Koozali.org: home of the SME Server

Foreign Email - Spam / Virus

Olsen

Foreign Email - Spam / Virus
« on: May 17, 2005, 01:54:40 AM »
Over the weekend, our company has had a FLOOD of emails coming in from German senders with subjects that are german.  The email is most typically virus related because all the email contains is a hyperlink to a site.  We are getting HUNDREDS of these emails.  

We reside in the USA, how can I block emails that have subject lines in German, or any other foreign languages?  

Currently, I am running ClamAV, Spamassassin, mailfront mailrules, and RBL.  

I dont know how I can filter these emails because there is no attachments, and I dont know if there is any filter that can distinguish if the content is in english or not.....

HELP?????

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Foreign Email - Spam / Virus
« Reply #1 on: May 17, 2005, 02:29:23 AM »
Quote from: "Olsen"
Over the weekend, our company has had a FLOOD of emails coming in from German senders with subjects that are german.  The email is most typically virus related because all the email contains is a hyperlink to a site.  We are getting HUNDREDS of these emails.


As is everyone else in the world.

Read more here:

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FSOBER%2EU

Offline funkusmunkus

  • *
  • 220
  • +0/-0
Foreign Email - Spam / Virus
« Reply #2 on: May 17, 2005, 07:48:56 AM »
Apparently you could place http://weblog.erenkrantz.com/~jerenk/german_spam.cf
in  /usr/share/spamassassin
and that should stop the new sober emails

worth a try

hope that helps
cheers
.........

CKConsulting

Foreign Email - Spam / Virus
« Reply #3 on: May 18, 2005, 02:46:35 AM »
funkusmunkus,

Can you explain your suggestion a bit more and did it work?  Do you add this to a file or create a file with this name.........  If this does work it could be very handy in the future to stop issues like the one that happened over the week end.

Thanks,
Rick

Offline funkusmunkus

  • *
  • 220
  • +0/-0
Foreign Email - Spam / Virus
« Reply #4 on: May 18, 2005, 03:13:27 AM »
I personally don't have spamassassin installed, I don't get any spam, and at work we only use fetchmail, so again never had a need for spamassassin someone on whirlpool (an Australian forum) using FC2 said just place the file in /usr/share/spamassassin and it worked.

The link I gave you had a heading of
Quote
SpamAssassin rules for new German spam.
There appear to be a new slate of German emails on the loose that are small enough that my Bayesian program isn't doing much with them.
I've updated my SA rules for German spam with some new rules. I believe Erik provided the rule set initially.
You can fetch my current german_spam.cf rules.
I'll try to keep it updated as I see more.
Perhaps it's worth seeing if rules-du-jour has any of these yet...
Enjoy. And, boo on spammers


but I also came across this http://www.viruswatch.nl/info/soberq_filter.html
which has a rule that doesn't report false positives at all
it hasn't been tested on spamassassin but this is the rule
Code: [Select]
^Received\:\sfrom\s[a-z]{5,10}\.*\nDate\:[\s\w\,\:]{4,22}\:[0-9]{1,2}\s[A-Z]{1,4}\n


hope that helps
sorry I can't be of more help
cheers
.........

CKConsulting

Foreign Email - Spam / Virus
« Reply #5 on: May 18, 2005, 05:03:55 AM »
Thanks for the info I'll give it a shot.

Rick

Offline p-jones

  • *
  • 594
  • +0/-0
Foreign Email - Spam / Virus
« Reply #6 on: May 18, 2005, 12:10:00 PM »
I have a similiar problem reversed. A vrus has entered the windows system and flooded the mailserver  with with email to a point that qmail has broken. I have manually cleaned out the local/remote and mess folders but Qmail is is still dead.

The fetchmail component has been continuing to collect the mail and depositing it ???. Likewise outward mail is also going from the client into a vapour that does not include the recipient.

I have never had this break before and I am not sure now where to go next to continue to fix / rebuild the mail system. Any pointers please

Peter
...

CKConsulting

Foreign Email - Spam / Virus
« Reply #7 on: May 18, 2005, 03:34:41 PM »
First did you find the PC causing this issue and kill it?  Maybe you have more than one PC with the virus?  
Is you hard drive full?
You could pull it off the network to see if you can get it back up.

Just my 2 cents.
Rick

cc_skavenger

Foreign Email - Spam / Virus
« Reply #8 on: May 18, 2005, 03:55:41 PM »
Quote from: "funkusmunkus"
... I also came across this http://www.viruswatch.nl/info/soberq_filter.html
which has a rule that doesn't report false positives at all
it hasn't been tested on spamassassin but this is the rule
Code: [Select]
^Received\:\sfrom\s[a-z]{5,10}\.*\nDate\:[\s\w\,\:]{4,22}\:[0-9]{1,2}\s[A-Z]{1,4}\n



Is this put in the same spot, ie. create a file located in /usr/share/spamassassin ?

Thanks

CKConsulting

Foreign Email - Spam / Virus
« Reply #9 on: May 18, 2005, 04:01:19 PM »
I tried the .sf file last night and it seems to be working well.
http://weblog.erenkrantz.com/~jerenk/german_spam.cf


I didn't try the code.

Rick

Offline soup

  • *
  • 10
  • +0/-0
Foreign Email - Spam / Virus
« Reply #10 on: May 18, 2005, 04:13:16 PM »
I'd like to install this .sf file but i'm having a hard time placing the file in the spamassassin dir. (I'm a SME newbie) I located the file in my home dir, how do I move it?  :oops:

I'd appreciate it if someone can explain this to me.

Thanks,

Matt

CKConsulting

Foreign Email - Spam / Virus
« Reply #11 on: May 18, 2005, 04:21:03 PM »
I use WINSCP.
http://winscp.net

and Edit pad Pro Free
http://www.editpadpro.com/

I create the files with Edit Pad Pro and then use WINSCP to place the files.  WINSCP works just like explorer for us old windoz guys.

or you can use the mv command from putty.

Rick

filk

Foreign Email - Spam / Virus
« Reply #12 on: May 18, 2005, 04:38:42 PM »
Quote from: "CKConsulting"
I tried the .sf file last night and it seems to be working well.
http://weblog.erenkrantz.com/~jerenk/german_spam.cf


I didn't try the code.

Rick


I installed this file and it only seemed to work if it was a "body" rule.  It was skipping everything in a "header" rule.  I used the spamassassin for dummies script to install.

Is there a config somewhere that may have turned off "header" checks?

What makes this even more odd is that if I reformat the "header" rules as "body" rules, it picks it up from the Subject line.  I have the resulting .cf if anyone else is interested.

Any ideas?  Is this happening to anyone else?

Offline funkusmunkus

  • *
  • 220
  • +0/-0
Foreign Email - Spam / Virus
« Reply #13 on: May 18, 2005, 04:58:16 PM »
just a correction the area you put the CF file in /etc/mail/spamassassin not /usr/share/spamassassin for more info on it check http://mywebpages.comcast.net/mkettler/sa/SA-rules-howto.txt

ahh cc_skavenger I really have no idea I just saw it on sans this morning http://isc.sans.org/diary.php?date=2005-05-16
.........

cc_skavenger

Foreign Email - Spam / Virus
« Reply #14 on: May 19, 2005, 06:36:14 AM »
What finally did work for my company:

Copied these spamassassin .cf rule files to the /etc/mail/spamassassin/ directory.

http://www.ccskavenger.info/sober-worm-spamassassin-rules/

Restart spamassassin with the command:  
/etc/rc.d/init.d/spamassassin restart

HTH someone else with the neo-nazi spam problem.

Olsen

Foreign Email - Spam / Virus
« Reply #15 on: May 19, 2005, 05:58:15 PM »
cc_skavenger,  

Thanks for posting those .cf files!  I have installed them into my spamassassin directory.  I will let everyone know if this has worked for our situation also.

Thanks again.

Olsen

Foreign Email - Spam / Virus
« Reply #16 on: May 19, 2005, 06:49:06 PM »
Nope, that did not work......

I click on the link on each .cf file on your site and copied the text.
I then opened up a blank doc on the server and pasted the text, saved as sober-p.cf (as well as saving the rest of the files also in the same manner)
restarted spamassassin....

I just got an email with the subject:
Tuerkei in die EU

This is a typical sober email.

Any suggestions?

BTW I put the files in /etc/mail/spamassassin as directed.

Olsen

Foreign Email - Spam / Virus
« Reply #17 on: May 19, 2005, 07:16:41 PM »
OK....It may have been a problem with the spamassassin restart,
I was installing a couple of other .cf files and had restarted spamassassin a couple of times.  One must have hung up because when I checked the status, it was stopped.  I started the spamd service and it SHOULD work because I saw that subject in the sober-p.cf file......

cc_skavenger

Foreign Email - Spam / Virus
« Reply #18 on: May 19, 2005, 07:24:08 PM »
It is working great here.  The boss isn't cursing my name anymore.... :-D

Olsen

Foreign Email - Spam / Virus
« Reply #19 on: May 19, 2005, 07:51:11 PM »
I am getting frustrated with spamd.  

I start it and it starts ok.  I check the status to make sure it is running, and it says its running.  A minute later, I check the status to make sure it is still running (because I am a little obsessive) and it says spamd stopped.  ANYONE KNOW WHY it keeps stopping?  I am not doing anything that would stop it, Is there a script that is running to stop it?  

I am running spamassassin 3.0.1-3 with an auto update script

cc_skavenger

Foreign Email - Spam / Virus
« Reply #20 on: May 19, 2005, 08:08:41 PM »
I know this is a pain, but I would uninstall it and reinstall it.  I seemed to have been having a problem with older versions not completely uninstalling or being overwritten when I did an upgrade.

Just a thought...

Olsen

Foreign Email - Spam / Virus
« Reply #21 on: May 19, 2005, 08:54:11 PM »
A pain...it was....

I uninstalled the perl module, spamassassin, sme-spamfilter, spamassassin tools, usa script.....

Then i installed using the script i downloaded from swerts.  

It installed fine, but when I go to check the status of spamd....it is stopped.

Pulling my hair out.....running out of ideas.

There has to be a script shutting spamd down.  When I look at the message log, there is nothing in there telling me that spamd is shutting down.

cc_skavenger

Foreign Email - Spam / Virus
« Reply #22 on: May 19, 2005, 09:29:47 PM »
ok, lets try this...

Restart spamassassin and immediately do a top.  In top, press shift and the letter m to see what processes are using the most memory.  Watch this, are there any processes that are hogging memory?  

Btw, what are the specs on the system you are using?

Olsen

Foreign Email - Spam / Virus
« Reply #23 on: May 19, 2005, 09:31:00 PM »
I may have figured it out.

Everytime I tried to
[me@myserver]# /etc/rc.d/init.d/spamassassin restart
Shutting down spamd:                   [ FAILED ]
Starting spamd:                        [   OK   ]

but then when I would check the status, it would say:
stopped


So I tried removing all the custom .cf files thinking maybe one of them had a bug in it or there was a problem with the script.  Sure enough, I was able to keep the spamd process running.

Weird though, I cannot use the restart command, I have to use "stop" then "start" and things work fine.

Now that I have spamd Running, it should be filtering through the German and Sober crap and getting rid of it.....but it is not.  So I think I have other problems.  

Anyone have any thoughts?

Olsen

Foreign Email - Spam / Virus
« Reply #24 on: May 19, 2005, 09:36:01 PM »
I did the top....did the shift+m

I am running a backup of the server (since 10:30pm) last night.....I know, I know I shouldnt be doing all of these changes during a backup, however, The president has climbed up my butt and will remain there until I get this resolved.  

So the tapeware process and spamd are top the list along with snort, squid, and clamd.

cc_skavenger

Foreign Email - Spam / Virus
« Reply #25 on: May 19, 2005, 10:04:36 PM »
There was a lot of crap stuck in the queue,in my situation; it took a little bit before it stopped coming through...

Olsen

Foreign Email - Spam / Virus
« Reply #26 on: May 20, 2005, 12:20:24 AM »
Just got another....

Here is what the header is....The spam score should be higher....shouldnt it?

Received: (qmail 1507 invoked by alias); 19 May 2005 22:05:10 -0000
Delivered-To: MY EMAIL
Received: (qmail 1498 invoked from network); 19 May 2005 22:05:01 -0000
X-Virus-Scanned: by amavis-ng-0.1.6.4-03dc on server.myserver.com
Received: from rbalvie.com (user-0c6t0bs.cable.mindspring.com [24.110.129.124])
  by server.myserver.com ([xxx.xxx.x.xxx])
  with SMTP via TCP; 19 May 2005 22:05:00 -0000
From: yosefa1@juno.com
To: Recipient@myserver.com
Date: Thu, 19 May 2005 22:01:05 UTC
Subject: Tuerkei in die EU
Importance: Normal
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
MIME-Version: 1.0
Message-ID: <95bae.66da0a5425@juno.com>
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="us-ascii"
X-Spam-Checker-Version: SpamAssassin 3.0.3 (2005-04-27) on server.myserver.com
X-Spam-Status: No, score=3.9 required=5.0 tests=BAYES_00,DCC_CHECK,
   FORGED_JUNO_RCVD,PYZOR_CHECK,RAZOR2_CF_RANGE_51_100 autolearn=no
   version=3.0.3
X-Spam-Level: ***

Offline funkusmunkus

  • *
  • 220
  • +0/-0
Foreign Email - Spam / Virus
« Reply #27 on: May 20, 2005, 02:59:44 AM »
I think you need at least 512M ram for SA to be affective, does that meet your current specs ??
cc_skavenger  another thing to check out is this site http://www.mailscanner.info/
I'm told it works rather well
.........

Olsen

Foreign Email - Spam / Virus
« Reply #28 on: May 20, 2005, 03:31:57 AM »
We have 1GB of ram running on the machine.

It appears that Spam assassin is getting a couple of these emails because I can go into the ;junkmail folders of users and see some of these german emails, but it is still allowing alot of these emails through.  I want to find a way to reject all emails with any of those subject lines included in all of the .cf files.  OR increase the score it gives to above 10.  I currently have our SpamAss, set at 7.

I appreciate all the help given so far, as I am frustrated beyond belief.  I feel as if our server is the only one not working using these .cf files.

I have gone to SARE's site and looked at some of their .cf files and installed some too.

One strange thing is after I loaded all of cc_skavenger's .cf files, I did a spamassassin --lint  AND spamassassin --lint -D
Both came up with 121 errors.....

I dont know if that is contributing to the ineffectiveness of the scripts.

Offline kruhm

  • *
  • 680
  • +0/-0
Foreign Email - Spam / Virus
« Reply #29 on: May 20, 2005, 05:57:11 AM »
@I click on the link on each .cf file on your site and copied the text.
I don't think you can just copy and paste it into a file. The word wrapping may be killing SA because it's not understanding the file.

Try creating the file, then transfering it onto the sme.

Olsen

Foreign Email - Spam / Virus
« Reply #30 on: May 20, 2005, 06:04:04 AM »
I debugged the .cf files.  You are right, the word wrap was killing me!  After correcting the files, I have not gotten any german emails.  

If I get in to work tomorrow with no german emails, I will be a happy (employed) man!

Offline kruhm

  • *
  • 680
  • +0/-0
Foreign Email - Spam / Virus
« Reply #31 on: May 20, 2005, 06:10:40 AM »
maybe we could get a corrected posting for the community to easily wget?

z80

Foreign Email - Spam / Virus
« Reply #32 on: May 20, 2005, 01:46:50 PM »
I've been getting loads of german spam too. The funny thing is though it comes from the iinet (perth western australia) IP address of 203.59.9.138

I'll ring Iinet as I'm the closes one.


Olsen

Foreign Email - Spam / Virus
« Reply #34 on: May 20, 2005, 05:29:17 PM »
RE:kruhm

In order to correct cc_skavenger's files I simply had to remove the line breaks and the word wrapping.  It is important that everyone know that spamassassin will not work properly by just using the wget command to download the files into the /etc/mail/spamassassin directory.  Even when I downloaded the files that way, the text wrapping was still causing me grief.

After getting all the files, I simply used pico to remove the extra line breaks and spacing.  It is also important to know that you cannot go to the end of the line and hit <delete> or <space>.  To get the text to space properly for parsing purposes, you must go to the beginning of the line below and hit <backspace>.  This will put all of the text in each function on one line.  

I could post my cf files, but the text wrap will still cause people issues.

I have not gotten any more German Emails....WHEW!

here is a list of custom .cf files I am using:
german.cf
german-spam.cf
german_bounce_spam.cf
sober_p.cf

HOPE THIS HELPS

cc_skavenger

Foreign Email - Spam / Virus
« Reply #35 on: May 20, 2005, 05:31:41 PM »
I have fixed the files.  Users can do a wget and not have any issues.

Thanks

Olsen

Foreign Email - Spam / Virus
« Reply #36 on: May 20, 2005, 05:36:24 PM »
Nice work cc_skavenger.

I was looking over the files and here are some unresolved errors.

File: german_spam.cf
meta __SUB_RASSISMUS_3 (__RASSISMUSHD_1 + __RASSISMUSHD_2 + __RASSISMUSHD_3 >=
1)
**** remove the line break after "RASSISMUSHD_3 >=" *****

Other than that....NICE!!!

Thanks for hosting these files for others to use!

Olsen

Foreign Email - Spam / Virus
« Reply #37 on: May 20, 2005, 05:38:12 PM »
Now user can do a wget and not have any issues.

I was writing my post at the same time you were skavenger...

Again, thanks for your hard work.

cc_skavenger

Foreign Email - Spam / Virus
« Reply #38 on: May 22, 2005, 02:34:38 AM »
Quote from: "Olsen"

File: german_spam.cf
meta __SUB_RASSISMUS_3 (__RASSISMUSHD_1 + __RASSISMUSHD_2 + __RASSISMUSHD_3 >=
1)
**** remove the line break after "RASSISMUSHD_3 >=" *****


Olsen,

Is this error still there?  I don't seem to see it....

Olsen

Foreign Email - Spam / Virus
« Reply #39 on: May 23, 2005, 06:07:24 PM »
The error is no longer there.  Great job!