Results 1 to 5 of 5

Thread: Increase of SPAM volume

  1. #1
    phoenix is offline Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,504
    Rep Power
    57

    Default

    You need to give some details of the headers from your 'spam', posting what text is in there doesn't tell us much. You should also post details of what modifications (if any) you've made to improve the anti-spam system (from the wiki articles and forum threads) and you really should upgrade to the most recent release of Zimbra and I mean immediately.
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  2. #2
    nrgyz is offline Intermediate Member
    Join Date
    Dec 2008
    Location
    Canada
    Posts
    20
    Rep Power
    6

    Default Increase of SPAM volume

    Hi all,

    I see more and more users complaining about a typical SPAM activity that occurs since early December. I'm very surprised that these messages are successful at defeating numerous anti-SPAM techniques used on our Zimbra server. RBLs are enabled, SpamAssassin too as well as Greylisting. The SPAM comes from domains with good reputation.

    My first question is : Anyone else is seeing this? Am I under a targeted attack?
    My second question is: Anyone having a suggestion so we could tweak SpamAssassin to increase the spam score for these messages?

    Thanks in advance!

    Alex


    Here is the typical SPAM message we receive :

    Code:
    I just earned $563 in five days doing simple things online! I went to - Business Week Journal You will thank me!
    Code:
    I just made $501 in 5 days browsing the internet! It came from - Business Week Journal Dont forget to thank me!
    Code:
    I just made $609 in a month doing simple things online! I used - Business Week Journal Keep this a secret!
    Code:
    I racked in $362 in a weekend being on the web! I went to - Business Week Journal friends help friends!
    Code:
    I just racked $72 in 5 days doing easy things! I went to - Channel 7 News friends help friends!
    Code:
    I just profited $118 in five days being online! All thanks to - Business Week Journal trust me, you will be happy

  3. #3
    nrgyz is offline Intermediate Member
    Join Date
    Dec 2008
    Location
    Canada
    Posts
    20
    Rep Power
    6

    Default

    You'll find attached a copy of those spam
    Attached Files Attached Files

  4. #4
    xeon is offline Advanced Member
    Join Date
    Oct 2008
    Posts
    212
    Rep Power
    6

    Default

    I am seeing these emails slip through as well. I have been just black listing the senders email address which is usually always the same, just does not match the name.

  5. #5
    nrgyz is offline Intermediate Member
    Join Date
    Dec 2008
    Location
    Canada
    Posts
    20
    Rep Power
    6

    Default

    Hi,

    I've analyzed some of these SPAM messages. They seem to come from a large botnet. They are infecting machines which in turn uses Hotmail and Yahoo MTAs to distribute those SPAM.

    Code:
    From				X-Originating-IP	Country
    
    demitendolle@hotmail.com	95.181.13.208		Russia
    anderton30@hotmail.com		201.165.177.253		Mexico
    xuyu8585@hotmail.com		194.146.217.50		Poland
    vincentb8@hotmail.fr		203.218.175.13		Hong Kong
    rookie_satya613@hotmail.co.jp	95.29.48.169		Russia
    saliha156@yahoo.com		151.205.166.204		USA
    ecko_red_babe@hotmail.com	98.207.91.234		USA
    marinaromano2908@hotmail.com	187.140.93.101		Mexico
    deja_voo2005@yahoo.com		115.113.183.2		Australia
    fridols@hotmail.com		217.118.93.92		Russia
    delphine_bootz@hotmail.com	89.214.162.225		Portugal
    manartuh@hotmail.com		92.83.154.175		Romania
    angelesnino@hotmail.com		190.137.83.167		Uruguay
    SANS ISC also published an article about these particular SPAM
    T'is the season to be SPAMMY, trallalalaa la la la laaa

    Thanks again!

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Spam, Spam and more Spam (Inbox)
    By luma in forum Administrators
    Replies: 4
    Last Post: 10-07-2010, 07:57 AM
  2. Replies: 3
    Last Post: 02-25-2008, 06:33 AM
  3. Increase spam filtrering
    By timothyalangorman in forum Administrators
    Replies: 0
    Last Post: 11-28-2007, 01:09 PM
  4. Spam being scored with BAYES_00
    By flyerguybham in forum Administrators
    Replies: 6
    Last Post: 04-24-2007, 12:07 PM
  5. Training spam and ham
    By Justin in forum Developers
    Replies: 2
    Last Post: 10-31-2006, 03:39 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •