Reply to topic
How to filter emails generated by w32.beagle.j
jamie
HostMySite Sales Rep
HostMySite Sales Rep

Joined: 19 Mar 2004
Posts: 770
Location: Newark, De
Reply with quote
By setting up filters in Web Messaging, you can actually filter the annoying messages generated by the Beagle.J virus (the ones warning you about your email account be 'disabling').

Here's how an IpSwitch Imail walkthrough on how to do so:
(located at http://support.ipswitch.com/kb/IM-20040303-DF01.htm)

NOTE: This walkthrough is given from the server-side point of view. When configuring the client-side webmail application you will not be able to follow step by step; simply setup your rules to match the ones described below.

Question/Problem: How do I configure IMail to block the new Beagle.J virus?

Answer/Solution: The virus transmits itself inside an encrypted (password protected) .zip file which AV applications currently cannot decode to scan the file contents. To trap the messages, create a rule that searches for the subjects used by the emails generated by the virus. It is recommended the rule be configured to forward the virus-infected emails to an account for review. Upon review, the headers of the infected messages will show the connecting IP in the 'Received' path. This IP can be blocked from connecting to the IMail server by adding it to the SMTP Control Access list.

1. Select the 'Inbound Rules' tab and click 'Add'.

2. In the 'Rules' dialog, select 'If the Subject' from the 'Select Rule' menu. Also, select 'Contains'.

3. In the 'Search Text' field type:
e-mail account disabling warning

4. Click 'Add Condition' and then click 'Insert OR'.

5. In the 'Search Text' field, remove the text currently entered and type:
e-mail account security warning

6. Click 'Add Condition' and then click 'Insert OR'.

7. In the 'Search Text' field, remove the text currently entered and type:
email account utilization warning

8. Click 'Add Condition' and then click 'Insert OR'.

9. In the 'Search Text' field, remove the text currently entered and type:
important notify about your e-mail account

10. Click 'Add Condition' and then click 'Insert OR'.

11. In the 'Search Text' field, remove the text currently entered and type:
notify about using the e-mail account

12. Click 'Add Condition' and then click 'Insert OR'.

13. In the 'Search Text' field, remove the text currently entered and type:
notify about your e-mail account utilization

14. Click 'Add Condition' and then click 'Insert OR'.

15. In the 'Search Text' field, remove the text currently entered and type:
warning about your e-mail account

16. Click 'Add Condition' and then click 'OK'.

17. Select 'Forward' and in the 'Address:' field, enter the complete email address to which you want the emails forwarded. This can be an existing user account or you can create a new account just for the viruses. The rules engine will not create the account if it does not exist.

18. Click 'Apply'.

More information on the virus can be found at the Symantec website:[url]
http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.j@mm.html[/url]
How to filter emails generated by w32.beagle.j
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic