Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

FORTRAN is the language of Powerful Computers. -- Steven Feiner


computers / news.software.nntp / A good criterion for detecting new googlegroups virus-download spams

SubjectAuthor
* A good criterion for detecting new googlegroups virus-download spamsOlivier Miakinen
`* Re: A good criterion for detecting new googlegroups virus-downloadD
 `* Re: A good criterion for detecting new googlegroups virus-downloadOlivier Miakinen
  +* Re: A good criterion for detecting new googlegroups virus-download spamsRay Banana
  |+- Re: A good criterion for detecting new googlegroups virus-downloadOlivier Miakinen
  |`* Re: A good criterion for detecting new googlegroups virus-download spamsllp
  | `* Re: A good criterion for detecting new googlegroups virus-downloadFranck
  |  `* Re: A good criterion for detecting new googlegroups virus-downloadyamo'
  |   `- Re: A good criterion for detecting new googlegroups virus-download spamsllp
  `- Re: A good criterion for detecting new googlegroups virus-download spamsD

1
A good criterion for detecting new googlegroups virus-download spams

<ukn5ja$2068$1@cabale.usenet-fr.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2571&group=news.software.nntp#2571

  copy link   Newsgroups: news.admin.net-abuse.usenet news.admin.peering news.software.nntp
Followup: news.software.nntp
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!eternal-september.org!news.gegeweb.eu!gegeweb.org!usenet-fr.net!.POSTED!not-for-mail
From: om+news@miakinen.net (Olivier Miakinen)
Newsgroups: news.admin.net-abuse.usenet,news.admin.peering,news.software.nntp
Subject: A good criterion for detecting new googlegroups virus-download spams
Followup-To: news.software.nntp
Date: Tue, 5 Dec 2023 13:38:02 +0100
Organization: There's no cabale
Lines: 38
Message-ID: <ukn5ja$2068$1@cabale.usenet-fr.net>
NNTP-Posting-Host: 200.89.28.93.rev.sfr.net
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
X-Trace: cabale.usenet-fr.net 1701779882 65736 93.28.89.200 (5 Dec 2023 12:38:02 GMT)
X-Complaints-To: abuse@usenet-fr.net
NNTP-Posting-Date: Tue, 5 Dec 2023 12:38:02 +0000 (UTC)
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101
Firefox/52.0 SeaMonkey/2.49.4
X-Mozilla-News-Host: news://news.galacsys.net:119
 by: Olivier Miakinen - Tue, 5 Dec 2023 12:38 UTC

[Preliminary note:

This article is crossposted in three groups because I don't know which
one is the most appropriate. I would have said news.admin.net-abuse.usenet
but this group seems to be highly spammed itself, so I set the followup
to news.software.nntp.

Please do a new crosspost with the correct Followup-To if you know better
than I do.
]

For the past few days I've been actively chasing the new spams originated
from Google groups, all with a link to download a .zip or .rar file, most
probably a virus. I do it on fr.* french-speaking hierarchy because I am
a French man (also please excuse me if I do mistakes in English).

Yesterday, Pierre Pallier has pointed out on fr.usenet.abus.d that all these
spams end with a kind of signature. He noticed it on alt.* newsgroups, but
I checked the exact same thing on fr.* newsgroups.

In brief, the very last line of all these spams is:
" 35727fac0c" from November the 22nd to November the 28th;
" eebf2c3492" after, up to today.

Maybe another signature could occur from time to time, but it changes way
less frequently that From header or Subject header. Of course it requires
to download the whole body and not only the headers before deciding that
it is a spam (that is why my own robot can not rely on that criterion),
but maybe it can help other guys here including newsmasters.

[reminder: please choose the appropriate group for responding]

Best Regards,
--
Olivier Miakinen

Re: A good criterion for detecting new googlegroups virus-download spams

<9074614f4dd0125a8cf8145513d84626@dizum.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2572&group=news.software.nntp#2572

  copy link   Newsgroups: news.software.nntp
From: J@M (D)
References: <ukn5ja$2068$1@cabale.usenet-fr.net>
Subject: Re: A good criterion for detecting new googlegroups virus-download
spams
Content-Transfer-Encoding: 7bit
Message-ID: <9074614f4dd0125a8cf8145513d84626@dizum.com>
Date: Tue, 5 Dec 2023 14:22:09 +0100 (CET)
Newsgroups: news.software.nntp
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.mixmin.net!news2.arglkargh.de!sewer!news.dizum.net!not-for-mail
Organization: dizum.com - The Internet Problem Provider
X-Abuse: abuse@dizum.com
Injection-Info: sewer.dizum.com - 2001::1/128
 by: D - Tue, 5 Dec 2023 13:22 UTC

On Tue, 5 Dec 2023 13:38:02 +0100, Olivier Miakinen <om+news@miakinen.net> wrote:
>For the past few days I've been actively chasing the new spams originated
>from Google groups, all with a link to download a .zip or .rar file, most
>probably a virus. I do it on fr.* french-speaking hierarchy because I am
>a French man (also please excuse me if I do mistakes in English).
>Yesterday, Pierre Pallier has pointed out on fr.usenet.abus.d that all these
>spams end with a kind of signature. He noticed it on alt.* newsgroups, but
>I checked the exact same thing on fr.* newsgroups.
>In brief, the very last line of all these spams is:
>" 35727fac0c" from November the 22nd to November the 28th;
>" eebf2c3492" after, up to today.
>Maybe another signature could occur from time to time, but it changes way
>less frequently that From header or Subject header. Of course it requires
>to download the whole body and not only the headers before deciding that
>it is a spam (that is why my own robot can not rely on that criterion),
>but maybe it can help other guys here including newsmasters.

i am not a server administrator but
filtering out google is recommended:

path: ...googlegroups.com
injection-info: ...googlegroups.com
message-id: ...googlegroups.com
references: ...googlegroups.com

it's also recommended to post using
nntp or at least non-google servers

google could stop their google2news
gateway to atone in the xmas spirit

Re: A good criterion for detecting new googlegroups virus-download spams

<ukpscs$2qk4$1@cabale.usenet-fr.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2579&group=news.software.nntp#2579

  copy link   Newsgroups: news.software.nntp
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!proxad.net!feeder1-2.proxad.net!usenet-fr.net!.POSTED!not-for-mail
From: om+news@miakinen.net (Olivier Miakinen)
Newsgroups: news.software.nntp
Subject: Re: A good criterion for detecting new googlegroups virus-download
spams
Date: Wed, 6 Dec 2023 14:19:24 +0100
Organization: There's no cabale
Lines: 23
Message-ID: <ukpscs$2qk4$1@cabale.usenet-fr.net>
References: <ukn5ja$2068$1@cabale.usenet-fr.net>
<9074614f4dd0125a8cf8145513d84626@dizum.com>
NNTP-Posting-Host: 200.89.28.93.rev.sfr.net
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-15
Content-Transfer-Encoding: 8bit
X-Trace: cabale.usenet-fr.net 1701868764 92804 93.28.89.200 (6 Dec 2023 13:19:24 GMT)
X-Complaints-To: abuse@usenet-fr.net
NNTP-Posting-Date: Wed, 6 Dec 2023 13:19:24 +0000 (UTC)
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101
Firefox/52.0 SeaMonkey/2.49.4
In-Reply-To: <9074614f4dd0125a8cf8145513d84626@dizum.com>
 by: Olivier Miakinen - Wed, 6 Dec 2023 13:19 UTC

Hello D,

Le 05/12/2023 14:22, D a écrit :
>
> i am not a server administrator but
> filtering out google is recommended:
>
> path: ...googlegroups.com
> injection-info: ...googlegroups.com
> message-id: ...googlegroups.com
> references: ...googlegroups.com

Ok, so you would choose to filter out not only what comes from Google (spam
and non-spam) but also the responses (via the header References).

Any other reactions to my proposal ?

Or maybe my message was already filtered out by the detection of the strings
" 35...0c" and " ee...92", so that nobody else has seen it before?

--
Olivier Miakinen

Re: A good criterion for detecting new googlegroups virus-download spams

<8mh6kvgxd1.fsf@raybanana.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2582&group=news.software.nntp#2582

  copy link   Newsgroups: news.software.nntp
Path: i2pn2.org!i2pn.org!news.niel.me!glou.org!news.glou.org!usenet-fr.net!news.trigofacile.com!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!raybanana.eternal-september.org!.POSTED!not-for-mail
From: rayban@raybanana.net (Ray Banana)
Newsgroups: news.software.nntp
Subject: Re: A good criterion for detecting new googlegroups virus-download spams
Date: Wed, 06 Dec 2023 16:32:42 +0100
Organization: A noiseless patient spider
Lines: 21
Message-ID: <8mh6kvgxd1.fsf@raybanana.net>
References: <ukn5ja$2068$1@cabale.usenet-fr.net>
<9074614f4dd0125a8cf8145513d84626@dizum.com>
<ukpscs$2qk4$1@cabale.usenet-fr.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
Injection-Info: raybanana.eternal-september.org; posting-host="c8e38282359b426a7b9071b3014f7688";
logging-data="874219"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+xwXtr1FeCvRTiwh65Ah5zViLMlElY2bU="
User-Agent: Plonkenlights
Cancel-Lock: sha1:mvHfMM3obB3Gr9im4POBPMWkj1g=
sha1:GIfm34hY0dCrtej1f9DaardPvrg=
X-Attribution: Ray Banana
 by: Ray Banana - Wed, 6 Dec 2023 15:32 UTC

Thus spake Olivier Miakinen <om+news@miakinen.net>
> Ok, so you would choose to filter out not only what comes from Google (spam
> and non-spam) but also the responses (via the header References).

> Any other reactions to my proposal ?

> Or maybe my message was already filtered out by the detection of the strings
> " 35...0c" and " ee...92", so that nobody else has seen it before?

Chances are that some of the nocemizers have already been filtering on
10 character hex strings as the only non-whitespace content of a line ;-).

BTW: I have also noted other hex strings than the two you quoted
and I found hints that these strings might be passwords for the
zip and rar archives that are advertised in the postings.
Haven't bothered to test this.

--
Пу́тін — хуйло́
http://www.eternal-september.org

Re: A good criterion for detecting new googlegroups virus-download spams

<ukq7pv$2u0r$1@cabale.usenet-fr.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2583&group=news.software.nntp#2583

  copy link   Newsgroups: news.software.nntp
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!proxad.net!feeder1-2.proxad.net!usenet-fr.net!.POSTED!not-for-mail
From: om+news@miakinen.net (Olivier Miakinen)
Newsgroups: news.software.nntp
Subject: Re: A good criterion for detecting new googlegroups virus-download
spams
Date: Wed, 6 Dec 2023 17:34:07 +0100
Organization: There's no cabale
Lines: 26
Message-ID: <ukq7pv$2u0r$1@cabale.usenet-fr.net>
References: <ukn5ja$2068$1@cabale.usenet-fr.net>
<9074614f4dd0125a8cf8145513d84626@dizum.com>
<ukpscs$2qk4$1@cabale.usenet-fr.net> <8mh6kvgxd1.fsf@raybanana.net>
NNTP-Posting-Host: 200.89.28.93.rev.sfr.net
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-15
Content-Transfer-Encoding: 8bit
X-Trace: cabale.usenet-fr.net 1701880447 96283 93.28.89.200 (6 Dec 2023 16:34:07 GMT)
X-Complaints-To: abuse@usenet-fr.net
NNTP-Posting-Date: Wed, 6 Dec 2023 16:34:07 +0000 (UTC)
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101
Firefox/52.0 SeaMonkey/2.49.4
In-Reply-To: <8mh6kvgxd1.fsf@raybanana.net>
 by: Olivier Miakinen - Wed, 6 Dec 2023 16:34 UTC

Le 06/12/2023 16:32, Ray Banana a écrit :
>
>> Or maybe my message was already filtered out by the detection of the strings
>> " 35...0c" and " ee...92", so that nobody else has seen it before?
>
> Chances are that some of the nocemizers have already been filtering on
> 10 character hex strings as the only non-whitespace content of a line ;-).

Ok, so the fact was already known. Sorry that I haven't read the articles that
talked about that.

> BTW: I have also noted other hex strings than the two you quoted

Ok.

> and I found hints that these strings might be passwords for the
> zip and rar archives that are advertised in the postings.
> Haven't bothered to test this.

I tried once to click on one of the links, and a message said that the
password for the .rar was 1234. Indeed the password 1234 worked, and
the archive contained one .exe and several .dll. Of course I did not
go further.

--
Olivier Miakinen

Re: A good criterion for detecting new googlegroups virus-download spams

<ukqet4$3itp1$1@news.usenet.ovh>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2588&group=news.software.nntp#2588

  copy link   Newsgroups: news.software.nntp
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!feeder8.news.weretis.net!usenet.ovh!news.usenet.ovh!.POSTED!not-for-mail
From: llp@news.usenet.ovh (llp)
Newsgroups: news.software.nntp
Subject: Re: A good criterion for detecting new googlegroups virus-download spams
Date: Wed, 06 Dec 2023 19:35:16 +0100
Organization: Alfa Network En Travaux
Message-ID: <ukqet4$3itp1$1@news.usenet.ovh>
References: <ukn5ja$2068$1@cabale.usenet-fr.net> <9074614f4dd0125a8cf8145513d84626@dizum.com> <ukpscs$2qk4$1@cabale.usenet-fr.net> <8mh6kvgxd1.fsf@raybanana.net>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-15"; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Wed, 6 Dec 2023 18:35:16 -0000 (UTC)
Injection-Info: news.usenet.ovh; posting-account="llp";
logging-data="3766049"; mail-complaints-to="abuse@usenet.ovh"
Cancel-Lock: sha256:64XSJZVTFDgRclz+XJcXqIIIMcFq1U52L89OpsNlFes=
X-Newsreader: MesNews/1.08.06.00-fr
 by: llp - Wed, 6 Dec 2023 18:35 UTC

Ray Banana a présenté l'énoncé suivant :
> Thus spake Olivier Miakinen <om+news@miakinen.net>
>
>> Ok, so you would choose to filter out not only what comes from Google (spam
>> and non-spam) but also the responses (via the header References).
>
>> Any other reactions to my proposal ?
>
>> Or maybe my message was already filtered out by the detection of the strings
>> " 35...0c" and " ee...92", so that nobody else has seen it before?
>
> Chances are that some of the nocemizers have already been filtering on
> 10 character hex strings as the only non-whitespace content of a line ;-).

The line begins with a space followed by the code.
On the last or penultimate line of the message.

Re: A good criterion for detecting new googlegroups virus-download spams

<20231206.204619.52dbe09e@yamn.paranoici.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2594&group=news.software.nntp#2594

  copy link   Newsgroups: news.software.nntp
Path: i2pn2.org!i2pn.org!news.neodome.net!mail2news
Comments: This message was transferred to Usenet via mail2news gateway at
<mail2news@neodome.net>. Please send questions and concerns to
<admin@neodome.net>. Report inappropriate use to <abuse@neodome.net>.
Date: Wed, 6 Dec 2023 20:46:19 +0000
Injection-Info: neodome.net;
posting-account="mail2news";
key="WhW+4HVzbYqpXRYCjcUa3bEG8ei5xOJ5fA7akpiPQunStfHxvMGvkKwNq2XG40g2R9Zu+o
QZhdJDafeDGNXvO8WmkmEk0CPf2rU8Vy2XAdE/jhc4yLSRMEOKduWW5BZ5L/96U3dpmlo7T7pBG
ynoYFPhw8PJJXqgs5pJYnvfWCWAHEQw+Zk+HQGIodAvhdWMK/YxuELSuBGVVz/F6PDKWmyGb0Hx
h/GZrTsDaUDlXqKnr8vR+I5ELD6mmbAS2NeZLDI4btiXSkJ1084ihQKtKmUBEGmOR/C4OwdtiJZ
KuZHtcq3rvDVwfNIjt8u06LFAxR9viG8hcv77am4+MZk6RQ==";
data="U2FsdGVkX19QRe8emdxeojcZCbx7uqn3yATxcy6XFdfqLO0GEDPBufP2n/g9Xt5Hx2fh8
HYdbPS7xL7rH60pGNNlcNUMGIX8xAJKJgCRf00dnAdzlc/6GMqERnvG1oLU8HxDPBk3FEZEJKKC
HR+4263L5I260mE7SF4QyYuURDCGEJ3+X76aRBsUHy8Qp7GLWhWaDLSYbW/wqBuMaJ022ZEc3q2
VxlMLlSNWRTMtyoH6K2t3uoBgBbKRoeLAizUqnH5SpWNZND+B9zS8AJ/GKi5k1t60AWH8t3y1pR
Hr/A1ZIUbSDgJlua0pY4dPQKPASO8AZ6dpUBarGS5x/Yt7FshatZLU21SUB94UXBf1JDxR3qa5z
1R/45svCnIieLeooKSDycY0NOzjW6037kEFX8FPZWkB1gNGl49gPhl3vwThjbrt9erjhFxHqygH
rx5mGbwi4ZKi/Nr3u9KiR9VohUiXKX/6uT6u0RIxr6OZmJdqba4U42PPjOylPEIvVe7WScdr29D
OJYdx7mTb80ddXQqrd4fGfK12DtdCobe3klXwOWWoFpyGkujIYLAHVvRtkcm2cXILbOXc2+OVIP
KPrcanw7vA3emTD60RX0XfelpnS25MhoKY7DhqLcHkucVZjwSDz+5aEEVA1zaWJDSim9zfWbTO1
ErXw/ZnZKmFtkxIshzzyktAg9InVLLrC7aXUPBB2TtVDfaduPhE5EuAApD9xYZGxIkz8pi3Mq/L
K5lkONB+GHT0fcwRUauwKho8mKu1awYJUnAX5Nos4AjJROw1zbSRMbry38khy93DYwI1HgR+JgM
BilLIVGjeUMWkSrNnjpXpAWhhKgJVqu5C88cp3mtqpzlCdu4zi99rayc7vhosdJU0k4BB2pxI/X
iH70jcWmF83uLbrzQ/qd49CB3Hg2hyiDR59eq0kVuuEb8DnHS9V0gMpEBSEidQGHnjS9CV4ObeN
3rkmPFPj2k6LYXUxOEw1m8X71OFDD2nqzKHgtDUckYdlux3TUybkMgzXB9ru9K88/9dvPe7mdEg
iYbSz9YShVge3q7QsH8FRy4mPwQMVqrRhYovy+apEpj2y8EjmrZ/sjXHoskUokxyXrYezw/Xv9z
qB0VIAACgi+dKZq/aUBz9v0jxUvid8jG1wXA+GWF3Tlcjz1Pvwu5Msb2zvbd27HQM+01lRMK/KT
nzxo2EzGM6LmDY/w46KempeLDg6Qb8C+dzPD3WLcR2fX9GKp3ycv4MHmbdpA5axS9+840wTNPIW
op3Rw5Kfpnu";
mail-complaints-to="abuse@neodome.net"
References: <ukn5ja$2068$1@cabale.usenet-fr.net> <9074614f4dd0125a8cf8145513d84626@dizum.com> <ukpscs$2qk4$1@cabale.usenet-fr.net>
Message-ID: <20231206.204619.52dbe09e@yamn.paranoici.org>
Injection-Date: Wed, 6 Dec 2023 20:50:01 +0000 (UTC)
From: nobody@yamn.paranoici.org (D)
Content-Transfer-Encoding: 7bit
Subject: Re: A good criterion for detecting new googlegroups virus-download spams
Newsgroups: news.software.nntp
 by: D - Wed, 6 Dec 2023 20:46 UTC

On Wed, 6 Dec 2023 14:19:24 +0100, Olivier Miakinen <om+news@miakinen.net> wrote:
>Hello D,
>Le 05/12/2023 14:22, D a ecrit :
>> i am not a server administrator but
>> filtering out google is recommended:
>> path: ...googlegroups.com
>> injection-info: ...googlegroups.com
>> message-id: ...googlegroups.com
>> references: ...googlegroups.com
>
>Ok, so you would choose to filter out not only what comes from Google (spam
>and non-spam) but also the responses (via the header References).

spam seems to be a normal percentage of content posted to unmoderated
usenet newsgroups from many thousands of different sources, the price
of free speech, a small cost which experienced newsgroup participants
find acceptable; however, what is popularly called googlespam appears
to be systematic and orchestrated around the usenet world; oftentimes
replies to googlespam articles quote all or part of the original spam
and are sometimes posted from non-google servers working in collusion

Re: A good criterion for detecting new googlegroups virus-download spams

<ukue9e$1la0v$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2607&group=news.software.nntp#2607

  copy link   Newsgroups: news.software.nntp
Path: i2pn2.org!i2pn.org!news.furie.org.uk!nntp.terraraq.uk!news.gegeweb.eu!gegeweb.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: franck@email.invalid (Franck)
Newsgroups: news.software.nntp
Subject: Re: A good criterion for detecting new googlegroups virus-download
spams
Date: Fri, 8 Dec 2023 07:49:17 +0100
Organization: A noiseless patient Spider
Lines: 14
Message-ID: <ukue9e$1la0v$1@dont-email.me>
References: <ukn5ja$2068$1@cabale.usenet-fr.net>
<9074614f4dd0125a8cf8145513d84626@dizum.com>
<ukpscs$2qk4$1@cabale.usenet-fr.net> <8mh6kvgxd1.fsf@raybanana.net>
<ukqet4$3itp1$1@news.usenet.ovh>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Fri, 8 Dec 2023 06:49:18 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="a5be46daf73d52ff63933568ac655d6c";
logging-data="1746975"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19qE5eRnzuX4ylrFc05cBwr"
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:2vbeNgYoQ4HUWhh1pj1HURK6ZhQ=
In-Reply-To: <ukqet4$3itp1$1@news.usenet.ovh>
Content-Language: fr
 by: Franck - Fri, 8 Dec 2023 06:49 UTC

Hello,

>> Chances are that some of the nocemizers have already been filtering on
>> 10 character hex strings as the only non-whitespace content of a line
>> ;-).
>
> The line begins with a space followed by the code.
> On the last or penultimate line of the message.

I'm not interested in the subject but perhaps adding [> \t]* to the
beginning of the regex will do the trick, even if the line is quoted in
the future?

Franck

Re: A good criterion for detecting new googlegroups virus-download spams

<ul6nqo$esq$1@rasp.pasdenom.info>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2627&group=news.software.nntp#2627

  copy link   Newsgroups: news.software.nntp
Path: i2pn2.org!i2pn.org!news.niel.me!pasdenom.info!.POSTED.2a01:e0a:21:ea80:86de:764:800b:623!not-for-mail
From: yamo@beurdin.invalid (yamo')
Newsgroups: news.software.nntp
Subject: Re: A good criterion for detecting new googlegroups virus-download
spams
Date: Mon, 11 Dec 2023 11:21:12 +0100
Organization: <http://pasdenom.info/news.html>
Message-ID: <ul6nqo$esq$1@rasp.pasdenom.info>
References: <ukn5ja$2068$1@cabale.usenet-fr.net>
<9074614f4dd0125a8cf8145513d84626@dizum.com>
<ukpscs$2qk4$1@cabale.usenet-fr.net> <8mh6kvgxd1.fsf@raybanana.net>
<ukqet4$3itp1$1@news.usenet.ovh> <ukue9e$1la0v$1@dont-email.me>
Reply-To: yamo@groumpf.org
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Mon, 11 Dec 2023 10:21:12 -0000 (UTC)
Injection-Info: rasp.pasdenom.info; posting-account="stephane@usenet"; posting-host="2a01:e0a:21:ea80:86de:764:800b:623";
logging-data="15258"; mail-complaints-to="abuse@pasdenom.info"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101
Firefox/91.0 SeaMonkey/2.53.17.1
Cancel-Lock: sha1:05ntpSq8/9hnv3loeXMfM6fGSiw= sha256:HKFdN8ovHWcYLmy4uQIuWcsF+pmaubW+mJ2eFgsuqVg=
sha1:SxZX/oFsCkdwj4WX9372BIwUO6Y= sha256:uShVw71eEcfir9g5GShOeAJGkM5SiJZN7lQpsfDp2kI=
In-Reply-To: <ukue9e$1la0v$1@dont-email.me>
X-Seamonkey: <https://www.seamonkey-project.org/>
 by: yamo' - Mon, 11 Dec 2023 10:21 UTC

Hi,
Franck a tapoté le 08/12/2023 07:49:
> I'm not interested in the subject but perhaps adding [> \t]* to the
> beginning of the regex will do the trick, even if the line is quoted in
> the future?

Thanks for your advice.

I use it.

--
Stéphane

Re: A good criterion for detecting new googlegroups virus-download spams

<um50on$2dj5q$1@news.usenet.ovh>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2755&group=news.software.nntp#2755

  copy link   Newsgroups: news.software.nntp
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!usenet.ovh!news.usenet.ovh!.POSTED!not-for-mail
From: llp@news.usenet.ovh (llp)
Newsgroups: news.software.nntp
Subject: Re: A good criterion for detecting new googlegroups virus-download spams
Date: Fri, 22 Dec 2023 22:57:43 +0100
Organization: Alfa Network En Travaux
Message-ID: <um50on$2dj5q$1@news.usenet.ovh>
References: <ukn5ja$2068$1@cabale.usenet-fr.net> <9074614f4dd0125a8cf8145513d84626@dizum.com> <ukpscs$2qk4$1@cabale.usenet-fr.net> <8mh6kvgxd1.fsf@raybanana.net> <ukqet4$3itp1$1@news.usenet.ovh> <ukue9e$1la0v$1@dont-email.me> <ul6nqo$esq$1@rasp.pasdenom.info>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-15"; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Fri, 22 Dec 2023 21:57:43 -0000 (UTC)
Injection-Info: news.usenet.ovh; posting-account="llp";
logging-data="2542778"; mail-complaints-to="abuse@usenet.ovh"
Cancel-Lock: sha256:Om497NLcPhcZsxlrN7K8toSjLdZGpmPlaQvc5z24G+U=
X-Newsreader: MesNews/1.08.06.00-fr
 by: llp - Fri, 22 Dec 2023 21:57 UTC

yamo' a émis l'idée suivante :
> Hi,
> Franck a tapoté le 08/12/2023 07:49:
>> I'm not interested in the subject but perhaps adding [> \t]* to the
>> beginning of the regex will do the trick, even if the line is quoted in
>> the future?
>
> Thanks for your advice.
>
>
> I use it.

Three others: a8ba361960, d8cbe59d7d et 0aad45d008

The latest joins the daily spam wave

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor