[SOLVED] Blocking mail via signer signerhash

poetry

Active Member
May 28, 2020
206
57
33
Hello,

Is it possible to block mail with this information provided. This was a request from Microsoft.

Example of what we have to block:
Bespoke Software Solutions Limited cba350fe1847a206580657758ad6813a9977c40efsigner signerhash

Thank you!
 
Pls provide the full email raw format.
It's not provided. We just got message from Microsoft with information provided above with multiple entries in CSV file.

Snippet from email:
"The Microsoft Threat Intelligence Center (MSTIC) is confidentially sharing the attached Activity Alert (AA) and CSV file of related indicators of compromise (IOCs) with Microsoft customers"...
 
I really am not sure how this information might relate to e-mail at all.

after a quick bit of googling it seems to me that the information provided by Microsoft is related to software you/someone in your organisation has installed on a windows machine, which was originally signed by Bespoke Software Solutions LImited, and that the certificate that was used for signing (belonging to Bespoke Software Solutions) was compromised at some point:
* you need to find the software signed by Bespoke Software Solutions on your Windows Endpoint (PC) and remove it since there might have been a compromise

AFAICT this has nothing to do with emails going through PMG?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!