Filter Files in Blank Plain Text MessageI've got a strange issue with my file filter.  I've been getting a lot of blank message body spam over the past two days that have an attachement that meets an at*.png filter that I have created.  When testing, if I send a message with one of the attachments, it is blocked (as it should be).  But for some reason, it does not seem to catch them if the message is sent in plain text.<br/><br/>Can you think of any reason why this would happen?  Further, is there any way to block blank message body spam that is sent in plain text?  I've seen a few threads talking about it, but no real definitive answer.<br/><br/>I appreciate any thoughts anyone can provide.  <br/><br/>Thank you!<br/><br/>© 2009 Microsoft Corporation. All rights reserved.Tue, 12 May 2009 13:21:44 Z4cda6fff-b9c2-436f-a4d6-a707eee53eeahttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/4cda6fff-b9c2-436f-a4d6-a707eee53eea#4cda6fff-b9c2-436f-a4d6-a707eee53eeahttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/4cda6fff-b9c2-436f-a4d6-a707eee53eea#4cda6fff-b9c2-436f-a4d6-a707eee53eeaMacros_1http://social.technet.microsoft.com/Profile/en-US/?user=Macros_1Filter Files in Blank Plain Text MessageI've got a strange issue with my file filter.  I've been getting a lot of blank message body spam over the past two days that have an attachement that meets an at*.png filter that I have created.  When testing, if I send a message with one of the attachments, it is blocked (as it should be).  But for some reason, it does not seem to catch them if the message is sent in plain text.<br/><br/>Can you think of any reason why this would happen?  Further, is there any way to block blank message body spam that is sent in plain text?  I've seen a few threads talking about it, but no real definitive answer.<br/><br/>I appreciate any thoughts anyone can provide.  <br/><br/>Thank you!<br/><br/>Wed, 06 May 2009 12:14:06 Z2009-05-06T12:14:06Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/4cda6fff-b9c2-436f-a4d6-a707eee53eea#95eaea0e-6c32-4af2-a7a1-41fed9ea15a2http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/4cda6fff-b9c2-436f-a4d6-a707eee53eea#95eaea0e-6c32-4af2-a7a1-41fed9ea15a2Alex Gray - MSFThttp://social.technet.microsoft.com/Profile/en-US/?user=Alex%20Gray%20-%20MSFTFilter Files in Blank Plain Text MessageHi,<br/><br/>I would recommend that, during a quite period for the server, you repeat your tests but with the additional realtime diagnostics enabled and the before/after achiving enabled. This will tell Antigen to write additional data to the programlog.txt file and also place a copy of every message before and after scan within the archive folder. PLEASE DISABLE BOTH OF THESE IMMEDIATELY AFTER YOUR EMAILS HAVE PASSED THROUGH, as both of these option can quickly use your hard disk space. <br/><br/>The additional realtime diagnostics will log every action that antigen performs on a message and the subsequent return code. It is then usually a case of comparing the differences between the successful test and the unsuccesful test. The same with the archived messages. If you see any differences and would like help in explaining these, please post your findings here and I will try to help you. I would also recommend that you make a note of the time/date, sender, recipient, and that you make sure that the subject line is populated with something that will allow you to find the relevent entries within the programlog as this will help you with your troubleshooting.<br/><br/>I hope this helps<br/>AlexWed, 06 May 2009 16:37:50 Z2009-05-06T16:37:50Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/4cda6fff-b9c2-436f-a4d6-a707eee53eea#25dd3e62-aad9-4c8b-9830-43e7065710cehttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/4cda6fff-b9c2-436f-a4d6-a707eee53eea#25dd3e62-aad9-4c8b-9830-43e7065710ceMacros_1http://social.technet.microsoft.com/Profile/en-US/?user=Macros_1Filter Files in Blank Plain Text MessageAlex,<br/><br/>Thanks for the suggestion.  I will look into it, though I can't seem to replicate the issue on my own.  My test mails get caught (both plain text and html), but the spammer messages were making it through. <br/><br/>The only good news to report is that it seems like SpamCure may be catching them now without my filter.  So the issue is resolved, but I have no way to figure out why they weren't caught in the first place.<br/><br/>Perhaps if we get another round of the same type of messages, I'll be able to try your suggestion and figure out exactly what is going wrong.<br/><br/>Thank you again!Wed, 06 May 2009 20:03:40 Z2009-05-06T20:03:40Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/4cda6fff-b9c2-436f-a4d6-a707eee53eea#92fd369a-8193-4b6b-a68c-f366a0a6944ehttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/4cda6fff-b9c2-436f-a4d6-a707eee53eea#92fd369a-8193-4b6b-a68c-f366a0a6944eAlex Gray - MSFThttp://social.technet.microsoft.com/Profile/en-US/?user=Alex%20Gray%20-%20MSFTFilter Files in Blank Plain Text MessageHi,<br/><br/>The archive function can be quite good to troubleshoot these types of issues as when the message enters exchange its format is changed and information removed which can be useful in troubleshooting.<br/><br/>AlexThu, 07 May 2009 12:04:11 Z2009-05-07T12:04:11Zhttp://social.technet.microsoft.com/Forums/en-US/Antigen/thread/4cda6fff-b9c2-436f-a4d6-a707eee53eea#b1a1c2f2-c826-40a7-afa8-e8ac27d2c730http://social.technet.microsoft.com/Forums/en-US/Antigen/thread/4cda6fff-b9c2-436f-a4d6-a707eee53eea#b1a1c2f2-c826-40a7-afa8-e8ac27d2c730Macros_1http://social.technet.microsoft.com/Profile/en-US/?user=Macros_1Filter Files in Blank Plain Text Message<p>Well, looks like the issue has returned.  The spammer changed the files to a different format (randomized name.png).  I've adjusted my filter to filter *.png&lt;=16KB.  Once again, the filter acts weird, it catches some of the messages and others it skips.  There are two strange issues, first is sometimes it doesn't even SEE the attachment on the message.  The second is, sometimes it sees the attachment and just lets it go.<br/><br/><strong>DOES NOT SEE MESSAGE ATTACHMENT<br/><br/></strong>: Begin scanning SMTP message&quot;<br/>: Begin scanning SMTP Inbound message named: Snex Mistakes That Men Make&quot;<br/>: Check allowed senders is scanning the sender address &quot;<a href="mailto:surmised@wormsercorp.com">surmised@wormsercorp.com</a>&quot; from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: Check allowed senders has finished scanning the sender address &quot;<a href="mailto:surmised@wormsercorp.com">surmised@wormsercorp.com</a>&quot; from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000) ulBypassTypes(0x00000000)&quot;<br/>: The IMS scanner is performing the AseScan test on the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder&quot;<br/>: The IMS scanner has finished the AseScan test with hResult(0x00000000)&quot;<br/>: The IMS scanner is performing the RBL test on the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS scanner has finished the RBL test with hResult(0x00000000)&quot;<br/>: The IMS Content Filter scanner is scanning the sender name &quot;Englert Brangers &quot; from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS Content Filter scanner has finished scanning the sender name from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000)&quot;<br/>: The IMS Content Filter scanner is scanning the sender address &quot;<a href="mailto:surmised@wormsercorp.com">surmised@wormsercorp.com</a>&quot; from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS Content Filter scanner has finished scanning the sender address &quot;<a href="mailto:surmised@wormsercorp.com">surmised@wormsercorp.com</a>&quot; from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000)&quot;<br/>: The IMS Content Filter scanner is scanning the subject line from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS Content Filter scanner has finished scanning the subject line from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000)&quot;<br/>: The IMS scanner detected a FileType of 33 (FOBTYPE_TEXT_PLAIN)&quot;<br/>: The IMS scanner is performing the Keyword Scanning on the file named &quot;Body of Message&quot; from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS scanner has finished the Keyword Scanning with hResult(0x00000000)&quot;<br/>: The IMS Virus scanner is scanning the file named &quot;Body of Message&quot; from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder&quot;<br/>: The IMS Virus scanner has finished scanning the file named &quot;Body of Message&quot; from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder with hResult(0x000C0100)&quot;<br/>: The IMS File Filter scanner is scanning the file named &quot;Body of Message&quot; from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS File Filter scanner has finished scanning the file named &quot;Body of Message&quot; from the message named &quot;Snex Mistakes That Men Make&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hResult(0x00000000)&quot;<br/>: Done scanning SMTP Inbound message named: Snex Mistakes That Men Make&quot;<br/><br/><strong>Here is one where it sees the attachment, but lets it through<br/><br/></strong>: Begin scanning SMTP message&quot;<br/>: Begin scanning SMTP Inbound message named: Fkertilization After 40&quot;<br/>: Check allowed senders is scanning the sender address &quot;<a href="mailto:groans@ros.si">groans@ros.si</a>&quot; from the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: Check allowed senders has finished scanning the sender address &quot;<a href="mailto:groans@ros.si">groans@ros.si</a>&quot; from the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000) ulBypassTypes(0x00000000)&quot;<br/>: The IMS scanner is performing the AseScan test on the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder&quot;<br/>: The IMS scanner has finished the AseScan test with hResult(0x00000000)&quot;<br/>: The IMS scanner is performing the RBL test on the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS scanner has finished the RBL test with hResult(0x00000000)&quot;<br/>: The IMS Content Filter scanner is scanning the sender name &quot;Salesky Rickel &quot; from the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS Content Filter scanner has finished scanning the sender name from the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000)&quot;<br/>: The IMS Content Filter scanner is scanning the sender address &quot;<a href="mailto:groans@ros.si">groans@ros.si</a>&quot; from the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS Content Filter scanner has finished scanning the sender address &quot;<a href="mailto:groans@ros.si">groans@ros.si</a>&quot; from the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000)&quot;<br/>: The IMS Content Filter scanner is scanning the subject line from the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS Content Filter scanner has finished scanning the subject line from the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000)&quot;<br/>: The IMS scanner detected a FileType of 61 (FOBTYPE_PNGFILE)&quot;<br/>: The IMS Virus scanner is scanning the file named &quot;Salesky.png&quot; from the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder&quot;<br/>: The IMS Virus scanner has finished scanning the file named &quot;Salesky.png&quot; from the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder with hResult(0x000C0100)&quot;<br/>: The IMS File Filter scanner is scanning the file named &quot;Salesky.png&quot; from the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS File Filter scanner has finished scanning the file named &quot;Salesky.png&quot; from the message named &quot;Fkertilization After 40&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hResult(0x00000000)&quot;<br/>: Done scanning SMTP Inbound message named: Fkertilization After 40&quot;<br/><br/><strong>And here is an example where it actually works<br/><br/></strong>: Message( Tantra fjor Beginners): IsInbound is checking the IP address: 10.1.1.2 in the SMTPExternalHosts list&quot;<br/>: Message( Tantra fjor Beginners): IsInbound determined message is sent by SMTP External Hosts, tagging message as &quot;inbound&quot;&quot;<br/>: Message( Tantra fjor Beginners): IsInbound is checking the IP address: 87.1.77.138 in the InternalAddress list&quot;<br/>: The Smtp Event Sink determined that the mail msg is Outbound based on the recipient's SMTP address: <a href="mailto:user@companyname.com">user@companyname.com</a>&quot;<br/>: Begin scanning SMTP message&quot;<br/>: Begin scanning SMTP Inbound message named: Tantra fjor Beginners&quot;<br/>: Check allowed senders is scanning the sender address &quot;<a href="mailto:schizogonous@nandor.com">schizogonous@nandor.com</a>&quot; from the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: Check allowed senders has finished scanning the sender address &quot;<a href="mailto:schizogonous@nandor.com">schizogonous@nandor.com</a>&quot; from the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000) ulBypassTypes(0x00000000)&quot;<br/>: The IMS scanner is performing the AseScan test on the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder&quot;<br/>: The IMS scanner has finished the AseScan test with hResult(0x00000000)&quot;<br/>: The IMS scanner is performing the RBL test on the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS scanner has finished the RBL test with hResult(0x00000000)&quot;<br/>: The IMS Content Filter scanner is scanning the sender name &quot;Liverance Segee &quot; from the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS Content Filter scanner has finished scanning the sender name from the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000)&quot;<br/>: The IMS Content Filter scanner is scanning the sender address &quot;<a href="mailto:schizogonous@nandor.com">schizogonous@nandor.com</a>&quot; from the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS Content Filter scanner has finished scanning the sender address &quot;<a href="mailto:schizogonous@nandor.com">schizogonous@nandor.com</a>&quot; from the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000)&quot;<br/>: The IMS Content Filter scanner is scanning the subject line from the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS Content Filter scanner has finished scanning the subject line from the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hr(0x00000000)&quot;<br/>: The IMS scanner detected a FileType of 61 (FOBTYPE_PNGFILE)&quot;<br/>: The IMS Virus scanner is scanning the file named &quot;Liverance.png&quot; from the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder&quot;<br/>: The IMS Virus scanner has finished scanning the file named &quot;Liverance.png&quot; from the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder with hResult(0x000C0100)&quot;<br/>: The IMS File Filter scanner is scanning the file named &quot;Liverance.png&quot; from the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine&quot;<br/>: The IMS File Filter scanner has finished scanning the file named &quot;Liverance.png&quot; from the message named &quot;Tantra fjor Beginners&quot; located in the &quot;Inbound&quot; folder using the Antigen Scan Engine with hResult(0x031C0101)&quot;<br/>: Internet scan found virus:<br/>   Folder: SMTP Messages\Inbound<br/>   Message: Tantra fjor Beginners<br/>   File: Liverance.png<br/>   Incident: FILE FILTER= LMI FILE SPAM: *.png&lt;16KB<br/>   State: Purged&quot;<br/>: The IMS scanner is attempting to delete the file named &quot;Liverance.png&quot;&quot;<br/>: Done scanning SMTP Inbound message named: Tantra fjor Beginners&quot;<br/><br/>I can tell you that I have verified that the messages that make it through are not on our whitelist and all attachments were .png with a filesize less than 15KB.  So they all should be caught, but they are unfortunately not.  I see, on average, about 4-8 of these messages make it through the filter per day. But I can't really tell when they will show up.<br/><br/>Any help, as always, is appreciated!<br/></p>Tue, 12 May 2009 13:21:44 Z2009-05-12T13:21:44Z