New Spam that bypasses most filters

PhilFCS

New Member
Reaction score
0
I've had numerous reports from my customers of certain employees mailboxes getting hammered daily with the same "style" of spam. An advertisement message, the user's email address in a "mail to" style link,
a link to a website presumably with more advertisements, and frequently some unrelated gibberish that looks like it was stripped off a website review or a legit email of some sort.
Then a link to unsubscribe that is obfuscated as un-sub-scribe or "to remove" or "to no longer receive" all kinds of random phrasing on the unsubscribe link.

The email address, the web url and the sending ip addresses are completely random must be some kind of botnet.

For one customer enabling the greylisting feature finally stopped the email. But since we've been migrating to Office 365 we lack that option not to mention old pop/imap accounts have no such feature either.

I ended up getting this on my own mailbox (so much for Office 365 spam filters) I got desperate and decided what the hell I'll do the unsubscribe even though conventional wisdom says that just tells the spammer you are reading these emails. So far it's been a week and a half of no further spam from this spammer.
I've gone ahead and assisted 2 other customers with this as well and it seems they too have stopped receiving the spam messages.

Anyone else seen this or is this somehow isolated to my area? Anyone else find any tricks to stopping the spam via filtering?
I'm still a bit shocked, a botnet that obeys unsubscribe requests... very strange.
 
In our office 365 setup you can create rules that show you to block embark based on phrases etc as well. If you are able and they ask have similar wording, maybe block by a couple of key phrases.
 
I've personally been getting a bunch lately on my gmail account. Been reporting them as spam, but still getting a couple here and there.
 
In our office 365 setup you can create rules that show you to block embark based on phrases etc as well. If you are able and they ask have similar wording, maybe block by a couple of key phrases.

That's the problem not a single phrase at all is similar, they range from Victoria Secret to Car Dealerships to Open Enrollment Healthcare services. I have a co-worker that blocks the word "unsubscribe" but I prefer not to as I have some newsletters I do want to receive. But as I said even the unsubscribe phrase is not consistent, I've got "Be removed here", "Modify mail preferences", "change subscription to our admail".
I've got 12 samples from my own issue with this spam and 12 different ways to say "unsubscribe".
 
Run your previous spam filter service ahead of O365...wash the mail ahead of it, if that previous spam filter service/appliance worked better.

Those e-mail started increasing in slipping through our spam appliance that we use for us and our clients, I finally kicked in graylisting and that put a huge dent in it.
 
Exactly, just use a commercial spam software such as symantec or sophos, direct your mx record to the appliance, and send it on to the mailserver from there.

Trust me, the big players in prefiltering have it all figured out, not much is going to get past these prefilters.
 
Back
Top