Can't get enough of those EvilNumbers...

2021-07-12 Thread Jared Hall
Turns out I ordered Norton for like a gazillion machines.  Add this number, +1(867)768-0009, to the list thusly: Services Activated Successfully. Order Details:- 0rder Date:   July 12, 2021 Product :   Norton Amount :   

Re: Email Phishing and Zloader: Redux

2021-07-12 Thread Jared Hall
1) Kenneth:  Uncomment the line in v343.  Rules in the present KAM.cf are thusly: ifplugin Mail::SpamAssassin::Plugin::OLEVBMacro   # increase number of mime parts checked   olemacro_num_mime 10   if (version >= 3.0040005)     body KAM_OLEMACRO eval:check_olemacro()     describe

Re: SPAM scanned twice

2021-07-12 Thread Joe Acquisto-j4
I just forgot how email works, it seems. It just now struck me it is not be rescanned at all, but merely has the information posted again, so it appears as part of the "new message"? I thought it odd the SPAM scores were identical. That should have been the first clue x four. But, no . . .

Re: Process of domain submission for inclusion in 60_whitelist_auth.cf

2021-07-12 Thread Bill Cole
On 2021-07-12 at 14:38:43 UTC-0400 (Mon, 12 Jul 2021 20:38:43 +0200) Robert Harnischmacher is rumored to have said: > Hi Bill, > > thanks for the detailed explanations. I understand the purpose of the > def_whitelist_auth list better now, but wonder if its benefit is not > overcompensated by

Re: Process of domain submission for inclusion in 60_whitelist_auth.cf

2021-07-12 Thread Robert Harnischmacher
Hi Bill, thanks for the detailed explanations. I understand the purpose of the def_whitelist_auth list better now, but wonder if its benefit is not overcompensated by significant negative effects, certainly not desired by the community. First of all, I would like to contribute some

Re: SPAM scanned twice

2021-07-12 Thread Antony Stone
On Monday 12 July 2021 at 20:07:16, Joe Acquisto-j4 wrote: > SpamAssassin 3.4.5 (2021-03-20) on Suse Leap 15.2 (their distro IIRC) > > Noticed that mail marked as SPAM was scanned again by SA after it had been > "disposed" as an attachment. > > I uncommented "report_safe 0" and did a restart

SPAM scanned twice

2021-07-12 Thread Joe Acquisto-j4
SpamAssassin 3.4.5 (2021-03-20) on Suse Leap 15.2 (their distro IIRC) Noticed that mail marked as SPAM was scanned again by SA after it had been "disposed" as an attachment. I uncommented "report_safe 0" and did a restart of SA. Next SPAM came through as a normal email, still marked as SPAM

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-12 Thread Matus UHLAR - fantomas
--On Sunday, July 11, 2021 4:55 PM -0400 "Kevin A. McGrail" wrote: We use the olevbmacro detection added to SA. I would guess that's blocking the payload.I would guess that's blocking the payload. On 11.07.21 13:35, Kenneth Porter wrote: I see the plugin in the distribution but it doesn't

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-12 Thread Matus UHLAR - fantomas
On 7/11/2021 5:11 PM, John Hardin wrote: "The other parts contain an application/vnd.ms-officetheme and an application/x-mso file. Which (in addition to the text/xml files) are used by Microsoft Word to load the embedded Word document." Would the presence of all three of those MIME types be

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-12 Thread Pedro David Marco
>On Monday, July 12, 2021, 04:01:03 AM GMT+2, Kevin A. McGrail wrote: >If you can get me a spample, I'm sure I can tell you but in general we >block macros so that's all that's needed.  Likely the OLEVBMacro plugin >and KAM ruleset is blocking all of these already if you have the plugin

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-12 Thread Dominic Raferd
On 12/07/2021 07:40, Dave Funk wrote: On Sun, 11 Jul 2021, Kevin A. McGrail wrote: On 7/11/2021 5:11 PM, John Hardin wrote: "The other parts contain an application/vnd.ms-officetheme and an application/x-mso file. Which (in addition to the text/xml files) are used by Microsoft Word to load

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-12 Thread Dave Funk
On Sun, 11 Jul 2021, Kevin A. McGrail wrote: On 7/11/2021 5:11 PM, John Hardin wrote: "The other parts contain an application/vnd.ms-officetheme and an application/x-mso file. Which (in addition to the text/xml files) are used by Microsoft Word to load the embedded Word document." Would the