Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-12 Thread Ricky Boone
came across as it may have, and also for the delay in reporting (I was alerted to this yesterday afternoon). On Thu, Oct 12, 2023 at 8:48 AM Bill Cole wrote: > > On 2023-10-11 at 22:02:22 UTC-0400 (Wed, 11 Oct 2023 22:02:22 -0400) > Ricky Boone > is rumored to have said: > &

Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-11 Thread Ricky Boone
at 9:25 PM Bill Cole wrote: > > On 2023-10-11 at 16:45:15 UTC-0400 (Wed, 11 Oct 2023 16:45:15 -0400) > Ricky Boone > is rumored to have said: > > > Just a heads up, it appears that usssa[.]com has had their SendGrid > > email sending account popped, and a bad actor ha

Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-11 Thread Ricky Boone
Just a heads up, it appears that usssa[.]com has had their SendGrid email sending account popped, and a bad actor has been sending phishing emails from it. The domain is defined in 60_welcomelist_auth.cf with def_welcomelist_auth/def_whitelist_auth entries with *@*.usssa.com.

Re: DNS Help

2023-09-11 Thread Ricky Boone
Many RBLs have policies in place against open resolvers, such as Google DNS, OpenDNS, etc. You're on the right track, you need a local resolver that is configured to query directly to the authoritative DNS server. Unbound, or any local resolver, would need to be configured to use root hints to

Re: (Re-)emergence of UTF based obfuscation in phishing/spam

2023-08-30 Thread Ricky Boone
Typo, I meant to say I was on SA 3.4.6. On Wed, Aug 30, 2023, 3:22 PM Ricky Boone wrote: > Something I noticed on a set of emails that were reported to me. > > I have custom rules to look out for certain names in From:name. The > messages should have been caught by them,

(Re-)emergence of UTF based obfuscation in phishing/spam

2023-08-30 Thread Ricky Boone
Something I noticed on a set of emails that were reported to me. I have custom rules to look out for certain names in From:name. The messages should have been caught by them, however upon inspection the name was UTF-8 encoded, and included a character that doesn't seem to render, but interferes

Re: PDFinfo not returning expected producer, creator values

2022-03-04 Thread Ricky Boone
the trick, though. On Thu, Mar 3, 2022 at 1:48 AM Bill Cole < sausers-20150...@billmail.scconsult.com> wrote: > On 2022-03-02 at 17:58:50 UTC-0500 (Wed, 2 Mar 2022 17:58:50 -0500) > Ricky Boone > is rumored to have said: > > > If this is the wrong forum to report this, let m

PDFinfo not returning expected producer, creator values

2022-03-02 Thread Ricky Boone
If this is the wrong forum to report this, let me know. I'm trying to create a couple rules to identify questionable PDFs (phishing, etc.). While evaluating the debug output from spamassassin for the pdfinfo plugin, I noticed that some of the test file attributes aren't being populated

Re: Lint failing

2021-08-03 Thread Ricky Boone
want to point to the vault server. On Tue, Aug 3, 2021 at 10:27 PM Ricky Boone wrote: > Throwing this out there... It does not solve the issue(s) with being on > EL6, and it doesn't solve the issue with what may be happening with > sa-update for 3.3.x, but it may be a potential interim

Re: Lint failing

2021-08-03 Thread Ricky Boone
Throwing this out there... It does not solve the issue(s) with being on EL6, and it doesn't solve the issue with what may be happening with sa-update for 3.3.x, but it may be a potential interim solution to allow your instance SpamAssassin to be more up to date in the meantime.

Phishing campaign using email address to personalize URL

2021-02-23 Thread Ricky Boone
Seeing an interesting phishing campaign that appears to be personalizing components of the message and URL endpoints to potentially get around blacklists and other filters. Unfortunately I can't share the exact example publicly without effectively recreating the email, but here's a summary of

Re: Homoglyph spam/phishing targeting popular brands

2021-02-22 Thread Ricky Boone
On Sun, Feb 14, 2021 at 4:45 PM John Hardin wrote: > > I've added FUZZY rules for amazon, apple, microsoft, facebook, paypal and > norton to my sandbox, they are likely going to be fairly commonB. Looks like the FUZZY_PAYPAL rule may need word boundaries added to the regex. I'm seeing it catch

Re: Phishing campaign using nested Google redirect

2021-02-18 Thread Ricky Boone
On Thu, Feb 18, 2021 at 7:08 PM John Hardin wrote: > > In our case it's best to upload an entire email (all headers intact and > with as little obfuscation as possible) to something like Pastebin, then > post the URL to that here so it can be downloaded. This keeps the spample > from being

Re: Phishing campaign using nested Google redirect

2021-02-18 Thread Ricky Boone
Nice. I've copied scrubbed versions of what I've seen so far here: https://gitlab.com/-/snippets/2079108 (I can never remember if it is appropriate to include attachments to mailing lists like this). On Thu, Feb 18, 2021 at 1:13 PM Giovanni Bechis wrote: > > On 2/18/21 6:37 PM, Ricky

Phishing campaign using nested Google redirect

2021-02-18 Thread Ricky Boone
Just wanted to forward an example of an interesting URL obfuscation tactic observed yesterday.

Re: Homoglyph spam/phishing targeting popular brands

2021-02-17 Thread Ricky Boone
Yep, so far so good. Thank you again for the pointers and creating the rules so quickly. On Tue, Feb 16, 2021 at 9:06 PM John Hardin wrote: > > On Tue, 16 Feb 2021, Ricky Boone wrote: > > > On Mon, Feb 15, 2021 at 12:16 AM John Hardin wrote: > >> > >> OK, I add

Re: Homoglyph spam/phishing targeting popular brands

2021-02-16 Thread Ricky Boone
On Mon, Feb 15, 2021 at 12:16 AM John Hardin wrote: > > OK, I added FUZZY_OVERSTOCK as well, we'll see what happens. > > If they don't perform well in masscheck you can always grab them out of my > sandbox for your local rules. > > Masscheck results: > >

Re: Homoglyph spam/phishing targeting popular brands

2021-02-14 Thread Ricky Boone
On Sun, Feb 14, 2021 at 4:45 PM John Hardin wrote: > > On Sun, 14 Feb 2021, Ricky Boone wrote: > > > What are the community's thoughts on handling spam/phishing that utilize > > homoglyphs to obfuscate the brands they're targeting? Are there any > > plugins that ar

Homoglyph spam/phishing targeting popular brands

2021-02-14 Thread Ricky Boone
What are the community's thoughts on handling spam/phishing that utilize homoglyphs to obfuscate the brands they're targeting? Are there any plugins that are in development that might assist with catching these? For example, here are some phrases that I've been monitoring from reported messages:

Google Docs spam and __URI_GOOGLE_DOC

2020-10-16 Thread Ricky Boone
Good afternoon. I'm seeing an increase in spam/phishing that is utilizing Google Docs. I see a rule that seems to be intended to flag certain Google Docs related URLs, but not the ones I'm seeing. 72_active.cf:uri __URI_GOOGLE_DOC

Re: Detecting SendGrid shared IPs

2020-07-17 Thread Ricky Boone
Looks like I might have replied to Kris and not the maillist. Sorry if this shows up twice. Made a couple adjustments to the two patterns and merged them into one if anyone is interested. /^\[[^\]]+ (?:helo|rdns)=[\w\d.]+\.(?:outbound-e?mail|shared)\.sendgrid\.net / On Thu, Jul 16, 2020 at