Today’s #malware sample is in #Spanish, leveraging a #ezmlm mailing list on the back end at facturanuevagenerada [DOT[ com which does not have an associated web site – just a placeholder.
#email #SRC 62.149.155.137 assigned to #aruba.it a hosting provider over in the #EU
Of interest:
#User-Agent: #Roundcube Webmail/1.6.0
#IP is not listed as an #openProxy
#spammers #scammers #malicious #suspectfiles #malware #triage #ioc #_ioc #infosec #informationSecurity #IncidentResponce #IR #spam #infosec #infomantionSecurity #virustotal #ABUSE #emailabuse
#filescan #virustotal
1/3
So far I've written replacements for qmail-smtpd and qmail-remote, and a helper between qmail-local and #ezmlm to prevent DMARC SPF problems with subscribers' domains. Looking at the notqmail design page, it seems I've already done most of what he describes for qmail-remote - EHLO options, STARTTLS, pipelining, DKIM, etc.
Definitely not SRS, though. I have *some* standards. 😱
Was ist von der #mailingliste|n Software #Ezmlm zu halten?
Ist ja schon etwas angestaubt. Kann man sowas noch sicher betreiben?