Delivery failures from spoofed users. Spam?

Users in our organization are receiving delivery failures for messages they did not send. The only mail clients in use are Notes 6.51.

The server config doc is set to deny all relaying from external sources. Although it wouldn’t make a lot of sense, given the reference to “notice.zip” I thought it might be somehow related to W32/Netsky.z@MM but there is no evidence of that virus on the servers or user machine. Any thoughts on how this is happening would be appreciated. Here’s a copy of the delivery failure the user, Leon, received (He denies any correspondence with short nurses):


Hi. This is the qmail-send program at excite.com.

I’m afraid I wasn’t able to deliver your message to the following addresses.

This is a permanent error; I’ve given up. Sorry it didn’t work out.

shortnurse@xprdmailbe.nwk.excite.com:

The users mailfolder (user=shortnurse) is over the allowed quota (size).

— Below this line is a copy of the message.

Return-Path: leon.boxer@acme.com

Received: (qmail 13008 invoked from network); 7 May 2004 13:25:28 -0000

Received: from unknown (HELO xprdmx26.nwk.excite.com) ([10.50.28.166]) (envelope-sender leon.boxer@acme.com)

      by 0 (qmail-ldap-1.03) with SMTP

      for <shortnurse@xprdmailbe.nwk.excite.com>; 7 May 2004 13:25:28 -0000

Return-Path: leon.boxer@acme.com

Received: from excite.com (firewall.islandone.com [216.79.62.130])

	 by xprdmx26.nwk.excite.com (Postfix) with ESMTP id E076573227

	 for <shortnurse@excite.com>; Fri,  7 May 2004 09:25:21 -0400 (EDT)

From: leon.boxer@acme.com

To: shortnurse@excite.com

Subject: Hi

Date: Fri, 7 May 2004 09:22:22 -0400

MIME-Version: 1.0

Content-Type: multipart/mixed;

	 boundary="----=_NextPart_000_0012_00006AFB.0000601A"

X-Priority: 1

X-MSMail-Priority: High

Message-Id: 20040507132521.E076573227@xprdmx26.nwk.excite.com

X-FII-Tracking: 0.636624

This is a multi-part message in MIME format.

------=_NextPart_000_0012_00006AFB.0000601A

Content-Type: text/plain;

	 charset="Windows-1252"

Content-Transfer-Encoding: 7bit

Important notice!

------=_NextPart_000_0012_00006AFB.0000601A

Content-Type: application/octet-stream;

	 name="Notice.zip"

Content-Transfer-Encoding: base64

Content-Disposition: attachment;

	 filename="Notice.zip"

Subject: yup - viral activity

Viruses and spammers both can send out messages with some.address@yourdomain.tld as faked sender address. That would cause all the non deliverable messages to be routed back to your server, even though the messages didn’t originate from you or your endusers. It’s just someone or something using your domainname!

A spammer would probably have used a fake address@your.domain.tld, a virus uses harvested (and thus probably real) addresses. So, in your case, it’s most probably a virus.

Subject: RE: yup - viral activity

I am having a similar experience. My gateway server 6.02 CF2 (running McAfee) is picking up about 50 messages a day infected with various flavors of the Netsky virus. I finally got tired of users asking if they had a virus every time they received an email saying that a message that they “sent” contained a virus that could not be cleaned, so I configured McAfee to only alert the Administrators when a virus was detected. I have the latest antivirus updates and did a full virus check on all of my Notes servers today and did not find a virus. I never believed that Notes clients were vulnerable to viruses, so I have always assumed that the infected messages were from outside. We are a company of 300 Notes users, all on Notes clients with a few who also use HTTP. I am beginning to wonder if the infected messages are being generated internally. Does anyone have any thoughts on this. Some of our users are remote, so I frequently have to deal with older OS versions as well as out of date virus definitions on their laptops.

Subject: Hello, HELO?

After re-reading my post I wonder if it just a spammer using the HELO/EHLO manipulation game?

Subject: RE: Hello, HELO?

Subject: RE: Hello, HELO?

Thanks for the post, Carsten. Great link.

Gregg

Subject: Pretty sure its not a virus in my environment, however…

First of all, thanks for your postings. However, as I mentioned in my original post I think I have already ruled out the Netsky virus operating inside our environment as the source of the problem and have another hypothesis.

A scan by trendmicro using the current definition file confirmed no infection. There are no virus related entries in the registries, none of the virus executables are found on the systems and none of the virus associated directories exist. I’m pretty sure this is not originating from within our environment. The link Carsten posted is a good overview of Netsky but when you look at the technical specs (Threat Encyclopedia | Trend Micro (US)) it seems the virus harvests spoofed “from” addresses from specific file extensions that does not include NSF. Since the worm apparently does not hit NAMES.NSF for addresses and there is no detectable evidence it exists on any system I’ve got to think its not Netsky generating spam from INSIDE my environment.

How about this hypothesis…If another company (non-Notes mail) has a Netsky infection and someone at that company has one of our users, i.e. leon.boxer@acme.com, in their Outlook address book then when the virus sends out spam from that company the “from” field would be leon.boxer@acme.com. If, for whatever reason, the intended recipient of the spam rejects the email where would the delivery failure be sent? I’m thinking good old Leon. That would explain why I couldn’t find any sign of Netsky internally but we’re getting delivery failures that have references to Netsky type content.

Subject: RE: Pretty sure its not a virus in my environment, however…

You are right. It is not a virus inside your environment.

It is a virus outside your environment. Not a lot you can do about it but for more background, start here:

http://chris-linfoot.net/plinks/CWLT-5WFLYW

http://chris-linfoot.net/plinks/CWLT-5QNAYC

http://chris-linfoot.net/plinks/CWLT-5XLCVV

http://chris-linfoot.net/plinks/CWLT-5WRJ99

Subject: Thanks…