Re: Catching well directed spear phishing messages

2016-06-27 Thread Raymond Dijkxhoorn
Hai! I dont understand why they would match your spf record either. Are they sended out by a IP adres you 'approved' ?? Thanks, Raymond Dijkxhoorn > Op 28 jun. 2016 om 03:27 heeft jdebert het volgende > geschreven: > > On Mon, 27 Jun 2016 18:41:04 +0530 > Ram wrote: > >> I am seeing messag

Re: Catching well directed spear phishing messages

2016-06-27 Thread jdebert
On Mon, 27 Jun 2016 18:41:04 +0530 Ram wrote: > I am seeing messages that appear to come from the MD or the CEO of > the company to the accounts department asking people to transfer > money to some fake account > > These messages were initially few and I ignored. But now this has > become a prob

Re: Protected Sky?

2016-06-27 Thread Vincent Fox
On 06/27/2016 01:15 PM, Reindl Harald wrote: Am 27.06.2016 um 21:27 schrieb Vincent Fox: I saw a reference today in my MxToolbox report, to an RBL named Protected Sky which had like double the listing activity of Spamhaus. Does anyone know anything about this outfit? that's a bullshit RBL w

Re: Protected Sky?

2016-06-27 Thread Reindl Harald
Am 27.06.2016 um 21:27 schrieb Vincent Fox: I saw a reference today in my MxToolbox report, to an RBL named Protected Sky which had like double the listing activity of Spamhaus. Does anyone know anything about this outfit? that's a bullshit RBL with large amounts of FP's We primarily rely on

Re: Catching well directed spear phishing messages

2016-06-27 Thread Sidney Markowitz
Ram wrote on 28/06/16 3:10 AM: > > Here is the sample > > > I just redacted the actual recpient email id and name > > > Return-Path: This isn't a SpamAssassin problem, but it is a problem that you can use SpamAssassin as a tool to help solve. If your company's accounting department can send

Protected Sky?

2016-06-27 Thread Vincent Fox
Hello, I saw a reference today in my MxToolbox report, to an RBL named Protected Sky which had like double the listing activity of Spamhaus. Does anyone know anything about this outfit? We primarily rely on Spamhaus at present, with some others thrown in which catch some that Spamhaus doesn't.

Re: Catching well directed spear phishing messages

2016-06-27 Thread Jari Fredriksson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Ram kirjoitti 27.6.2016 16:11: > I am seeing messages that appear to come from the MD or the CEO of the > company to the accounts department asking people to transfer money to > some fake account > > These messages were initially few and I ignored. Bu

Re: Catching well directed spear phishing messages

2016-06-27 Thread John Hardin
On Mon, 27 Jun 2016, Reindl Harald wrote: > Am 27.06.2016 um 15:11 schrieb Ram: > > I am seeing messages that appear to come from the MD or the CEO of the > > company to the accounts department asking people to transfer money to > > some fake account > > > These messages have different env

Re: Catching well directed spear phishing messages

2016-06-27 Thread Alex
Hi, >>> These messages have different envelope ids so SPF checks always pass. >>> The header from is properly formatted exactly how it will be in a normal >>> mail >>> >>> What measures do you take for such spear phishing - look for little anomalies that are unique to these messages and somethin

Re: Catching well directed spear phishing messages

2016-06-27 Thread Reindl Harald
Am 27.06.2016 um 17:10 schrieb Ram: On Monday 27 June 2016 06:50 PM, Reindl Harald wrote: Am 27.06.2016 um 15:11 schrieb Ram: I am seeing messages that appear to come from the MD or the CEO of the company to the accounts department asking people to transfer money to some fake account happ

Re: Catching well directed spear phishing messages

2016-06-27 Thread Ram
On Monday 27 June 2016 06:50 PM, Reindl Harald wrote: Am 27.06.2016 um 15:11 schrieb Ram: I am seeing messages that appear to come from the MD or the CEO of the company to the accounts department asking people to transfer money to some fake account happens all day long I know these are n

Re: Question regarding address_verify_map

2016-06-27 Thread Heinrich Boeder
Hi everbody, wrong mailing list! I am really sorry. I picked the wrong mailinglist folder. it likely creates it at first use @Harald: Thank you for your answer! - heinrich heinr...@heinrichboeder.com -- www.heinrichboeder.com key: 0xC15DAD56 -- 363D 5BC3 9C45 9D09 3D78 1C28 DB68 F047 C15

Re: Question regarding address_verify_map

2016-06-27 Thread Reindl Harald
Am 27.06.2016 um 15:32 schrieb Heinrich Boeder: Hi folks, I have a question regarding the command address_verify_map. I use the default setting in my postfix configuration: address_verify_map = btree:$data_directory/verify_cache The verify_cache.db was in my /var/lib/postfix/ folder and I de

Question regarding address_verify_map

2016-06-27 Thread Heinrich Boeder
Hi folks, I have a question regarding the command address_verify_map. I use the default setting in my postfix configuration: address_verify_map = btree:$data_directory/verify_cache The verify_cache.db was in my /var/lib/postfix/ folder and I deleted it to purge it (maybe not the best way to

Re: Catching well directed spear phishing messages

2016-06-27 Thread Reindl Harald
Am 27.06.2016 um 15:11 schrieb Ram: I am seeing messages that appear to come from the MD or the CEO of the company to the accounts department asking people to transfer money to some fake account happens all day long I know these are not spam messages so catching them will be out of scope fo

Catching well directed spear phishing messages

2016-06-27 Thread Ram
I am seeing messages that appear to come from the MD or the CEO of the company to the accounts department asking people to transfer money to some fake account These messages were initially few and I ignored. But now this has become a problem. I know these are not spam messages so catching them

Re: How SA reactes to a bunch of garbage characters

2016-06-27 Thread Olivier
Hi, As promissed, ehere is one week log of FuzzyOcr http://pastebin.com/XwwdXkTV The result are not too good. Olivier --