Phishing messages disguised to look like bounces

Patrick Ben Koetter p at sys4.de
Wed Oct 16 17:43:23 CEST 2019


If you use Postfix, catch it with the reject_multi_recipient_bounce
restriction.

p@

Am 16.10.19 um 08:21 schrieb Mika Ilmaranta:
>
> Hi,
>
> We have seen a few phishing messages go through filtering that are
> disguised to look like bounces.
>
> Envelope sender is "<>" and the messages have multiple recipients and
> From: and To: headers missing. I tried to catch them with spamassassin
> plugin only to find out that envelope sender/recipient is not
> available in spamassassin.
>
> Amavis code seems to be too much perl for me ..
>
> Any ideas?
>
> BR,
> Mika
>
-- 
[*] sys4 AG
 
https://sys4.de, +49 (89) 30 90 46 64
Schleißheimer Straße 26/MG,80333 München
 
Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263
Vorstand: Patrick Ben Koetter, Marc Schiffbauer, Wolfgang Stief
Aufsichtsratsvorsitzender: Florian Kirstein
 


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4789 bytes
Desc: S/MIME Cryptographic Signature
URL: <https://lists.amavis.org/pipermail/amavis-users/attachments/20191016/55dadeeb/attachment.bin>


More information about the amavis-users mailing list