cancel
Showing results for 
Search instead for 
Did you mean: 

Warning: New SPAM threat - Your Latest Documents from RS Components

Superuser
Superuser
Posts: 11,263
Thanks: 2,699
Fixes: 22
Registered: 22-08-2007

Warning: New SPAM threat - Your Latest Documents from RS Components

Received the above email today @ 13:41
A little disappointed that the spam / AV filters filters did not detect and mark / flag / drop this virus loaded email...
See - http://sanesecurity.blogspot.co.uk/2015/03/your-latest-documents-from-rs-components.html

Return-path: <Bethany.d9@h94-12-137.cornut.fr>
Envelope-to: kevin@mydomain.me.uk
Delivery-date: Tue, 31 Mar 2015 13:40:44 +0100
Received: from [212.159.9.108] (helo=avasin16.plus.net)
 by inmx02.plus.net with esmtp (PlusNet MXCore v2.00) id 1YcvTI-0001dB-Ct
 for kevin@mydomain.me.uk; Tue, 31 Mar 2015 13:40:44 +0100
Received: from h94-12-137.cornut.fr ([94.127.12.137])
by avasin16.plus.net with Plusnet Cloudmark Gateway
id ACgg1q00Z2xQtnA01Cgjl7; Tue, 31 Mar 2015 13:40:44 +0100
X-CM-Score: 0.00
X-CNFS-Analysis: v=2.1 cv=bPKYIZOZ c=1 sm=1 tr=0
a=NhQCZthBbaTFKWukfNrmSg==:117 a=NhQCZthBbaTFKWukfNrmSg==:17 a=0Bzu9jTXAAAA:8
a=7uKcwXwSavkA:10 a=iOjNAnK1AAAA:8 a=r77TgQKjGQsHNAKrUKIA:9 a=9iDbn-4jx3cA:10
a=cKsnjEOsciEA:10 a=gZbpxnkM3yUA:10 a=_tVgneDzAAAA:8 a=jFmJkzCuAAAA:8
a=XfRHHcAGAAAA:8 a=zwPxn2DFAAAA:8 a=nNAiHkcKAAAA:8 a=C4ap_-gFvuNgxOLsa8kA:9
a=T7WGOHuFxzaqwkbJ:21 a=XS6_rZEKEvzJ4XUq:21 a=eXxoa78awwOIa-2W:21
a=QEXdDO2ut3YA:10 a=0rFf1bzUEKIA:10 a=wSbQ_-_mLXwA:10 a=YnUBg1f03_wA:10
a=UJPb-PXoAM6YQ1_fK8kA:9 a=diV1Cm6KfS4A:10
Message-ID: <954D39F0.3279635@mydomain.me.uk>
Date: Tue, 31 Mar 2015 14:40:33 +0200
From: Wendy Hanson <Bethany.d9@h94-12-137.cornut.fr>
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Thunderbird/31.3.0
MIME-Version: 1.0
To: kevin@mydomain.me.uk
Content-Type: multipart/mixed;
boundary="------------475949562821689934092096"
X-PN-Virus-Filtered: by PlusNet MXCore (v5.00)
X-PN-Spam-Filtered: by PlusNet MXCore (v5.00)
Subject: 39437-Your Latest Documents from RS Components 298498999

Somewhat miffed that this email addy is in the hands of spammers, but that's down to the 2007 foible!
What is the Cloudmark new threat catch-up / turn round window - hours, days or weeks?
Kevin
5 REPLIES
Community Veteran
Posts: 38,460
Thanks: 1,027
Fixes: 62
Registered: 15-06-2007

Re: Warning: New SPAM threat - Your Latest Documents from RS Components

Community Gaffer
Community Gaffer
Posts: 13,161
Thanks: 928
Fixes: 77
Registered: 04-04-2007

Re: Warning: New SPAM threat - Your Latest Documents from RS Components

Received the same message to an externally-hosted email address. It was marked as spam, but only just. Without some of the custom weighting I've applied to Spamassassin tests, it would have got through unscathed.
Looks to originate from a botnet so trapping at the source is tricky.
I expect Cloudmark will develop a signature for it eventually, not sure when though as it's not an exact science.

Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵

Superuser
Superuser
Posts: 9,452
Thanks: 786
Fixes: 52
Registered: 06-04-2007

Re: Warning: New SPAM threat - Your Latest Documents from RS Components

Quote from: Townman
What is the Cloudmark new threat catch-up / turn round window - hours, days or weeks?

I believe it can be hours if they get enough reliable reports. Most of these to me have been trapped already. I've reported one that wasn't (using the 'spam' button in webmail).
David
Community Veteran
Posts: 3,380
Thanks: 4
Registered: 18-01-2013

Re: Warning: New SPAM threat - Your Latest Documents from RS Components

Had 30-40 of these today - sent to an email address not used by PN so you can rule that out.
In fact they were sent to an email address with my full name showing as well so I suspect something to do with either Yahoo Groups or one of the many Chinese companies I've used that email address with.
Routefinder
Grafter
Posts: 382
Thanks: 1
Registered: 01-08-2007

Re: Warning: New SPAM threat - Your Latest Documents from RS Components

I did get 3 quarantine alerts to 3 separate mailboxes ~ not a thing I recall seeing before from @quarantine.plus.com
I would like to hope that had they gotten through my AV setup would have detected them Smiley