?-i)^from\s[A-Z][a-z]{2,}\s[A-Z][a-z]{3,}$"
[enabled],"Known 1-word spam subject","Known Spam Subjects",16711680,OR,Delete,Automatic,Subject,is,Enlarge,Subject,is,Rwd:,Subject,is,Vulcan!,Subject,containsRE,^[0-9]{4}$,Subject,containsRE,^(Ave|Best|Electronics|Finest|Good(iest)?|Salute|Super)$,Subject,containsRE,^(attehuor|fumerent|herkapit|Hermes|idaza|atiohar|Mego|ne-gnorw|nidnalad)$
[enabled],"Known Spam [From or Body]","Known Spam [F or B]",16711680,OR,Delete,Automatic,Body,contains,"The most powerful weapon for your battles",Body,containsRE,"SpamIt\.com|best-kept\ secret\ for\ Men|^peascod|^(?-i)Severtieth|Healthcare\ Management\ Inc",Body,containsRE,"\b(show\ woman\ you(rself)?\ care|(many|Your)\ w[eo]men)\b",Body,contains,"The finest of products, at the lowest of prices:",EntireHeader,containsRE,"(^From:\s{1,3}""?(Mr\.?\ Song\ Li|ph[ra]{2}macy|(?-i)E-STORE|\{|\}|""=\?ISO-8859-1\?Q\?))|(^X-Mailer:\ PHPMailer\ \[version 1\.73\]\r\n^X-Mailer:\ phplist\ v2\.10\.4$)",EntireHeader,contains,"From: ""USA Government Center""",Body,containsRE,"^Satisfy\ (your\ (girl|wom[ae]n)|her\b)|^Best\ offers\.\ \(c\)\ 200[89]",Body,contains,"gift for your lover",Body,contains,"Make her worship you",Body,contains,"pleasure in bed",Body,contains,"(c) 2008. To unsubscribe press ,Body,contains,"preparations for immunity improvement",Body,containsRE,Canadian.?(Phar?|p\.h\.a\.r\.m\.a\.c\.y)|Pharma?.*(Canada|market),Body,containsRE,"^.+>>>$"
[enabled],"Fake MSN Newsletter","Canadian Pharmacy",16711680,AND,Delete,TakesPrecedence,EntireHeader,doesn'tContainRE,"^Received:\ from\ .*\.msn\.com",Subject,containsRE,"(?-i)^RE:\ .+",Body,contains,"you subscribed to MSN Featured Offers."
[enabled],"Hidden ISO Subject","Hidden ISO or Ascii Subject",16711680,OR,Delete,Automatic,EntireHeader,containsRE,^Subject:[^\n]*?=?ISO-8859-[^\n]*?\n,EntireHeader,contains,"Subject: =?us-ascii?",EntireHeader,contains,"Subject: =?windows-1251?B?",EntireHeader,contains,"Subject: =?gb2312?B?"
[enabled],"  Spam","  Spam",16711680,AND,Delete,Body,contains,"
.+