Why no subject changes or higher score for this phishing email?
<[email protected]> Tue, 28 Oct 2025 23:50:48 -0400
| Newsgroups | gmane.mail.virus.mailscanner |
|---|---|
| Message-ID | <[email protected]> |
This is a multipart message in MIME format. --===============2763809379379130116== Content-Type: multipart/alternative; boundary="----=_NextPart_000_338D_01DC4865.AF7E2990" Content-Language: en-us This is a multipart message in MIME format. ------=_NextPart_000_338D_01DC4865.AF7E2990 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Got a piece of mail identified as ham, with no header changes. The = Hidden URL=E2=80=99s were correctly highlighted.=20 I would have expected this to put up some sort of phishing alert. Do I = need to enable Disarmed Modify Subject for this? I disabled the Disarmed Modify Subject because it was getting added to = every single message with a hidden link, seemed like, many innocent = messages.=20 =20 (I have since fixed my RBL checks, and I=E2=80=99ve set up another email = address to bypass MailScanner so=E2=80=99s I can get my hands on the = unaltered originals) =20 2025-10-28T18:45:02.175284-07:00 sentry MailScanner[183011]: Found = phishing fraud from = https://www.prayers1.com/US/Kosciusko/863615230361694/WeeKids-Children%%2= 7s-Ministry?e=3D1602972382 = <https://www.prayers1.com/US/Kosciusko/863615230361694/WeeKids-Children%2= 5%27s-Ministry?e=3D1602972382> claiming to be www.facebook.com = <http://www.facebook.com/> in BC4DE84A9A.A1DD7 2025-10-28T18:45:02.243128-07:00 sentry MailScanner[182315]: Content = Checks: Detected and have disarmed hidden, phishing tags in HTML message = in BC4DE84A9A.A1DD7 from support-T+jlv20hwxlWk0Htik3J/[email protected] = <mailto:support-T+jlv20hwxlWk0Htik3J/[email protected]>=20 =20 X-MyOrg-MailScanner-SpamCheck: not spam, SpamAssassin (not cached, score=3D2.706, required 4, DKIM_SIGNED 0.10, DKIM_VALID = -0.10, DMARC_NONE 0.90, HTML_MESSAGE 0.00, HTTPS_HTTP_MISMATCH = 0.10, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED 0.00, RCVD_IN_VALIDITY_RPBL_BLOCKED 0.00, RCVD_IN_VALIDITY_SAFE_BLOCKED 0.00, = RCVD_IN_ZEN_BLOCKED_OPENDNS 0.00, SPF_HELO_NONE 0.00, URIBL_BLACK 1.70, URIBL_BLOCKED = 0.00, URIBL_DBL_BLOCKED_OPENDNS 0.00) X-MyOrg-MailScanner-SpamScore: 2 =20 Thanks, Betsy =20 Excerpts from MailScanner.conf: (I haven=E2=80=99t touched the phishing*sites* files, beyond the = automatic updates) =20 =20 Allow Form Tags =3D disarm Allow IFrame Tags =3D disarm Allow Object Codebase Tags =3D disarm Allow Script Tags =3D disarm Allow WebBugs =3D yes Also Find Numeric Phishing =3D yes Content Modify Subject =3D start Content Subject Text =3D {Dangerous Content?} Convert Dangerous HTML To Text =3D no Convert HTML To Text =3D no Dangerous Content Scanning =3D yes Disarmed Modify Subject =3D no Disarmed Subject Text =3D {Disarmed} Find Phishing Fraud =3D yes Highlight Mailto Phishing =3D yes Highlight Phishing Fraud =3D yes Inline HTML External Warning =3D = %report-dir%/inline.external.warning.html Inline HTML Signature =3D %report-dir%/inline.sig.html Inline HTML Warning =3D %report-dir%/inline.warning.html Log Dangerous HTML Tags =3D no <-- changing this to yes Log Silent Viruses =3D yes Phishing Bad Sites File =3D %etc-dir%/phishing.bad.sites.conf Phishing Modify Subject =3D yes Phishing Safe Sites File =3D %etc-dir%/phishing.safe.sites.conf Phishing Subject Text =3D {Possible Phishing} Quarantine Silent Viruses =3D no Silent Viruses =3D HTML-IFrame All-Viruses Still Deliver Silent Viruses =3D no Still Deliver Silent Viruses Unmodified =3D no Still Scan Silent Viruses =3D no Use Stricter Phishing Net =3D yes Virus Modify Subject =3D start Virus Subject Text =3D {Virus?} =20 MailWatch Version: 1.2.23 Operating System Version: Ubuntu 24.04.3 LTS (Noble Numbat) Postfix Version: 3.8.6 MailScanner Version: 5.5.3 ClamAV Version: 1.4.3 SpamAssassin Version: 4.0.0 PHP Version: 8.3.6 MySQL Version: 10.11.13-MariaDB-0ubuntu0.24.04.1 GeoIP Database Version: No database downloaded ------=_NextPart_000_338D_01DC4865.AF7E2990 Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" = xmlns:o=3D"urn:schemas-microsoft-com:office:office" = xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" = xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta = http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta = name=3DGenerator content=3D"Microsoft Word 15 (filtered = medium)"><style><!-- /* Font Definitions */ @font-face {font-family:Wingdings; panose-1:5 0 0 0 0 0 0 0 0 0;} @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; font-size:12.0pt; font-family:"Calibri",sans-serif; mso-ligatures:standardcontextual;} a:link, span.MsoHyperlink {mso-style-priority:99; color:#0563C1; text-decoration:underline;} span.EmailStyle17 {mso-style-type:personal-compose; font-family:"Calibri",sans-serif; color:windowtext;} .MsoChpDefault {mso-style-type:export-only;} @page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1 {page:WordSection1;} --></style></head><body lang=3DEN-US link=3D"#0563C1" vlink=3D"#954F72" = style=3D'word-wrap:break-word'><div class=3DWordSection1><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>Got a piece of mail = identified as ham, with no header changes. The Hidden URL=E2=80=99s were = correctly highlighted. <o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>I would have expected this to put up some = sort of phishing alert. Do I need to enable <b>Disarmed Modify = Subject</b> for this?<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'> I disabled the Disarmed Modify =C2=A0Subject = because it was getting added to every single message with a hidden link, = seemed like, many innocent messages. <o:p></o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt'><o:p> </o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>(I have since fixed = my RBL checks, and I=E2=80=99ve set up another email address to bypass = MailScanner so=E2=80=99s I can get my hands on the unaltered = originals)<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'><o:p> </o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt'>2025-10-28T18:45:02.175284-07:00 sentry = MailScanner[183011]: Found phishing fraud from <a = href=3D"https://www.prayers1.com/US/Kosciusko/863615230361694/WeeKids-Chi= ldren%25%27s-Ministry?e=3D1602972382" = target=3D"_blank">https://www.prayers1.com/US/Kosciusko/863615230361694/W= eeKids-Children%%27s-Ministry?e=3D1602972382</a> claiming to be <a = href=3D"http://www.facebook.com/" target=3D"_blank">www.facebook.com</a> = in BC4DE84A9A.A1DD7<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>2025-10-28T18:45:02.243128-07:00 sentry = MailScanner[182315]: Content Checks: Detected and have disarmed hidden, = phishing tags in HTML message in BC4DE84A9A.A1DD7 from <a = href=3D"mailto:support-T+jlv20hwxlWk0Htik3J/[email protected]">support-T+jlv20hwxlWk0Htik3J/[email protected]</a><o:p></o:p><= /span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'><o:p> </o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt'>X-MyOrg-MailScanner-SpamCheck: not spam, = SpamAssassin (not cached,<o:p></o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 score=3D2.706, required 4, = DKIM_SIGNED 0.10, DKIM_VALID -0.10,<o:p></o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 DMARC_NONE 0.90, HTML_MESSAGE = 0.00, HTTPS_HTTP_MISMATCH 0.10,<o:p></o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 = RCVD_IN_VALIDITY_CERTIFIED_BLOCKED 0.00,<o:p></o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 RCVD_IN_VALIDITY_RPBL_BLOCKED = 0.00,<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 RCVD_IN_VALIDITY_SAFE_BLOCKED = 0.00, RCVD_IN_ZEN_BLOCKED_OPENDNS 0.00,<o:p></o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 SPF_HELO_NONE 0.00, = URIBL_BLACK 1.70, URIBL_BLOCKED 0.00,<o:p></o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 URIBL_DBL_BLOCKED_OPENDNS = 0.00)<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>X-MyOrg-MailScanner-SpamScore: = 2<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'><o:p> </o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>Thanks, = Betsy<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'><o:p> </o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>Excerpts from = MailScanner.conf:<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>(I haven=E2=80=99t touched the = phishing*sites* files, beyond the automatic = updates)<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'><o:p> </o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt'><o:p> </o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>Allow Form Tags =3D = disarm<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Allow IFrame Tags =3D = disarm<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Allow Object Codebase Tags =3D = disarm<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Allow Script Tags =3D = disarm<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Allow WebBugs =3D yes<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>Also Find Numeric = Phishing =3D yes<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Content Modify Subject =3D = start<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Content Subject Text =3D {Dangerous = Content?}<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Convert Dangerous HTML To Text =3D = no<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Convert HTML To Text =3D = no<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Dangerous Content Scanning =3D = yes<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Disarmed Modify Subject =3D = no<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Disarmed Subject Text =3D = {Disarmed}<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Find Phishing Fraud =3D = yes<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Highlight Mailto Phishing =3D = yes<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Highlight Phishing Fraud =3D = yes<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Inline HTML External Warning =3D = %report-dir%/inline.external.warning.html<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>Inline HTML Signature = =3D %report-dir%/inline.sig.html<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>Inline HTML Warning = =3D %report-dir%/inline.warning.html<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>Log Dangerous HTML = Tags =3D no=C2=A0=C2=A0 </span><span = style=3D'font-size:11.0pt;font-family:Wingdings'>=C3=9F</span><span = style=3D'font-size:11.0pt'> changing this to yes<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>Log Silent Viruses = =3D yes<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Phishing Bad Sites File =3D = %etc-dir%/phishing.bad.sites.conf<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>Phishing Modify = Subject =3D yes<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Phishing Safe Sites File =3D = %etc-dir%/phishing.safe.sites.conf<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>Phishing Subject Text = =3D {Possible Phishing}<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Quarantine Silent Viruses =3D = no<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Silent Viruses =3D HTML-IFrame = All-Viruses<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Still Deliver Silent Viruses =3D = no<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Still Deliver Silent Viruses Unmodified =3D = no<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Still Scan Silent Viruses =3D = no<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Use Stricter Phishing Net =3D = yes<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Virus Modify Subject =3D = start<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'>Virus Subject Text =3D = {Virus?}<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt'><o:p> </o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:11.0pt'>MailWatch Version: = 1.2.23<br>Operating System Version: Ubuntu 24.04.3 LTS (Noble = Numbat)<br>Postfix Version: 3.8.6<br>MailScanner Version: = 5.5.3<br>ClamAV Version: 1.4.3<br>SpamAssassin Version: 4.0.0<br>PHP = Version: 8.3.6<br>MySQL Version: = 10.11.13-MariaDB-0ubuntu0.24.04.1<br>GeoIP Database Version: No database = downloaded<o:p></o:p></span></p></div></body></html> ------=_NextPart_000_338D_01DC4865.AF7E2990-- --===============2763809379379130116== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- MailScanner mailing list mailscanner-qhrM8SXbD5JTOyd/[email protected] http://lists.mailscanner.info/mailman/listinfo/mailscanner --===============2763809379379130116==--