CudaMail Solutions

 Monday, April 28, 2008
Monday, April 28, 2008 1:51:12 PM (Mountain Daylight Time, UTC-06:00) ( Anti-Spam | CudaMail | False Spam | Outlook Plug-In | Spam Filtering Service )
Mark - as the handler on duty at the Internet Storm Center - was nice enough to not only read all his spam for the week (about 2500 messages) but he also put together a nice chart showing what type of spam he was getting and from where:

Description

Email Origin

 

Greeting card

Germany

 

URL Link to exe.  28/33 AV products detected the file, three days ago it was 4.

Viagra/Cailis Mesages

Texas
Latvia
Paris
Russia
Chilli

Mount Laurel (US)
US
Italy
Israel

Links to Canadian Pharmacy web site.

Viagra/Cailis Meds

France

 

Web Site Canadian Healthcare

Movie downloads
(in Chinese)

Argentina

 

Nothing no links and nothing nasty, maybe a trial run.

Herbal remedies

USA
Germany

Sweden

Oman
Lithuania

Brazil

 

Products to enlarge body parts.

The message contained a URL to one of three sites hosted in the same address range.

The registrar owns 695 other domains, received 50 of them.

Lottery*

UK
Canada

Greece

 

So far this week I have won  about $500,000,000, not bad for not entering any lotteries.   The majority were sent from UK machines, machines at one particular facility.

Click Fraud

Spain
Bolivia

Poland

 

The links in the message are ad click redirects.

Paypal

US

France

 

The usual phishing exercise aimed at extracting account information.

I am Lonely Tonight

Turkey

 

The usual I’m lonely tonight emails.  If you respond it goes into how she wants to travel and can’t you help her out.  

Fake Goods

Bombay
Russia

Bahrain

Greece

Italy

Turkey
Slovak Republic

Thailand

Fake goods, watches, bags, etc. 

Business Proposal (419 messages)

US
Germany
Los Angeles

United Arab

Emirates

The Netherlands
Japan

Transfer money and get a percentage.

Work offers

Belgium

 

Work for a few hours per week and make thousands,  most of these linked to professional looking sites.   Typically they are recruiting for mules.

Threats

Turkey

Russia

There have been a few variants of these doing the rounds.


> Source: http://isc.sans.org/diary.html?storyid=4343

This is a lot of work that Mark has gone through but it does highlight the value of good metrics or ways of gauging how effective an anti-spam system is.

Here at the CudaMail support desk we occasionally get a client who at first is very upset that they got 5 spam messages in their inbox this morning and can't we do something about it? They are usually very thankful when we provide them with a report similar to the one below for their domain showing that tens of thousands of messages have already been blocked for them and these 5 messages are the start of a new campaign that they were lucky enough to get the first few messages from and now that they have provided us with some samples to work with we can stop this campaign in it's tracks too.

Sample CudaMail Spam Quarantine Summary



> Click CudaMail_Summary_for_Domain.pdf (12.76 KB) for to download the PDF sample

This also highlights the different perceptions we have as anti-spam specialists and the typical end-user or client. From our perspective we are fighting the good fight and our efforts are winning the war on spam. We block millions of messages a day and allow only a few 10's of thousands to be delivered to the client. Typical statistics are that on average 97 out of every 100 messages are spam and this is with a very low false positive rate (false positive = marking a wanted message as spam).

What is The Customer's Perspective On The Same Volume of Messages?

They are going about their important work without being bothered by those 97 out of 100 messages that are spam so when a few messages slip through to them all of a sudden they are being "flooded" with spam. Same numbers but a very different perspective on the issue.

What Can You - the CudaMail End-User - Do to Help Out?

1. Keep us in the loop. "One person's spam is another person's ham" as the saying goes so we don't know what you did or did not sign up for online. We maintain a number of spam traps and are always looking for new spam messages but may not be first in line when a spammer fires up his money making spam bot and sends out the latest surge. So if you are the lucky one to be fist on the spammers list and get a spam sample there are two very good ways to provide this feedback to CudaMail support.

2. Install and use the Outlook plug-in. For those of you who use Microsoft Office with the full Outlook e-mail client the Plug-in is the easiest way to send spam samples back to CudaMail support and we have blogged about this before. There are plug-ins available now for other e-mail clients (Thunderbird 2.x and Lotus Notes 6.5, 7 and 8) but these are under going beta testing right now.

You can read me Blog post about it by going here:


3. Debug-ID. For those who don't run Outlook or don't want to run a beta plug-in you can simply forward just the Debug-ID of the unwanted messages to the support@CudaMail.com address.

A quick 'How to display full headers in client x' can be found at the following URL:
While support only needs the one line with the X-ASG-Debug-ID: number on it go ahead and forward all the information in the full headers on to us. What you do not want to do is forward the spam message body along with the full headers. What happens more often than not is that the CudaMail system will take your spam sample re-processes it and block it before it gets to support. We don't know that you were trying to send us this sample and can't do any thing about it because we didn't get it in the first place. Now typically we don't respond to every message providing a spam sample but we do review each and every one of them and make sure that he system will block them in the future.

With the above two thoughts in mind - perspective and feedback - what do you - the CudaMail client - want to see from the CudaMail system? Do you want to be sent reports on a regular basis (Daily, Weekly or Monthly) or will this just add to your information overload?

We look forward to hearing from your either in the comments below or direct to support@CudaMail.com.

- Shaun

Comments [0] | Trackback | # 
 Thursday, February 28, 2008
Thursday, February 28, 2008 4:57:21 PM (Mountain Standard Time, UTC-07:00) ( Anti-Spam | CudaMail | Outlook Plug-In | Spam )
Do you want to educate the CudaMail system so it understands better what kind of e-mail you want to get and what you consider as spam?

Do you want to have a very easy way to submit SPAM and false positive reports?

Do you want an easy way to keep your white list up to date?

If you answered YES to any of the above questions then you may want to try the Outlook Plug-in.

Getting to Know The Outlook Plug-In:


This very simple toolbar can be installed in the Outlook 2000 to 2007 e-mail client (not Outlook Express or the new MS Mail) to give you some additional options and two new buttons. These Green and Red buttons with an envelope and either a Check Mark (good) or Red X (bad) make the process of sending a report back to the system that you consider a message SPAM or Wanted as easy as clicking on the corresponding button. It can't get any simpler than that!

To download the toolbar simply go to the CudaMail Web Portal and click on the 'Get Mail Client Plugins Here' link at the bottom of the page. (this download link is only for current CudaMail customers - if you have a Barracuda Spam Firewall and want the plug-in go talk to your network administrator)

Per-user Web portal is at https://web.CudaMail.com

Once you download the Outlook Plug-in you have to run it to install it so you need to do this with an account that has administrative access to your PC. After it is installed you should be able to get to the 'Spam Firewall' tab under the 'Tools' - 'Options' menu item and it should look something like this:



What Does This All Mean?

Automatically Update White list: When this option is checked off every time you add someone as a new personal contact or e-mail someone then they will be added to your personal white list. While this sounds like a great idea you need to login to your personal options area on the CudaMail system on a semi-regular basis to clear out old or stale white list entries and specifically to make sure your own e-mail address is not on the white list.

A typical spammer trick is to send you spam pretending to be you so you do not want to white list your own e-mail address or you will get more spam.

This can happen by accident if you 'reply all' to an e-mail and don't take your e-mail address off or if you are in the habit of always cc'ing yourself.

Additional Button Actions:

Spam: Permanently Delete Message or Move to Deleted Items folder.

While I like to completely get rid of any spam messages by leaving it on the 'Permanently Delete Items' option you have no way of easily getting back any message you accidently marked as Spam. By setting this option to "Move to - Deleted Items Folder' you can always rescue it from there if you have an accident.

Not Spam: Add E-Mail addresses to Whitelist. When a message come through with the subject tagged as spam '[CudaMailTagged] -original subject' and you click on the Green button to submit a 'falsely marked as spam' report this option will also update your personal whitelist so that this senders e-mail will not be tagged in the future.

There is a second benefit to the plug-in as it is building your own personal database of 'Good' and 'Bad' messages that are unique to you. Once you have marked at least 200 messages of each type then the statistical analysis or 'Barracuda Bayesian Learning' will kick in and provide additional protection against Spam. You will only be able to mark messages that have been processed by the CudaMail system so don't just select everything in your inbox and try to mark them all as 'good'. What you should do is look at the message and ask yourself 'Did this e-mail come from outside our organization and is it a representative sample of e-mail that I want to get in the future?'

This plug-in is also the answer to questions like the following:

1. How do I automatically whitelist all of my contacts?
2. I get so few messages in the per-user quarantine how am I ever going to get 200 'good' messages?
3. How do I send you samples of spam that I don't want?

Does the Outlook plug-in work with Microsoft Vista?

Yes the Outlook Plug-in versions 2.1.0.5 and above work with Microsoft Vista and Outlook 2007. The plug-in version can be found on the licensing screen when installing the plug-in, or in Microsoft Outlook by viewing the Spam Firewall tab in the Options window. The version number will be located in the bottom-right corner of the window.

If you can give the Outlook Plug-in a try. I have been using it myself for the last 2 years and I get a sense of joy every time I can click on the 'Spam' button because I know that this is making the Spammer's job that much harder next time.

- Shaun

Comments [0] | Trackback | # 

About the author

Shaun Sturby, MCSE Shaun Sturby, MCSE
Technical Services Manager, and Optrics' point person for email security

  Navigation

  Search

  Tag Cloud

  Category Feeds

  Archive

  Blogroll

  Statistics

Total Posts: 41
This Year: 41
This Month: 3
This Week: 1
Comments: 5


Subscribe


Technology Blogs - BlogCatalog Blog Directory
 

© Copyright 2008, Optrics Inc.