M
Mel
Here is the rundown of our incoming MIMAIL infected messages:
1. Hits external server as coming from (e-mail address removed),
(e-mail address removed), (e-mail address removed) or
usersupports##@paypal.com.
2. Routes to internal Exchange 5.5 mail system with Sybari Antigen.
Now shows sender as (e-mail address removed) instead of above.
3. Messages have no attachments.
4. Subject line is empty.
5. Message body contains garbage text beginning with this, but
including 20-30K more garbage.
6. Messages appear to be harmless, however, raising concern as more
Help Desk calls come in and now Paypal scam involved.
------------46734746001E1EB
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Dear PayPal member,
We regret to inform you that your account is about to be expired in
next five business days. To avoid suspension of your account you have
to reactivate it by providing us with your personal information.
To update your personal profile and continue using PayPal services you
have to run the attached application to this email. Just run it and
follow the instructions.
IMPORTANT! If you ignore this alert, your account will be suspended in
next five business days and you will not be able to use PayPal
anymore.
Thank you for using PayPal.
kkcksiis
------------46734746001E1EB
Content-Type: application/octet-stream; name="www.paypal.com.pif"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="www.paypal.com.pif"
TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAgAAAAA4fug4AtAnNIbgBTM0hVGhpcyBwcm9ncmFtIGNhbm5vdCBiZSBydW4gaW4gRE9TIG1v
ZGUuDQ0KJAAAAAAAAABQRQAATAEDAA/puD8AAAAAAAAAAOAADwELAQI3AEAAAAAQAAAAUAcAcI8H
Problems:
1. Sender filters don't work as the message sender is changing before
it hits our internal system.
2. Subject filters don't work as the subjects are removed.
3. Attachment filters don't work as the attachment is no longer there.
4. We do not yet have content filtering capability, so can not filter
on file names appearing in body.
5. We do not have any filtering on our external server.
Is anyone else seeing these messages this way?
What are you doing to block?
Thanks,
Melanie
1. Hits external server as coming from (e-mail address removed),
(e-mail address removed), (e-mail address removed) or
usersupports##@paypal.com.
2. Routes to internal Exchange 5.5 mail system with Sybari Antigen.
Now shows sender as (e-mail address removed) instead of above.
3. Messages have no attachments.
4. Subject line is empty.
5. Message body contains garbage text beginning with this, but
including 20-30K more garbage.
6. Messages appear to be harmless, however, raising concern as more
Help Desk calls come in and now Paypal scam involved.
------------46734746001E1EB
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Dear PayPal member,
We regret to inform you that your account is about to be expired in
next five business days. To avoid suspension of your account you have
to reactivate it by providing us with your personal information.
To update your personal profile and continue using PayPal services you
have to run the attached application to this email. Just run it and
follow the instructions.
IMPORTANT! If you ignore this alert, your account will be suspended in
next five business days and you will not be able to use PayPal
anymore.
Thank you for using PayPal.
kkcksiis
------------46734746001E1EB
Content-Type: application/octet-stream; name="www.paypal.com.pif"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="www.paypal.com.pif"
TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAgAAAAA4fug4AtAnNIbgBTM0hVGhpcyBwcm9ncmFtIGNhbm5vdCBiZSBydW4gaW4gRE9TIG1v
ZGUuDQ0KJAAAAAAAAABQRQAATAEDAA/puD8AAAAAAAAAAOAADwELAQI3AEAAAAAQAAAAUAcAcI8H
Problems:
1. Sender filters don't work as the message sender is changing before
it hits our internal system.
2. Subject filters don't work as the subjects are removed.
3. Attachment filters don't work as the attachment is no longer there.
4. We do not yet have content filtering capability, so can not filter
on file names appearing in body.
5. We do not have any filtering on our external server.
Is anyone else seeing these messages this way?
What are you doing to block?
Thanks,
Melanie