Re: Email Phishing and Zloader: Such a Disappointment

2021-07-12 Thread Matus UHLAR - fantomas
--On Sunday, July 11, 2021 4:55 PM -0400 "Kevin A. McGrail" wrote: We use the olevbmacro detection added to SA. I would guess that's blocking the payload.I would guess that's blocking the payload. On 11.07.21 13:35, Kenneth Porter wrote: I see the plugin in the distribution but it doesn't

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-12 Thread Matus UHLAR - fantomas
On 7/11/2021 5:11 PM, John Hardin wrote: "The other parts contain an application/vnd.ms-officetheme and an application/x-mso file. Which (in addition to the text/xml files) are used by Microsoft Word to load the embedded Word document." Would the presence of all three of those MIME types be

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-12 Thread Pedro David Marco
>On Monday, July 12, 2021, 04:01:03 AM GMT+2, Kevin A. McGrail wrote: >If you can get me a spample, I'm sure I can tell you but in general we >block macros so that's all that's needed.  Likely the OLEVBMacro plugin >and KAM ruleset is blocking all of these already if you have the plugin

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-12 Thread Dominic Raferd
On 12/07/2021 07:40, Dave Funk wrote: On Sun, 11 Jul 2021, Kevin A. McGrail wrote: On 7/11/2021 5:11 PM, John Hardin wrote: "The other parts contain an application/vnd.ms-officetheme and an application/x-mso file. Which (in addition to the text/xml files) are used by Microsoft Word to load

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-12 Thread Dave Funk
On Sun, 11 Jul 2021, Kevin A. McGrail wrote: On 7/11/2021 5:11 PM, John Hardin wrote: "The other parts contain an application/vnd.ms-officetheme and an application/x-mso file. Which (in addition to the text/xml files) are used by Microsoft Word to load the embedded Word document." Would the

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-11 Thread Kevin A. McGrail
On 7/11/2021 5:11 PM, John Hardin wrote: "The other parts contain an application/vnd.ms-officetheme and an application/x-mso file. Which (in addition to the text/xml files) are used by Microsoft Word to load the embedded Word document." Would the presence of all three of those MIME types be a

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-11 Thread Kevin A. McGrail
It's in the KAM ruleset if that helps.  Search "ifplugin Mail::SpamAssassin::Plugin::OLEVBMacro" and you'll see the set of rules we use.  Add the plugin to an appropriate pre file to activate it. On 7/11/2021 4:35 PM, Kenneth Porter wrote: I see the plugin in the distribution but it doesn't

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-11 Thread John Hardin
On Sun, 11 Jul 2021, Kenneth Porter wrote: --On Sunday, July 11, 2021 1:20 PM -0400 Jared Hall wrote: The Word document (without macros) loads an external encrypted Excel file It has macros. It tricks the user into enabling and running them by telling him to enable the document for

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-11 Thread Kenneth Porter
--On Sunday, July 11, 2021 4:55 PM -0400 "Kevin A. McGrail" wrote: We use the olevbmacro detection added to SA. I would guess that's blocking the payload.I would guess that's blocking the payload. I see the plugin in the distribution but it doesn't appear to be loaded by default and the

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-11 Thread Kevin A. McGrail
We use the olevbmacro detection added to SA. I would guess that's blocking the payload.I would guess that's blocking the payload. On Sun, Jul 11, 2021, 15:00 Kenneth Porter wrote: > --On Sunday, July 11, 2021 1:20 PM -0400 Jared Hall > wrote: > > > The Word document (without macros) loads an

Re: Email Phishing and Zloader: Such a Disappointment

2021-07-11 Thread Kenneth Porter
--On Sunday, July 11, 2021 1:20 PM -0400 Jared Hall wrote: The Word document (without macros) loads an external encrypted Excel file It has macros. It tricks the user into enabling and running them by telling him to enable the document for editing and enabling "content" (ie. macros).

Email Phishing and Zloader: Such a Disappointment

2021-07-11 Thread Jared Hall
Reference: My reply to KAM's post: "Looking for a sample of the Microsoft zero day print nightmare" To continue my rant about the disconnect with the Security community, this ThreatPost article pops up on my Google feed "Microsoft Office Users Warned on New Malware-Protection Bypass".  I