Hi,
I tried the phishing test with my email gateway, the phishing email successfully pass all spam check and delivered to user. It can fake the sender even spf required.
Here is the log, can anybody have experience on?
I tried the phishing test with my email gateway, the phishing email successfully pass all spam check and delivered to user. It can fake the sender even spf required.
Here is the log, can anybody have experience on?
Code:
Mar 23 13:10:50 smgw2 postfix/postscreen[2270866]: CONNECT from [23.21.109.197]:43534 to [192.168.110.202]:25
Mar 23 13:10:50 smgw2 postfix/postscreen[2270866]: CONNECT from [23.21.109.197]:5016 to [192.168.110.202]:25
Mar 23 13:10:56 smgw2 postfix/postscreen[2270866]: PASS NEW [23.21.109.197]:43534
Mar 23 13:10:56 smgw2 postfix/postscreen[2270866]: PASS OLD [23.21.109.197]:5016
Mar 23 13:10:56 smgw2 postfix/smtpd[2329615]: connect from psm.knowbe4.com[23.21.109.197]
Mar 23 13:10:56 smgw2 postfix/smtpd[2329616]: connect from psm.knowbe4.com[23.21.109.197]
Mar 23 13:10:57 smgw2 postfix/smtpd[2329615]: 05378380C12: client=psm.knowbe4.com[23.21.109.197]
Mar 23 13:10:57 smgw2 postfix/smtpd[2329616]: 2FA4D380C5A: client=psm.knowbe4.com[23.21.109.197]
Mar 23 13:10:57 smgw2 postfix/cleanup[2327590]: 2FA4D380C5A: message-id=<4a6ff2ed.4aca7f0c@psm.knowbe4.com>
Mar 23 13:10:57 smgw2 postfix/qmgr[1057]: 2FA4D380C5A: from=<4a6ff2ed.4aca7f0c@psm.knowbe4.com>, size=6730, nrcpt=1 (queue active)
Mar 23 13:10:57 smgw2 pmg-smtp-filter[2329457]: 380CE2623D6B01A9D32: new mail message-id=<4a6ff2ed.4aca7f0c@psm.knowbe4.com>#012
Mar 23 13:10:57 smgw2 pmg-smtp-filter[2329457]: 380CE2623D6B01A9D32: Subject: Change Your Microsoft 365 Password Immediately
Mar 23 13:10:57 smgw2 pmg-smtp-filter[2329457]: 380CE2623D6B01A9D32: From: IT <IT@thecompanypizza.com>
Mar 23 13:10:59 smgw2 postfix/smtpd[2329641]: 03158380CEC: client=localhost.localdomain[127.0.0.1], orig_client=psm.knowbe4.com[23.21.109.197]
Mar 23 13:10:59 smgw2 pmg-smtp-filter[2329457]: 380CE2623D6B01A9D32: SA score=1/5 time=1.435 bayes=0.00 autolearn=no autolearn_force=no hits=BAYES_00(-1.9),HEADER_FROM_DIFFERENT_DOMAINS(0.25),HTML_MESSAGE(0.001),HTML_MIME_NO_HTML_TAG(0.377),KAM_DMARC_STATUS(0.01),KAM_REALLYHUGEIMGSRC(0.5),MIME_HTML_ONLY(0.1),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001),TO_NO_BRKTS_HTML_ONLY(1.999),T_SCC_BODY_TEXT_LINE(-0.01),URIBL_BLOCKED(0.001)
Mar 23 13:10:59 smgw2 postfix/smtpd[2329016]: 2ABEF380CD8: client=localhost.localdomain[127.0.0.1], orig_client=psm.knowbe4.com[23.21.109.197]
Mar 23 13:10:59 smgw2 postfix/cleanup[2328613]: 2ABEF380CD8: message-id=<4a6ff2ed.4aca7f0c@psm.knowbe4.com>
Mar 23 13:10:59 smgw2 postfix/qmgr[1057]: 2ABEF380CD8: from=<4a6ff2ed.4aca7f0c@psm.knowbe4.com>, size=7959, nrcpt=1 (queue active)
Mar 23 13:10:59 smgw2 pmg-smtp-filter[2329457]: 380CE2623D6B01A9D32: accept mail to <testuser@thecompanypizza.com> (2ABEF380CD8) (rule: default-accept)
Mar 23 13:10:59 smgw2 pmg-smtp-filter[2329457]: 380CE2623D6B01A9D32: processing time: 1.483 seconds (1.435, 0.029, 0)
Mar 23 13:10:59 smgw2 postfix/lmtp[2326075]: 2FA4D380C5A: to=<testuser@thecompanypizza.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=2.5, delays=1/0/0/1.5, dsn=2.5.0, status=sent (250 2.5.0 OK (380CE2623D6B01A9D32))
Mar 23 13:10:59 smgw2 postfix/qmgr[1057]: 2FA4D380C5A: removed
Mar 23 13:10:59 smgw2 postfix/smtp[2329224]: 2ABEF380CD8: to=<testuser@thecompanypizza.com>, relay=192.168.110.27[192.168.110.27]:25, delay=0.04, delays=0/0/0/0.03, dsn=2.0.0, status=sent (250 Message accepted for delivery)
Mar 23 13:10:59 smgw2 postfix/qmgr[1057]: 2ABEF380CD8: removed
Mar 23 13:16:49 smgw2 postfix/smtpd[2329615]: disconnect from psm.knowbe4.com[23.21.109.197] ehlo=1 mail=1 rcpt=1 data=1 rset=5 quit=1 commands=10
Mar 23 13:16:50 smgw2 postfix/smtpd[2329616]: disconnect from psm.knowbe4.com[23.21.109.197] ehlo=1 mail=1 rcpt=1 data=1 rset=5 quit=1 commands=10