Quantcast
PC World: Technology Advice You Can Trust
Techlog
News, opinion, and links from Editor in Chief Harry McCracken.
Recent entries in this blog:
Sunday, May 15, 2005 5:47 PM PT Posted by Harry McCracken

The Mystery of the Right-Wing German Spam

At first, it sailed right into my mailbox without me noticing it. Then I realized that I was getting a lot of spam in German this weekend. (My college German is very, very rusty, but I could tell that it seemed to link to sites discussing right-wing political matters.)

I assumed I was probably the only lucky guy getting this...until I asked my PC World coworkers and found that they were receiving it, too.

Then I Googled around and found bloggers wondering about the German spam in their inboxes. The world, it seems, is experiencing a right-wing German spamademic at the moment.

And it turns out that there's a fairly straightforward reason why: At the moment, the Sober.q worm, a variant of one that's been around since 2003, is purloining e-mail address from people's address books and pelting them with propaganda. (As usual, the fact that the mail is turning up in your inbox isn't evidence that your PC is infected; just that a PC out there with your contact info in its address book is.)

All this startled me, in part because the Postini anti-spam service we use here at PC World does a pretty good job, so I'm not used to seeing much spam of any sort. (It's logical enough that spam in another language might slip by more easily.) But it's not a new problem: Eleven months ago, Sober.g, an earlier variant, did much the same thing.

So did your e-mail get clogged up with this stuff this weekend?
Comments

yep. i've gotten 15 messages so far. provided an opportunity for my partner to rehearse her college german also :)

acg
May 15, 2005
6:15 PM PT

yes, i've gotten mayb 200 unwanted emails in German in the last 20 hours.

stephen
May 15, 2005
6:19 PM PT

Yes, I'm receiving lots of German spam about 20 in total thus far but I'm sure more is to come. I use Yahoo and I hope they implement something to stop the spam.

Anonymous
May 15, 2005
6:53 PM PT

I have received over 900 of these emails on my work account in the last 24 hours. This is terrible!

susan
May 15, 2005
7:14 PM PT

Yes. I have been receiving messages in German complaining about the firebombing of Dresden in 1945 and how the Allied commanders were never charged with war crimes.

Matthew Miller
May 15, 2005
7:21 PM PT

We have blocked close to 3000 since making rule changes to our work Spam Filter yesterday

ffasle
May 15, 2005
7:22 PM PT

Nope. Not a single one. I've read about this on the GMail boards, but I can truthfully say that I got no German right wing spam.

Tom S
May 15, 2005
7:28 PM PT

got well over 60 emails to my corporate account

Neal
May 15, 2005
7:44 PM PT

o yeah... i send those emails...Deutschland Uber Alles!!!

Jacob Goldstein
May 15, 2005
7:51 PM PT

i got about 200 in the past 2 days... just started on Saturday around 5:30PM for me... :( hope our network does something to fix it soon!

cathryn
May 15, 2005
7:59 PM PT

Isnt it interesting that we are getting spamed about Dresden while the US and UK are fighting a war that not many agree with? I think whoever is behind this has deeper intentions than just bugging us over the weekend.

The Historian
May 15, 2005
8:20 PM PT

I've had hundreds, and upon closer examination they aren't sent directly to me. They are sent to obscure addresses such as X-mailer@sbcglobal.net, server@sbcglobal.net, and they are only coming through when I check my mail using Outlook express.

michael brown
May 15, 2005
9:25 PM PT

I have a comcast email address and I have been receiving about 20 a day since Friday night. I tried replying to a few of them to tell them to remove me from their mailing address but the return delivery was unacceted.

Barb
May 15, 2005
9:36 PM PT

I have a comcast email address and I have been receiving about 20 a day since Friday night. I tried replying to a few of them to tell them to remove me from their mailing address but the return delivery was unacceted.

John Smith
May 15, 2005
9:37 PM PT

I staff a help desk for a small ebook biz that does a pretty good business. There were 330 when I logged on this morning, and they kept coming all day until I logged off about 6 hours laters, at a rate of 20 an hour. I'm no techie so I don't know how it works, but it appeared to have attached itself to one of our customer's email address because two of them ended up associated with one of their tickets. I'd sure like to understand how it works and if it can be halted somehow. Another blocker? Forgive me if I don't leave my email address!

molly
May 15, 2005
9:41 PM PT

SpamAssassin Rule:
http://mailscanner.prolocation.net/german.cf

As seen here: http://article.gmane.org/gmane.mail.spam.spamassassin.general/67203

Dulantha Peiris
May 15, 2005
9:45 PM PT

I have been getting hit both as a "source" and as a target - Gmail is starting to get the idea.

I have, however identified one source.

I would like to take this opportunity to those who have "recieved" it from me to say: it is not me!

Wayne
May 15, 2005
10:01 PM PT

At least 100 here so far, not counting the ones that didn't make it through the spam filters.

a reader
May 15, 2005
10:19 PM PT

Thanks for the german.cf!!!!!

Matt
May 15, 2005
10:59 PM PT

I work at a German publication (not right wing) whose website was apparently also linked in some of these spam emails, for reasons we still don't really understand. Anyone who has received these emails, is there a link to Spiegel Online? We're suffering under a mountain of spam as well as potentially very bad PR.

Scott Lamb
May 16, 2005
12:39 AM PT

mine had mike myers dressed in a black leotard, dancing strangely.

red hand
May 16, 2005
1:13 AM PT

We got 52 every ten minutes to our work email. First thing this morning that meant about 20,000 emails mostly sent through to the admin account but also loads to sales@..., manager@...etc.

They are still coming through as well.

And guess who gets the blame... the IT manager :(

Andrew S
May 16, 2005
2:57 AM PT

Yep. Got it at home and then at work. Just started my new job, so was concerned since no one should have this email address yet.. Thanks for techlogging it. Now I know and knowing is half the battle.

Bob
May 16, 2005
3:15 AM PT

I have gotten over 200 the last coupld of days. It seems that our Spam Filter is going to need a little tweaking

Gene
May 16, 2005
3:36 AM PT

> SpamAssassin Rule:
> http://mailscanner.prolocation.net/german.cf

A better way to filter off those, if you can, is to look at the "To: " field. In the case of this Sober spam, it contains a non-existing address in your domain. You can use it to filter out this spam.

The german.cf rule is dangerous as it can filter legitimates email that have the same subject (e.g. Tuerkei in die EU).

nobody
May 16, 2005
3:38 AM PT

3000 spams - wasting an hour trying to get rid of it all

Michael hussey
May 16, 2005
5:58 AM PT

I had 22 this morning.

brad
May 16, 2005
9:00 AM PT

I thought the worm was actually someone in my German department, because I didn't get any right-wing German sites, but Communist and other left-leaning German sites.

Nate
May 16, 2005
9:32 AM PT

My admin/info mail box for my organization got a couple thousand over the weekend. Most were not addressed to admin or info, but to random names/words@myorganization.org. It was very time consuming to deal with and I have revamped my spam filtering as a result.

Jessica J.
May 16, 2005
9:43 AM PT

I've gotten thousands of those buggers through the email addresses set up for my website. Not even the filters I set up were working and after a while my addresses was starting to appear in both the to and from fields! I gave up and disabled those email addresses for now.

Scott Lamb: Many of the ones I received linked to Spiegel Online. Way too many to count, in fact.

Debi
May 16, 2005
9:50 AM PT

My admin/info mail box for my organization got a couple thousand over the weekend. Most were not addressed to admin or info, but to random names/words@myorganization.org. It was very time consuming to deal with and I have revamped my spam filtering as a result.

Anonymous
May 16, 2005
10:00 AM PT

Yes, I've gotten dozens of these stupid e-mails on my work e-mail address and a few on my personal so far. It sucks!

Barbara C.
May 16, 2005
10:07 AM PT

Yes, I got them too...not even a computer "guru" but still wound up with them anyway...got about 100 of them but none in the last couple of hours...I too tweaked my spam filter on Yahoo.

Becca
May 16, 2005
10:24 AM PT

i am a listserv manager, i got 1,500 german spams today and 500 yesterday. since we use lotus notes, i used rules to block these. but i am still getting leakers with new german keywords.

hope this peaks soon...

jerry
May 16, 2005
11:15 AM PT

I got an unsolicited email directing me to a German propaganda website. I wish I were dead.

Anonymous
May 16, 2005
11:19 AM PT

SpamAssassin Rule:
http://mailscanner.prolocation.net/german.cf

WORKS!

nn
May 16, 2005
11:36 AM PT

I have a local.cf in my
etc/mail/spamassassin dir
I dropped the german.cf in there and it dod not seem to work. what types of things should I be looking at?

patrick
May 16, 2005
12:26 PM PT

I only had one! It came in on Sunday. From reading how many everybody else had hit them, I would say our IT guy rocks. I work in sales so I send out a lot of emails to clients also.

jimmyjames
May 16, 2005
12:31 PM PT

I was concerned initially since I had visited the website for a neo-nazi type group based in Kansas who is supposed to picket our high school's graduation ceremony with hate based "religious" messages. After visiting their site I started getting this crap. Furthermore, neither Norton or Microsoft's Ad Aware type software detected anything amiss with my machine.

Anonymous
May 16, 2005
12:54 PM PT

Here at the biggest Ivy school, with a supposedly good spam filter, other students' email addresses are appearing in the "From" box of the almost 100 messages I've recieved, even though the students don't have anything to do with it. And all with the same xenophobic, rascist, preserve-German-blood sort of message. At first I thought they were sent to me because I'm a German Lit major...but it's worldwide! Does anyone know if it is technically possible to find out who's responsible?

L-Train
May 16, 2005
1:50 PM PT

I've gotten about 500 so far

Bob
May 16, 2005
2:39 PM PT

YEP me too. And No sprechenzie Deutsch! (Sp?)
Maybe a half dozen in the last 2 days. I don't open them, I spam them to AOL right away!

CeeBee
May 16, 2005
3:21 PM PT

I also added alot of the German words to the AOL spam filter list so hopefully fewer emails will come through. Unless they try the Viagra trick where they spell one of the words wrong..oh well.

CeeBee
May 16, 2005
3:36 PM PT

It's like Hitler has been reincarnated as annoying email.

Todd
May 16, 2005
4:49 PM PT

I saw that many of you have replied to the spam to tell them to take you off the mailing list. This is not wise. These are spammers that are not afraid of the law and a reply will only worsen the situation. They will then have an email address they know is live which they can spam to their hears content.

Jason
May 16, 2005
5:20 PM PT

All of our clients who run GFI's anti spam product have been un-affected because the GFI product has the option to only accept mail written in a particular language/keyboard set.

Just thought I would toss that out there .. you can get a free trial from them to get you over the hump at least.

KiddX
May 16, 2005
5:38 PM PT

Springtime for Hitler and Germany, Winter for Polan and France....

My mdaemon server is handling these well so far, not of the domain match the source IP, so they are being dropped.

W
May 16, 2005
6:09 PM PT

It's no coincidence that the german spam is coming from the same machines that flooded us with viruses last week...

Oscar
May 16, 2005
6:14 PM PT

Not only have I been receiving them, (about 60), I am also receiving mail daemon alerts about them. Does that mean my system is affected? It is only happening in y Yahoo account.

Cathy
May 16, 2005
6:27 PM PT

Yep, getting it here. Only in my yahoo acct.
Have averaged around 20-30 a day.

KIDWRITER
May 16, 2005
6:45 PM PT

Have received a couple of thousand of them through the tmobile system. Have spent several hours setting up filters to block them to no avail. Hopefully, this too shall pass...:)

Scott
May 16, 2005
7:27 PM PT

i simply filtered all mail containing http:// NEAR .de

simple./ the chance of receiving a legitimate email with a link to a german site is pretty slim. and if it ever happens i can manually let it through.

Easy

IR
May 16, 2005
7:47 PM PT

It looks like we do need to bomb Dresden, again.

Todd
May 16, 2005
11:24 PM PT

deutschspam uber alles

Anonymous
May 17, 2005
1:11 AM PT

i was on my way to change my email address (and blame a friend for going to some random site while here on the weekend ) when i read about the worm on rogersyahoo news. really freaking frustrating.

Tracy
May 17, 2005
5:40 AM PT

Hey Todd, your a complete imbecile.

David
May 17, 2005
6:33 AM PT

hey david, you're is a contraction. meaning you are. your is a possessive pronoun. for gods sake man, i'm an accountant. don't throw stones at glass houses.

lil
May 17, 2005
8:13 AM PT

I am getting about 1 message every 5 min through my schools exchange system. It has cloged the network and is making my work on the server verry anoying.. Alot of timed out mysql querries.

Brian Hursey
May 17, 2005
9:29 AM PT

Hey lil, if you are going to correct someone's grammar, you should at least get your's right. By using the shift key, you can start your sentences with a capital letter.

On topic....about 20 since Sunday at noon.

Deception
May 17, 2005
11:04 AM PT

Since Friday or Saturday, I have received about 500 of these message each day.

Dennis
May 17, 2005
5:29 PM PT

David is a hambone.

Stacey
May 17, 2005
6:17 PM PT

Got about six of them in the past 48 hours or so. I guess I'm one of the lucky ones...

Edward
May 17, 2005
8:37 PM PT

I got probably 50 German-mails a day, for the last 4~5days. I can't understand German-language. So, I don't know what's the sender's intention.
Eric---Singapore.

Eric
May 18, 2005
12:43 AM PT

Deception,

"Hey lil, if you are going to correct someone's grammar, you should at least get your's right."

That was a joke, right?

Anonymous
May 18, 2005
2:18 AM PT

Hey lil, is saying that you are an accountant and correcting my grammer suppose to excuse you from being a racist and hostile to foreigners?. To say something like "We need to bomb Dresden again" is pretty low and is kind of like saying "We need to crash a couple more jets into NY" seriously (man!), these kind sayings show no character at all . Hey Stacey are you an accountant to?
Gruß aus Deutschland (for everyone who can't read German "Greetings from Germany")

David
May 18, 2005
3:02 AM PT

I'm averaging almost 3,000 a day. It doesn't start until after 7am and is over by 4pm (central time).

Robin
May 18, 2005
4:19 AM PT

Thanks to Dulantha Peiris for:http://mailscanner.prolocation.net/german.cf
I copied the subjects into my rules in Outlook 2000 and no more German Spam ! I also sent the link to my isp (frontiernet) and they are going to add the list to their mailserver so none of their clients get the unwanted mail

Steve Blakely
May 18, 2005
8:39 AM PT

Totally, I get at least 300 daily, over several e-mail addresses on different domains.

Ryan
May 18, 2005
8:46 AM PT

Someone tell these damn nazis to leave us alone!!

Anonymous
May 18, 2005
9:26 AM PT

OK, it is clear everybody is getting this spam (Sober virus) but how do we block them? I use Outlook Express. I've spoken with a teir 2 tech at Yahoo and his suggections did nothing. I have ran the "Sober virus" from Norton Antivirus update several times and that didn't do the trick.

So, let's hear from all you "Computer Guru's" on how to end the misery.......and may God bless you

Steven
May 18, 2005
1:51 PM PT

OK...now I am at 15 and I just keep going to AOL block and type in each German word. But I don't know how effective it is. Everyday I get one or two more, with new words.

CeeBee
May 18, 2005
3:25 PM PT

I've received 90 today alone!

Gemma
May 19, 2005
5:53 AM PT

Instructions for blocking this in Outlook Express:
1. Download the list of subject headings from:
http://mailscanner.prolocation.net/german.cf
2. Open Outlook Express and click on "Tools", then on "Message Rules", and "Mail". A box will open for creation/modification of message rules. Click "New". In the top box check "Where the subject contains specific words", and in the second box check "Do not Download it from the server". Click on the highlighted link "contains specific words" in the third box, and a new box opens. Copy and paste each of the subject headers previously downloaded into the appropriate field, and click "Add" after you paste each one. When all have been included, click "Okay", and then again "Okay". That's you done... no more spam (not with these subject headers, anyway).

Robin M
May 19, 2005
1:24 PM PT

How do you block all these german emails through Microsoft Office Outlook. It has totally taken over my work email and several others. PLEASE HELP!!

Kelly C
May 19, 2005
1:40 PM PT

For Outlook - similar process to Outlook Express. On the "Tools" menu select "Rules Wizard". Click "New". Highlight "Check messages when they arrive" and click "Next". Check "with specific words in the subject" and click the "Specific words" link in the lower box. Go through the process of adding each header - except you will have to type it in (Outlook doesn't allow pasting).Click "Okay" and "Next". Check "permanently delete it" and click "Finish". Voila.

Robin M
May 19, 2005
2:29 PM PT

If you can copy it (ctrl+c) or right click>copy and no right click>paste just use ctrl+v to paste it when adding the subjects in Outlook.

DMS
May 21, 2005
7:30 AM PT

Germans pis me of anyway, never mind having to see their language in use in my clents mailboxes, proper pissin me off. cus of the same senario in that they are all different theres no direct way of stopping em. I use GFI Mailessentials which is a killer spamkiller (inlike the wack mcafee released one) - it does everything but block the germans.

Someone find the culprits.

James Hawthornthwaite
May 25, 2005
9:10 AM PT

wes (http://wab.co.za) actually wants your spam!!

anonymoose
May 25, 2005
12:59 PM PT

Hmm, since I rarely use email and few people know my gmail address I have never received spam at my gmail account, but my old Yahoo account is probably full of it. At least it blocks spam accurately.

Ib
June 06, 2005
2:10 PM PT

drug zyban order zyban online http://bazaranet.iranseek.com/zyban/zyban_indicaciones.html zyban snort zyban sr tablets http://bazaranet.iranseek.com/zyban/anti_drug_smoking_zyban.html and .... web site zyban zyban prices http://bazaranet.iranseek.com/zyban/zyban_helping_quit_smoking.html zyban ban uk zyban prescription http://bazaranet.iranseek.com/zyban/generic_zyban.html buy canada zyban by canada in mail zyban http://bazaranet.iranseek.com/zyban/quitting_smoking_zyban.html .Thanks.

bupropion hcl zyban
October 13, 2005
4:06 AM PT

yes.this is my site http://shumaher.hollyvalance.tk/carisoprodol/carisoprodol_discription_and_image.html Thanks.

soma carisoprodol online
December 13, 2005
10:44 PM PT

yes.this is my site http://shumaher.hollyvalance.tk/carisoprodol/carisoprodol_c_o_d_.html Thanks.

carisoprodol online pharmacy
December 14, 2005
12:35 AM PT

phentermine http://home.tiscali.cz:8080/phenterminecool/ ; Thanks!

phentermine
February 28, 2006
10:12 PM PT

Hello! Great blog! if you have an interest I can welcome you to my page! low rate credit card http://low-rate-credit-card.buy-cheap-pharmacy.com/low-rate-credit-card Respect to author! You are real genius!

low rate credit card
March 25, 2006
5:18 AM PT
Post a comment Post a comment
Archives
View posts from:
 

PC World's Marketplace

PC World's Free Whitepapers

Visit other IDG sites: