Know your ISP.

User #238393   63 posts
Participant

Received a United Parcel email scam through my isp being iprimus yesterday which had a malware.exe attached which was disguised as a word document.

Had a bit of a play around with this malware then zipped and emailed to an antimalware developer for addition to the data base.

Received an email from the iprimus postmaster:
"The following viruses were detected in the message (MID ..............):
'Troj/Agent-HFZ', 'Troj/Invo-Zip'

Actions taken:
Message archived
Message dropped"

What I would like to know is why the malware message came through unhindered to my email address, probably by a dictionary attack, but it was stopped by iprimus when I tried to email it to the antimalware developer.

posted 2008-Jul-23, 11pm AEST
edited 2008-Jul-24, 12am AEST
User #107898   822 posts
ISP Representative

Jaxryley writes...

What I would like to know is why the malware message came through unhindered to my email address, probably by a dictionary attack, but it was stopped by iprimus when I tried to email it the malware developer.

Do you have the AV/AS Product enabled?

We use a cluster of IronPort Anti-Spam appliances for Anti-Spam both inbound and outbound (separate clusters) behind load balancers.

If you don't have the full AV/AS feature enabled you only get the basic IronPort reputation based filtering, which is fairly effective, but it doesn't do deep scanning.

We do more deep scanning on the outbound IronPort's because we need to ensure that our customers are not able to send Spam, if they were able to relay Spam through them, they would get blacklisted and that would impact negatively on all customers, not to mention we have a responsibility to prevent outbound Spam.

The main reason for the cost for deep scanning product is we need to recover some of the cost of providing the Anti-Spam service, as IronPorts are a per-user licence.

IronPort have become very popular, we trialled a lot of anti-spam appliances before we made our decision and we felt it was the best quality and value, and a great many other Australian ISPs have done the same.

Cheers,

Rory

posted 2008-Jul-24, 12am AEST
edited 2008-Jul-24, 12am AEST
User #238393   63 posts
Participant

Thanks for reply Rory.

Malware this end is no prob and I was just wondering how the email system worked.

Can't send my samples via yahoo mail either.Probably be better to upload them to rapidshare and send the link to the developer.

posted 2008-Jul-24, 12am AEST
Hosted by
WebCentral Australia
Big numbers
953,752 threads
16,780,490 posts
1,968,187 whims sent
2,997 wiki topics
236 ISPs listed
8,018 broadband plans
804 modems & routers
39,415 features filled