This morning we have been getting drilled by spam/virus emails. 40 so
far. Been getting a lot of phone calls from across the company about
these emails. At least my mailscanner boxes are stripping the files,
and tagging it as spam, but what worries me, is the low scores these
messages are receiving. I start tagging spam, at 3.5 so each message
has been tagged, but still sent through. Any one else seeing these
emails?
Header:
Return-Path: < g>
Received: from bohoqsobp.us (
[12.219.139.163])
by mail.lovebox.com (8.13.4/8.13.4) with SMTP id jALMiLIS008948;
Mon, 21 Nov 2005 16:44:22 -0600
From: webmaster (AT) dfa (DOT) state.ny.us
To: XPost (AT) lovebox (DOT) com
Date: Mon, 21 Nov 2005 22:41:54 UTC
Subject: Mail delivery failed
Importance: Normal
X-Priority: 3 (Normal)
Message-ID: <5dbcea3e2fce.853b4 (AT) dfa (DOT) state.ny.us>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary=""
Content-Transfer-Encoding: 7bit
Subject: Mail delivery failed
Report:
MailScanner: Executable DS/Windows programs are dangerous in email
(File-packed_da.exe)
Inoculate: File ./jALMiLIS008948/mail_body.zip is infected by virus:
Win32/Sober.W!Worm Inoculate: File
is infected by
virus: Win32/Sober.W!Worm
ClamAV: mail_body.zip contains Worm.Sober.U
Inoculate: File is infected by
virus: Win32/Sober.W!Worm ClamAV: File-packed_dataInfo.exe contains
Worm.Sober.U
MailScanner: Executable DS/Windows programs are dangerous in email
(File-packed_dataInfo.exe)
MailScanner: Executable DS/Windows programs are dangerous in email
(File-packed_da.exe)
Inoculate: File is infected by
virus: Win32/Sober.W!Worm
ClamAV: File-packed_dataInfo.exe contains Worm.Sober.U
MailScanner: Executable DS/Windows programs are dangerous in email
(File-packed_dataInfo.exe)
SpamAssassin Score: 3.85
Spam Report:
ScoreMatching RuleDescription-1.80ALL_TRUSTED
Did not pass through any untrusted hosts
2.19INVALID_DATEInvalid Date: header (not RFC 2822)
0.96NREAL_NAMEFrom: does not include a real name
0.50RAZR2_CF_RANGE_51_100Razor2 gives confidence level above 50%
1.50RAZR2_CF_RANGE_E4_51_100
0.50RAZR2_CHECKListed in Razor2 (http://razor.sf.net/)
/var/log/maillog
Nov 21 16:44:42 wks-lin12 MailScanner[21338]: Saved archive copies of
jALMiUJ008973 jALMiLIS008948
Nov 21 16:44:52 wks-lin12 MailScanner[21338]: Message jALMiLIS008948
from 12.219.139.163 (webmaster (AT) dfa (DOT) state.ny.us) to lovebox.com is spam,
SpamAssassin (score=3.854, required 3, ALL_TRUSTED -1.80, INVALID_DATE
2.19, NREAL_NAME 0.96, RAZR2_CF_RANGE_51_100 0.50,
RAZR2_CF_RANGE_E4_51_100 1.50, RAZR2_CHECK 0.50)
Nov 21 16:44:53 wks-lin12 MailScanner[21338]: Spam Actions: message
jALMiLIS008948 actions are store,deliver,striphtml
Nov 21 16:44:55 wks-lin12 MailScanner[21338]: File
/
nfo.exe is infected by virus: Win32/Sober.W!Worm
Nov 21 16:44:55 wks-lin12 MailScanner[21338]: File
/ is
infected by virus: Win32/Sober.W!Worm
Nov 21 16:44:55 wks-lin12 MailScanner[21338]: File
/<Fil
e-packed_dataInfo.exeis infected by virus: Win32/Sober.W!Worm
Nov 21 16:44:57 wks-lin12 MailScanner[21338]:
/
nfo.exe: Worm.Sober.U FUND
Nov 21 16:44:57 wks-lin12 MailScanner[21338]:
/
Worm.Sober.U FUND
Nov 21 16:44:57 wks-lin12 MailScanner[21338]: Infected message
jALMiLIS008948 came from 12.219.139.163
Nov 21 16:44:57 wks-lin12 MailScanner[21338]: Filename Checks:
Windows/DS Executable (jALMiLIS008948 File-packed_dataInfo.exe)
Nov 21 16:44:57 wks-lin12 MailScanner[21338]: Filename Checks:
Windows/DS Executable (jALMiLIS008948 File-packed_dataInfo.exe)
Nov 21 16:44:57 wks-lin12 MailScanner[21338]: Saved entire message to
/
Nov 21 16:44:57 wks-lin12 MailScanner[21338]: Saved infected
"File-packed_da.exe" to
/
Nov 21 16:44:57 wks-lin12 MailScanner[21338]: Saved infected
"mail_body.zip" to
/
Nov 21 16:44:57 wks-lin12 MailScanner[21338]: Saved infected
"File-packed_dataInfo.exe" to
/
Nov 21 16:44:57 wks-lin12 MailScanner[21338]: Logging message
jALMiLIS008948 to SQL
Nov 21 16:44:57 wks-lin12 MailScanner[1488]: jALMiLIS008948: Logged to
MailWatch SQL
Nov 21 16:44:58 wks-lin12 sendmail[9046]: jALMiLIS008948: to=dfair,
ctladdr=<eBay (AT) lovebox (DOT) com(8/0), delay=00:00:36, mailer=local,
pri=285904, dsn=5.1.1, stat=User unknown
Nov 21 16:44:58 wks-lin12 sendmail[9046]: jALMiLIS008948:
to=awray (AT) imap (DOT) lovebox.com,root (AT) imap (DOT) lovebox.com,tprice (AT) imap (DOT) lovebox.com,
delay=00:00:36, xdelay=00:00:00, mailer=esmtp, pri=285904,
relay=imap.lovebox.com. [172.16.3.106], dsn=2.0.0, stat=Sent
(jALMiw1A006072 Message accepted for delivery)
Nov 21 16:44:58 wks-lin12 sendmail[9046]: jALMiLIS008948:
jALMivMA009046: DSN: User unknown