Advance fee loan scams and fraudulent loan sites.
#398022 by buried under 419s Sat Oct 05, 2019 5:19 pm
Return-path: <>
Delivery-date: Sat, 05 Oct 2019 13:51:38 -0700
Received: from [] (port=52103
by with esmtp (Exim 4.89)
id 1iGr1Z-0003uF-7b
for ; Sat, 05 Oct 2019 13:51:37 -0700
From: "Financial Services" <[email protected]>
Reply-to: <[email protected]>
Content-Type: text/html; charset=us-ascii;
Content-Disposition: inline
Date: Sat, 05 Oct 2019 14:23:55 -0400
X-Spam-Status: Yes, score=19.5
X-Spam-Score: 195
X-Spam-Bar: +++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: 'Find a great rate on a personal loan, no obligation and
free' [...]

Content analysis details: (19.5 points, 7.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
1.0 BAYES_999 BODY: Bayes spam probability is 99.9 to 100%
[score: 1.0000]
5.0 BAYES_99 BODY: Bayes spam probability is 99 to 100%
[score: 1.0000]
0.5 KAM_NUMSUBJECT Subject ends in numbers
0.1 URIBL_CSS_A Contains URL's A record listed in the Spamhaus CSS
0.1 URIBL_CSS Contains an URL's NS IP listed in the Spamhaus CSS
0.0 NORMAL_HTTP_TO_IP URI: URI host has a public dotted-decimal IPv4
1.2 NUMERIC_HTTP_ADDR URI: Uses a numeric IP address in URL
0.0 HTML_MESSAGE BODY: HTML included in message
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
2.1 HTML_IMAGE_ONLY_12 BODY: HTML: images with 800-1200 bytes of words
1.9 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
0.9 RAZOR2_CHECK Listed in Razor2 (
1.6 MISSING_MID Missing Message-Id: header
0.0 LOTS_OF_MONEY Huge... sums of money
0.0 FSL_BULK_SIG Bulk signature with no Unsubscribe
0.0 HTML_SHORT_LINK_IMG_1 HTML is very short with a linked image
2.0 RDNS_NONE Delivered to internal network by a host with no rDNS
2.0 KAM_BADIPHTTP Due to the Storm Bot Network, IPs in emails is bad
1.0 BODY_URI_ONLY Message body is only a URI in one line of text or for
an image
0.0 T_REMOTE_IMAGE Message contains an external image
X-Spam-Flag: YES
Subject: ***SPAM*** 3.99% APR Loans-Up to $100,000

'Find a great rate on a personal loan, no obligation and free'

Questions about scams? fraudatiocruor @ to contact remove spaces

