Hello guys ,
Please take a look at that ,
Mail that arrive to my systems , with virus (detected by Eset)
But not avail on the regular mailing list ==> Tracking Center.
Does anyone can advice.
Best Regards ,
Koby Peleg Hen
Please take a look at that ,
Mail that arrive to my systems , with virus (detected by Eset)
But not avail on the regular mailing list ==> Tracking Center.
Does anyone can advice.
Best Regards ,
Koby Peleg Hen
Code:
Jan 12 14:41:14 smg01 pmg-smtp-filter[24222]: 7E31B5FFD98E37582D: virus detected: a variant of Win32/TrojanDownloader.Delf.DCX trojan (Eset) (custom)
Jan 12 14:41:15 smg01 pmg-smtp-filter[24222]: 7E31B5FFD98E37582D: SA score=8/5 time=1.098 bayes=undefined autolearn=no autolearn_force=no hits=HTML_MESSAGE(0.001),KAM_DMARC_STATUS(0.01),KAM_LAZY_DOMAIN_SECURITY(1),KHOP_HELO_FCRDNS(0.398),MISSING_HEADERS(1.207),SPF_HELO_NONE(0.001),SPF_NONE(3),URIBL_BLOCKED(3)
Jan 12 14:41:15 smg01 postfix/smtpd[24106]: connect from localhost[127.0.0.1]
Jan 12 14:41:15 smg01 postfix/smtpd[24106]: 6E9E51FED8: client=localhost[127.0.0.1]
Jan 12 14:41:15 smg01 postfix/cleanup[24107]: 6E9E51FED8: message-id=<20210112124115.6E9E51FED8@smg01.localdomain>
Jan 12 14:41:15 smg01 postfix/qmgr[21050]: 6E9E51FED8: from=<postmaster@smg01.localdomain>, size=1688, nrcpt=1 (queue active)
Jan 12 14:41:15 smg01 postfix/smtpd[24106]: disconnect from localhost[127.0.0.1] ehlo=1 mail=1 rcpt=1 data=1 commands=4
Jan 12 14:41:15 smg01 pmg-smtp-filter[24222]: 7E31B5FFD98E37582D: notify <koby@mksoft.co.il> (rule: 00 - OnViruses, 6E9E51FED8)
Jan 12 14:41:15 smg01 pmg-smtp-filter[24222]: ERROR: MIME::Body::File->open /tmp/.proxdump_24222_7E31B5FFD98E37582D/2021 New Price Vat.xz: No such file or directory at /usr/share/perl5/MIME/Body.pm line 435.
Jan 12 14:41:15 smg01 pmg-smtp-filter[24222]: 7E31B5FFD98E37582D: processing time: 7.975 seconds (1.098, 0, 6.018)
Jan 12 14:41:15 smg01 postfix/smtpd[24228]: proxy-reject: END-OF-MESSAGE: 451 4.4.0 detected undelivered mail (7E31B5FFD98E37582D); from=<kristin.b@asterch.com> to=<neomi.a@huberman.co.il> proto=ESMTP helo=<mail.asterch.com>
Jan 12 14:41:15 smg01 postfix/smtpd[24228]: disconnect from hwsrv-824003.hostwindsdns.com[108.174.196.58] ehlo=2 starttls=1 mail=1 rcpt=1 data=0/1 quit=1 commands=6/7
Jan 12 14:41:15 smg01 postfix/smtp[24146]: Trusted TLS connection established to mksoft-co-il.mail.protection.outlook.com[104.47.17.138]:25: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
Last edited: