Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-13-2010, 09:06 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

You need to give some details of the headers from your 'spam', posting what text is in there doesn't tell us much. You should also post details of what modifications (if any) you've made to improve the anti-spam system (from the wiki articles and forum threads) and you really should upgrade to the most recent release of Zimbra and I mean immediately.
__________________
Regards


Bill
Reply With Quote
  #2 (permalink)  
Old 12-13-2010, 09:07 AM
Intermediate Member
 
Posts: 20
Default Increase of SPAM volume

Hi all,

I see more and more users complaining about a typical SPAM activity that occurs since early December. I'm very surprised that these messages are successful at defeating numerous anti-SPAM techniques used on our Zimbra server. RBLs are enabled, SpamAssassin too as well as Greylisting. The SPAM comes from domains with good reputation.

My first question is : Anyone else is seeing this? Am I under a targeted attack?
My second question is: Anyone having a suggestion so we could tweak SpamAssassin to increase the spam score for these messages?

Thanks in advance!

Alex


Here is the typical SPAM message we receive :

Code:
I just earned $563 in five days doing simple things online! I went to - Business Week Journal You will thank me!
Code:
I just made $501 in 5 days browsing the internet! It came from - Business Week Journal Dont forget to thank me!
Code:
I just made $609 in a month doing simple things online! I used - Business Week Journal Keep this a secret!
Code:
I racked in $362 in a weekend being on the web! I went to - Business Week Journal friends help friends!
Code:
I just racked $72 in 5 days doing easy things! I went to - Channel 7 News friends help friends!
Code:
I just profited $118 in five days being online! All thanks to - Business Week Journal trust me, you will be happy
Reply With Quote
  #3 (permalink)  
Old 12-13-2010, 09:34 AM
Intermediate Member
 
Posts: 20
Default

You'll find attached a copy of those spam
Attached Files
File Type: zip spam.zip (5.2 KB, 2 views)
Reply With Quote
  #4 (permalink)  
Old 12-13-2010, 04:35 PM
Advanced Member
 
Posts: 212
Default

I am seeing these emails slip through as well. I have been just black listing the senders email address which is usually always the same, just does not match the name.
Reply With Quote
  #5 (permalink)  
Old 12-14-2010, 06:46 AM
Intermediate Member
 
Posts: 20
Default

Hi,

I've analyzed some of these SPAM messages. They seem to come from a large botnet. They are infecting machines which in turn uses Hotmail and Yahoo MTAs to distribute those SPAM.

Code:
From				X-Originating-IP	Country

demitendolle@hotmail.com	95.181.13.208		Russia
anderton30@hotmail.com		201.165.177.253		Mexico
xuyu8585@hotmail.com		194.146.217.50		Poland
vincentb8@hotmail.fr		203.218.175.13		Hong Kong
rookie_satya613@hotmail.co.jp	95.29.48.169		Russia
saliha156@yahoo.com		151.205.166.204		USA
ecko_red_babe@hotmail.com	98.207.91.234		USA
marinaromano2908@hotmail.com	187.140.93.101		Mexico
deja_voo2005@yahoo.com		115.113.183.2		Australia
fridols@hotmail.com		217.118.93.92		Russia
delphine_bootz@hotmail.com	89.214.162.225		Portugal
manartuh@hotmail.com		92.83.154.175		Romania
angelesnino@hotmail.com		190.137.83.167		Uruguay
SANS ISC also published an article about these particular SPAM
T'is the season to be SPAMMY, trallalalaa la la la laaa

Thanks again!
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.