spamming from zombies

Unanswered Question
Oct 12th, 2007
User Badges:

in our organization (italian ISP) we have ten ironport appliance for relay service of our customers.
In last weeks we are receiving a lot of spam from clients probably infected by worms.
These messages are not blocked from IPAS.
The bodies, senders, recipients ed subjects change continuosly. It's an hard work for us insert filters every few hours.
All messages have a similar entry in the header. After the ehlo the worm insert a variable number of digit (from 4 to 8 digit).
For example:
EHLO 8035583
EHLO 5516357
EHLO 5649719

Is it possibile to insert a filter that drops connections if after helo a numeric value is inserted ?

Thanks for your help.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Mark [CSE]_ironport Tue, 10/16/2007 - 10:34
User Badges:

You cannot filter on the HELO line in the SMTP session. Content or message filter are no able to parse this information.

You can only submit the samples to help us improve our IPAS rules.

Best Regards,



This Discussion