Fake party invitations - Spam getting through
Problem reported by Douglas Foster - Today at 4:45 AM
Submitted
I am seeing a new attack technique centered around anonymous party invitations:  The recipient has to click the link to find out the details of who the party is for and when it is occurring

I have four examples from Gmail and one example from Yahoo.   The subject lines were all different:
  • RSVP: Invitation from Arlene Malone
  • Arlene Malone sent you an invitation
  • Shukriyyah Payne INVITE YOU
  • Join Us to Celebrate a Milestone
  • SPECIAL INVITAION
  • REMINDER: Your invitation is ready!
  • COME CELEBRATE THIS SPECIAL OCCASION WITH US
The message bodies were also unique.   Some used references to Punchbowl or Evite, some did not bother.   The Gmail messages had this header field:
  • X-Forwarded-Encrypted: i=1; <meaningless string, base64-encoded>
  • To: undisclosed-recipients:;
The one from Yahoo did not have a To: header at all.
It also had this header field, which is probably irrelevant, but I am grasping at straws:
X-Mailer: WebService/1.1.26380 YMailNovation

It may become necessary to quarantine anything come from unknown Yahoo and Gmail addresses, regardless of detected risk, but doing that would be pretty disruptive to our legitimate traffic.

Reply to Thread

Enter the verification text