Discussion:
[Postfixbuch-users] seltsamer Linkspam - wie abwehren
sebastian
2014-09-02 19:36:47 UTC
Permalink
Hallo & Guten Abend zusammen,

ich bekomme seit längerem "seltsamen Spam", d.h. Mails von kryptischen
Adressen mit Links zu Unterseiten von irgendwelchen Domains.

Vermutlich hat irgendwer auf den Servern der Domains einzelne Seiten
eingeschoben und schickt die Links per Mail.
Hinter den Links verbirgt sich von Trojanern bis zum Laden für blaue
Pillen alles.

Wie kann man dieses abwehren?

gruß
Sebastian

Return-Path: <stofi at inmail.sk>
Delivered-To: sebastian at meinserver.de
X-policyd-weight: using cached result; rate: -6.2
X-Greylist: delayed 349 seconds by postgrey-1.34 at meinserver.de; Tue, 02 Sep 2014 21:24:52 CEST
Received: from smtp.inmail24.com (ri2.inmail24.com [217.198.113.97])
by meinserver.de (Postfix) with ESMTPS id E5B5120B9B
for <sebastian at meinserver.de>; Tue, 2 Sep 2014 21:24:42 +0200 (CEST)
X-Amavis-Modified: Mail body modified (using disclaimer) - smtp.inmail24.com
Received: from smtp.inmail24.com ([217.198.113.94])
by localhost (smtp.inmail24.com [127.0.0.1]) (amavisd-new, port 10026)
with LMTP id ejVQh6Vt3Hni; Tue, 2 Sep 2014 21:18:56 +0200 (CEST)
Received: from xupivadi (unknown [181.67.67.60])
(Authenticated sender: stofi at inmail.sk)
by smtp.inmail24.com (Postfix) with ESMTPA id E58B610A83;
Tue, 2 Sep 2014 21:18:52 +0200 (CEST)
Message-ID: <CC41F7A4CFCF94D66D99890A3C13C834 at xupivadi>
From: "uofpussylicking" <stofi at inmail.sk>
To: <ggoyo28 at yahoo.com>
Subject:
Date: Wed, 3 Sep 2014 01:13:24 -0700
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0083_01CF2195.5082C2A0"
X-Priority: 3
X-MSMail-Priority: Normal
Importance: Normal
X-Mailer: Microsoft Windows Live Mail 16.4.3508.205
X-MimeOLE: Produced By Microsoft MimeOLE V16.4.3508.205

This is a multi-part message in MIME format.

------=_NextPart_000_0083_01CF2195.5082C2A0
Content-Type: text/plain;
charset="charset=us-ascii"
Content-Transfer-Encoding: quoted-printable

http://yakaron.com/XXXXXanimeXXXXXXX.html
----------=0D=0A
Zoner Photo Studio 16 s rozsirenim pre celu domacnost len za 39 EUR=0D=0A
=0D=0A
Najdite si strateny alebo ukradnuty telefon pomocou aplikacie Zoner AntiVir=
us Free pre Android=0D=0A
=0D=0A
Domeny .SK len za 12.29 EUR=0D=0A
=0D=0A
Skvele knihy z vydavatelstva Zoner Press=0D=0A
=0D=0A
Mam rad Android - klikni tu

------=_NextPart_000_0083_01CF2195.5082C2A0
Winfried Neessen
2014-09-03 08:05:46 UTC
Permalink
Hi,
Post by sebastian
ich bekomme seit längerem "seltsamen Spam", d.h. Mails von kryptischen
Adressen mit
Links zu Unterseiten von irgendwelchen Domains.
Hab' mal die Mail die Du angehaengt hattest durch einen meiner
Spamassassins gejagt
und dort wurde sie sofort als SPAM geflaggt.

Content analysis details: (11.5 points, 6.1 required)

pts rule name description
---- ----------------------
--------------------------------------------------
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail
provider
(stofi[at]inmail.sk)
2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL
[217.198.113.97 listed in psbl.surriel.com]
3.8 RCVD_IN_MSPIKE_L5 RBL: Very bad reputation (-5)
[217.198.113.97 listed in bl.mailspike.net]
1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see
<http://www.spamcop.net/bl.shtml?181.67.67.60>]
1.4 RCVD_IN_BRBL_LASTEXT RBL: No description available.
[217.198.113.97 listed in
bb.barracudacentral.org]
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was
blocked.
See

http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URIs: yakaron.com]
3.2 DATE_IN_FUTURE_12_24 Date: is 12 to 24 hours after Received: date
-1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1%
[score: 0.0000]
0.9 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
0.0 RCVD_IN_MSPIKE_BL Mailspike blacklisted


Ich wuerde mal sagen, das ist die einfachste Methode sowas zu blocken.


Winni
Mathias Jeschke
2014-09-03 08:11:13 UTC
Permalink
Hi Winfried,

On 09/03/2014 10:05 AM, Winfried Neessen wrote:

[...]
Post by Winfried Neessen
2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL
[217.198.113.97 listed in psbl.surriel.com]
3.8 RCVD_IN_MSPIKE_L5 RBL: Very bad reputation (-5)
[217.198.113.97 listed in bl.mailspike.net]
1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see
<http://www.spamcop.net/bl.shtml?181.67.67.60>]
1.4 RCVD_IN_BRBL_LASTEXT RBL: No description available.
[217.198.113.97 listed in
[...]
Post by Winfried Neessen
Ich wuerde mal sagen, das ist die einfachste Methode sowas zu blocken.
Nun ja, *Stunden* später irgendwelche RBLs zu fragen ist nicht das was
ich ein "reproduzierbares Ergebnis" nennen würde ;)

Mathias.

Lesen Sie weiter auf narkive:
Loading...