User got this SPAM over the weekend. Countless, basically identical mails got through and we had similar cases in the past.
He has catchall email for this Domain and
How did the SPAMMERs manage to bypass PMG's checks and how can further similar incidents be avoided?
Needless to say, that the SPAMMERs Domain and the content of the emails change every time, so blacklisting them - which was of course done, yet merely after user reported - won't probably do much...
Cheers,
~R.
He has catchall email for this Domain and
X-Original-To
went to random addresses @his.Domain, while the To:
-address is on a totally unrelated Domain.How did the SPAMMERs manage to bypass PMG's checks and how can further similar incidents be avoided?
Needless to say, that the SPAMMERs Domain and the content of the emails change every time, so blacklisting them - which was of course done, yet merely after user reported - won't probably do much...
Cheers,
~R.
Return-Path: <ucxepfs@azimuters.gen.tr>
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on [ destination.host ]
X-Spam-Level:
X-Spam-Status: No, score=-3.2 required=5.0 tests=BAYES_00,HTML_FONT_SIZE_LARGE,
HTML_IMAGE_ONLY_24,HTML_IMAGE_RATIO_04,HTML_MESSAGE,PYZOR_CHECK,
RCVD_IN_DNSWL_HI,SPF_HELO_NONE,SPF_SOFTFAIL,T_SCC_BODY_TEXT_LINE,
T_TVD_MIME_EPI autolearn=ham autolearn_force=no version=3.4.2
X-Original-To: 7gbamc5fwb3gz7h@[ user domain redacted for privacy ]
Delivered-To: default@[ destination.host ]
Received: from [ pmg.host ] ([ pmg.host ] [ pmg IP ])
by [ destination.host ] (Postfix) with ESMTP id 07EA570FB0;
Mon, 20 Jun 2022 00:46:26 +0200 (CEST)
Received: from [ pmg.host ] (localhost [127.0.0.1])
by [ pmg.host ] (Proxmox) with ESMTP id 5E18D60FD3;
Sun, 19 Jun 2022 23:39:52 +0200 (CEST)
Received-SPF: pass (azimuters.gen.tr: 46.19.137.136 is authorized to use 'ucxepfs@azimuters.gen.tr' in 'mfrom' identity (mechanism 'a' matched)) receiver=[ pmg.host ]; identity=mailfrom; envelope-from="ucxepfs@azimuters.gen.tr"; helo=mail.azimuters.gen.tr; client-ip=46.19.137.136
Received-SPF: pass (azimuters.gen.tr: 46.19.137.136 is authorized to use 'ucxepfs@azimuters.gen.tr' in 'mfrom' identity (mechanism 'a' matched)) receiver=[ pmg.host ]; identity=mailfrom; envelope-from="ucxepfs@azimuters.gen.tr"; helo=mail.azimuters.gen.tr; client-ip=46.19.137.136
Received: from mail.azimuters.gen.tr (mail.azimuters.gen.tr [46.19.137.136])
by [ pmg.host ] (Proxmox) with ESMTP id EB6FE6002D;
Sun, 19 Jun 2022 23:39:50 +0200 (CEST)
Received: from azimuters.gen.tr (rel.tetarox.site [2.56.88.81])
by mail.azimuters.gen.tr (Postfix) with ESMTPA id 332CC7F19;
Sun, 19 Jun 2022 23:48:12 +0300 (EEST)
Message-ID: <53646257401831364774715016820331@azimuters.gen.tr>
From: "CARDIOXIL" <ucxepfs@azimuters.gen.tr>
To: <comercial@hipocrate2002serv.ro>
Subject: =?utf-8?B?MSBsdW7EgyBkZSBhZG1pbmlzdHJhcmUgQ2FyZGlveGlsIC0gZSBjYSDImWkgY3VtIHRlLWFpIG5hyJl0ZSBkaW4gbm91?=
Date: Sun, 19 Jun 2022 23:48:22 +0300
MIME-Version: 1.0
Content-Type: multipart/related;
type="multipart/alternative";
boundary="----=_NextPart_000_0006_01D88435.36FD4250"
This is a multi-part message in MIME format.
------=_NextPart_000_0006_01D88435.36FD4250
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0007_01D88435.36FD4250"
------=_NextPart_000_0007_01D88435.36FD4250
Content-Type: text/plain;
charset="windows-1251"
Content-Transfer-Encoding: quoted-printable
=0D=0A=0D=0A=0D=0A=0D=0ACardioxil este o comoară de extracte=
medicinale care funcționează =0D=0Aarmonios pentru a v=
ă menține vasele de sânge curate și =0D=0Afer=
me.=0D=0A =0D=0ACondiții pentru =0D=0Aachiziționarea Ca=
rdioxil în cadrul =0D=0Aprogramului:=0D=0A =0D=0AComanda5=
9;i =0D=0ACardioxil pentru uz =0D=0Apersonal.=0D=0AComandați=
un produs pentru dvs., familie =0D=0Asau prieteni. Nu avem de-a=20=
face cu intermediari care caută să cumpere loturi de =0D=
=0ACardioxil pentru revânzare =0D=0Aulterioară la un pr=
eț mai ridicat.=0D=0APlasați comanda =0D=0Aprin formula=
rul oficial de program.=0D=0AFormularul =0D=0Aoficial de comand&#=
259; garantează prețul producătorului și v=
59; protejează de =0D=0Aintermediari.=0D=0A =0D=0AReducerea=20=
=0D=0A-50% se va termina în >>>=0D=0A =0D=0A318 =0D=
=0ARON 159 =0D=0ARON=0D=0A =0D=0A=0D=0A
------=_NextPart_000_0007_01D88435.36FD4250
Content-Type: text/html;
charset="windows-1251"
Content-Transfer-Encoding: quoted-printable
<HTML><HEAD>=0D=0A<META http-equiv=3D"Content-Type" content=3D"te=
xt/html; charset=3Dwindows-1251">=0D=0A</HEAD>=0D=0A<BODY bgColor=
=3D#ffffff>=0D=0A<DIV align=3Dcenter><FONT color=3D#ff0080 size=3D=
4 face=3DArial><STRONG><FONT =0D=0Asize=3D6>Cardioxil</FONT> este=
o comoară de extracte medicinale care funcționează=
; =0D=0Aarmonios pentru a vă menține vasele de sân=
ge curate și =0D=0Aferme.</STRONG></FONT></DIV>=0D=0A<DIV al=
ign=3Dcenter><FONT size=3D4></FONT> </DIV>=0D=0A<DIV align=3D=
center><FONT color=3D#800000 size=3D4 face=3DArial><STRONG>Condi&=
#539;ii pentru =0D=0Aachiziționarea <FONT color=3D#ff0080>Ca=
rdioxil</FONT> în cadrul =0D=0Aprogramului:</STRONG></FONT><=
/DIV>=0D=0A<DIV align=3Dcenter><FONT size=3D4></FONT> </DIV>=
=0D=0A<DIV align=3Dcenter><FONT size=3D4 face=3DArial><FONT color=
=3D#008000>Comandați</FONT> =0D=0A<STRONG><FONT color=3D#ff0=
080>Cardioxil</FONT></STRONG> pentru uz =0D=0Apersonal.<BR><FONT=20=
color=3D#008000>Comandați</FONT> un produs pentru dvs., fami=
lie =0D=0Asau prieteni. Nu avem de-a face cu intermediari care ca=
ută să cumpere loturi de =0D=0A<FONT color=3D#ff0080><S=
TRONG>Cardioxil</STRONG></FONT> pentru revânzare =0D=0Aulter=
ioară la un preț mai ridicat.<BR><FONT color=3D#008000>=
Plasați</FONT> comanda =0D=0Aprin formularul oficial de prog=
ram.<BR><FONT color=3D#008000>Formularul</FONT> =0D=0Aoficial de=20=
comandă garantează prețul producătorului 5=
7;i vă protejează de =0D=0Aintermediari.</FONT></DIV>=0D=
=0A<DIV align=3Dcenter><FONT size=3D4></FONT> </DIV>=0D=0A<D=
IV align=3Dcenter><FONT color=3D#0000ff size=3D4 face=3DArial><A=20=
=0D=0Ahref=3D"https://golistoenser.free.hr/macapnd2/"><STRONG>Red=
ucerea =0D=0A-50% se va termina în >>></STRONG></A>=
</FONT></DIV>=0D=0A<DIV align=3Dcenter><FONT size=3D4></FONT>&nbs=
p;</DIV>=0D=0A<DIV align=3Dcenter><FONT size=3D4 face=3DArial><ST=
RIKE><FONT color=3D#008000>318 =0D=0ARON</FONT></STRIKE> <STRONG>=
<FONT color=3D#ff0000>159 =0D=0ARON</FONT></STRONG></FONT></DIV>=0D=
=0A<DIV align=3Dcenter><FONT size=3D4 face=3DArial></FONT> <=
/DIV>=0D=0A<DIV align=3Dcenter><A =0D=0Ahref=3D"https://golistoen=
ser.free.hr/macapnd3/"><IMG border=3D0 hspace=3D0 alt=3D"" src=3D=
"cid:1000e01d88987987774d0fc824a69@ucxepfs" width=3D480 height=3D=
345></A></DIV></BODY></HTML>=0D=0A
------=_NextPart_000_0007_01D88435.36FD4250--
------=_NextPart_000_0006_01D88435.36FD4250
Content-Type: image/jpeg;
name="wfoiuqwwjkimix.jpeg"
Content-Transfer-Encoding: base64
Content-ID: <12d7e01d8843770fa774d0fc824a69@ucxepfs>
[ removed ]
------=_NextPart_000_0006_01D88435.36FD4250--
bOLmEzC0rJWlKSkpT
lsMsGjRo1qol+DRo0aIINGjRogg0aNGiCDRo0aIINGjRogj/2Q==
------=_NextPart_000_0006_01D88435.36FD4250--