Hallo Zusammen,
seit einigen Tagen sind wir Ziel einer Spam-Flut mit kyrillischen Werbetexten bzw. Werbegrafiken im Anhang. Die Mails werden leider nicht als Spam klassifiziert. Die Absender stehen nicht auf der Whitelist.
Anbei einige aktuelle Header als Beispiele:
Return-Path: <roddenberryd424@bk.ru>
Received: from unsere_domain ([unix socket])
by callisto.unsere_domain.local (Cyrus v2.3.14) with LMTPA;
Wed, 12 Aug 2009 09:56:16 +0200
X-Sieve: CMU Sieve 2.3
Received: from localhost (callisto.unsere_domain.local [127.0.0.1])
by localhost (Postfix) with ESMTP id 8F3931E075
for <empfänger@unsere_domain>; Wed, 12 Aug 2009 09:56:15 +0200 (CEST)
Received: from cube1.unsere_domain (cube1.unsere_domain.local)
by unsere_domain (Postfix) with ESMTP id A11961E073
for <empfänger@unsere_domain>; Wed, 12 Aug 2009 09:56:13 +0200 (CEST)
Received: from [190.241.229.15] (unknown [190.241.229.15])
by cube1.unsere_domain (Postfix) with ESMTP id 15BD2F7E6;
Wed, 12 Aug 2009 09:56:14 +0200 (CEST)
Received: from [132.8.51.126] (account roddenberryd424@bk.ru HELO bzyavoqldwxlh.phoyr.ua)
by (CommuniGate Pro SMTP 5.2.3)
with ESMTPA id 565019920 for empfänger@unsere_domain; Wed, 12 Aug 2009 01:56:12 -0600
Message-ID: <1296065116.VBMBT8HU978779@jarsyyxkbttic.ianhlik.s u>
From: =?koi8-r?B?89TBzsnTzMHXIA==?= <exuma@aol.com>
To: <empfänger@unsere_domain>
Subject: ***SPAM*** =?koi8-r?B?8+/n7OHz7/fh7unlIPDl8uXw7OHu6fLv9+/r?=
Date: Wed, 12 Aug 2009 01:56:12 -0600
MIME-Version: 1.0
Content-Type: text/plain;
charset="koi8-r"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4133.2400
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
X-Virus-Scanned: by Intranator (www.intra2net.com) with AMaViS and F-Secure AntiVirus (fsavdb 2009-08-12_04)
X-Spam-Status: hits=20.8
tests=[BAYES_99=3.5,FORGED_MUA_OUTLOOK=3.116,FROM_EXCESS_ BASE64=1.456,I2N_RAZOR_ADJUST_2=-3,I2N_RAZOR_ADJUST_3=-3,RAZOR2_CF_RANGE_51_100=3.5,RAZOR2_CF_RANGE_E4_51 _100=3.5,RAZOR2_CHECK=3.5,RCVD_IN_BL_SPAMCOP_NET=2 .5,RCVD_IN_CBL=1.5,RCVD_IN_UCEPROTECT1=0.5,RDNS_NO NE=1.5,TVD_SPACE_RATIO=2.219]
X-Spam-Level: 1208
Return-Path: <boyery28@sanyo-machine.co.jp>
Received: from unsere_domain ([unix socket])
by callisto.unsere_domain.local (Cyrus v2.3.14) with LMTPA;
Wed, 12 Aug 2009 05:43:05 +0200
X-Sieve: CMU Sieve 2.3
Received: from localhost (callisto.unsere_domain.local [127.0.0.1])
by localhost (Postfix) with ESMTP id ECD001E073
for <empfänger@unsere_domain>; Wed, 12 Aug 2009 05:43:04 +0200 (CEST)
Received: from callisto.unsere_domain.local (callisto.unsere_domain.local [127.0.0.1])
by unsere_domain (Postfix) with ESMTP id 684C51E06F
for <empfänger@unsere_domain>; Wed, 12 Aug 2009 05:43:01 +0200 (CEST)
Received: from mail.unsere_domain []
by callisto.unsere_domain.local with POP3 (fetchmail-6.3.9)
for <empfänger@unsere_domain> (multi-drop); Wed, 12 Aug 2009 05:43:01 +0200 (CEST)
Received: from ens41fl..de (root@localhost)
by unsere_domain (8.12.11.20060308/8.12.11) with ESMTP id n7C3gDfP028541
for <empfänger@unsere_domain>; Wed, 12 Aug 2009 05:42:19 +0200
Received: from SGZXGOARTV ([123.22.12.101])
by (8.12.11.20060308/8.12.11) with ESMTP id n7C3g0AI028432
for <empfänger@unsere_domain>; Wed, 12 Aug 2009 05:42:06 +0200
X-ClientAddr: 123.22.12.101
X-Envelope-To: <empfänger@unsere_domain>
Received: from 123.22.12.101 by fw.sanyo-machine.co.jp; Wed, 12 Aug 2009 10:41:58 +0700
Message-ID: <000d01ca1afe$d815e790$6400a8c0@boyery28>
From: =?koi8-r?B?88HbwSDzwdfXwdTFxdfJ3g==?= <boyery28@sanyo-machine.co.jp>
To: <empfänger@unsere_domain>
Subject: ***SPAM*** =?koi8-r?B?7sUg1cTBzNHK1MUg3NTPINDJ09jNzw==?=
Date: Wed, 12 Aug 2009 10:41:58 +0700
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0007_01CA1AFE.D815E790"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 4.72.3110.3
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.3110.3
X-Virus-Scanned: ClamAV version 0.93, clamav-milter version 0.93 on 82.140.32.218
X-Virus-Status: Clean
X-Virus-Scanned: by Intranator (www.intra2net.com) with AMaViS and F-Secure AntiVirus (fsavdb 2009-08-11_17)
X-Spam-Status: hits=19.9
tests=[BAYES_80=2,FROM_EXCESS_BASE64=1.456,HTML_FONT_SIZE _LARGE=0.001,HTML_MESSAGE=0.001,I2N_RAZOR_ADJUST_2 =-3,I2N_RAZOR_ADJUST_3=-3,MIME_QP_LONG_LINE=1.396,RAZOR2_CF_RANGE_51_100=3 .5,RAZOR2_CF_RANGE_E4_51_100=3.5,RAZOR2_CHECK=3.5, RCVD_IN_BL_SPAMCOP_NET=2.5,RCVD_IN_CBL=1.5,RCVD_IN _NIX_SPAM=2.5,RCVD_IN_SPAMRATS_NOPTR=0.5,RDNS_NONE =1.5,XMAILER_MIMEOLE_OL_83BF7=2.069]
X-Spam-Level: 1199


Zitieren
