[SOLVED] proxmox let in phishing mail

vusald

New Member
Apr 16, 2023
18
1
3
My colleague just received this mail



1694008476810.png



This is the mail log



Code:
Sep 6 04:54:40 mail postfix/smtpd[385982]: connect from server.colibertum.kozow.com[188.166.246.78]

Sep 6 04:54:41 mail postfix/smtpd[385982]: Anonymous TLS connection established from server.colibertum.kozow.com[188.166.246.78]: TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256

Sep 6 04:54:41 mail postfix/smtpd[385982]: 92ED32A137F: client=server.colibertum.kozow.com[188.166.246.78]

Sep 6 04:54:41 mail postfix/cleanup[385985]: 92ED32A137F: message-id=<0cd43abcad92d4da7f27b2edfb37cffa@colibertum.kozow.com>

Sep 6 04:54:42 mail postfix/qmgr[219055]: 92ED32A137F: from=<admin@colibertum.kozow.com>, size=23843, nrcpt=1 (queue active)

Sep 6 04:54:42 mail postfix/smtpd[385982]: disconnect from server.colibertum.kozow.com[188.166.246.78] ehlo=2 starttls=1 mail=1 rcpt=1 data=1 quit=1 commands=7

Sep 6 04:54:42 mail pmg-smtp-filter[385819]: 2A13A264F7CDD212002: new mail message-id=<0cd43abcad92d4da7f27b2edfb37cffa@colibertum.kozow.com>#012

Sep 6 04:54:47 mail pmg-smtp-filter[385819]: 2A13A264F7CDD212002: SA score=0/5 time=5.338 bayes=undefined autolearn=ham autolearn_force=no hits=DKIM_SIGNED(0.1),DKIM_VALID(-0.1),DKIM_VALID_AU(-0.1),HTML_IMAGE_RATIO_06(0.001),HTML_MESSAGE(0.001),KAM_DISCORDCDN(4.5),RCVD_IN_DNSWL_HI(-5),SPF_HELO_NONE(0.001),SPF_PASS(-0.001),T_SCC_BODY_TEXT_LINE(-0.01),URIBL_BLOCKED(0.001)

Sep 6 04:54:47 mail pmg-smtp-filter[385819]: 2A13A264F7CDD212002: adding disclaimer failed (rule: Add Disclaimer)

Sep 6 04:54:47 mail pmg-smtp-filter[385819]: 2A13A264F7CDD212002: added disclaimer (rule: Add Disclaimer)

Sep 6 04:54:47 mail postfix/smtpd[385991]: connect from localhost.localdomain[127.0.0.1]

Sep 6 04:54:47 mail postfix/smtpd[385991]: 7B8DB2A13A8: client=localhost.localdomain[127.0.0.1], orig_client=server.colibertum.kozow.com[188.166.246.78]

Sep 6 04:54:47 mail postfix/cleanup[385985]: 7B8DB2A13A8: message-id=<0cd43abcad92d4da7f27b2edfb37cffa@colibertum.kozow.com>

Sep 6 04:54:47 mail postfix/qmgr[219055]: 7B8DB2A13A8: from=<admin@colibertum.kozow.com>, size=25869, nrcpt=1 (queue active)

Sep 6 04:54:47 mail postfix/smtpd[385991]: disconnect from localhost.localdomain[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5

Sep 6 04:54:47 mail pmg-smtp-filter[385819]: 2A13A264F7CDD212002: accept mail to <mailbox@domain.tld> (7B8DB2A13A8) (rule: default-accept)

Sep 6 04:54:47 mail pmg-smtp-filter[385819]: 2A13A264F7CDD212002: processing time: 5.437 seconds (5.338, 0.059, 0)

Sep 6 04:54:47 mail postfix/lmtp[385986]: 92ED32A137F: to=<mailbox@domain.tld>, relay=127.0.0.1[127.0.0.1]:10024, delay=6, delays=0.58/0.02/0/5.4, dsn=2.5.0, status=sent (250 2.5.0 OK (2A13A264F7CDD212002))

Sep 6 04:54:47 mail postfix/qmgr[219055]: 92ED32A137F: removed

Sep 6 04:54:47 mail postfix/smtp[385992]: Untrusted TLS connection established to 10.22.10.26[10.22.10.26]:25: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)

Sep 6 04:54:47 mail postfix/smtp[385992]: 7B8DB2A13A8: to=<mailbox@domain.tld>, relay=10.22.10.26[10.22.10.26]:25, delay=0.16, delays=0.01/0.02/0.02/0.11, dsn=2.6.0, status=sent (250 2.6.0 <0cd43abcad92d4da7f27b2edfb37cffa@colibertum.kozow.com> [InternalId=15646565859338, Hostname=EXCH01.exchange.local] 27228 bytes in 0.102, 258.377 KB/sec Queued mail for delivery)

Sep 6 04:54:47 mail postfix/qmgr[219055]: 7B8DB2A13A8: removed





As you can see
Code:
SA score=0/5
..Why proxmox considered it as NOT SPAM
 

Attachments

  • 1694008476810.png
    1694008476810.png
    27.5 KB · Views: 21
Last edited:
Sep 6 04:54:47 mail pmg-smtp-filter[385819]: 2A13A264F7CDD212002: SA score=0/5 time=5.338 bayes=undefined autolearn=ham autolearn_force=no hits=DKIM_SIGNED(0.1),DKIM_VALID(-0.1),DKIM_VALID_AU(-0.1),HTML_IMAGE_RATIO_06(0.001),HTML_MESSAGE(0.001),KAM_DISCORDCDN(4.5),RCVD_IN_DNSWL_HI(-5),SPF_HELO_NONE(0.001),SPF_PASS(-0.001),T_SCC_BODY_TEXT_LINE(-0.01),URIBL_BLOCKED(0.001)
The following line shows what spamassassin saw of the mail ...

the URIBL_BLOCKED part means that your PMG cannot ask uribl for the links inside the mail (something which really helps in detecting spam/phisihing)

see the recommendation in the pmg-wiki - follow the guides (and also check the linked pages) - This should improve detection:
https://pmg.proxmox.com/wiki/index.php/Getting_started_with_Proxmox_Mail_Gateway
 
  • Like
Reactions: vusald

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!