Why no subject changes or higher score for this phishing email?

<[email protected]> Tue, 28 Oct 2025 23:50:48 -0400
Newsgroups gmane.mail.virus.mailscanner
Message-ID <[email protected]>
This is a multipart message in MIME format.

--===============2763809379379130116==
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_338D_01DC4865.AF7E2990"
Content-Language: en-us

This is a multipart message in MIME format.

------=_NextPart_000_338D_01DC4865.AF7E2990
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Got a piece of mail identified as ham, with no header changes. The =
Hidden URL=E2=80=99s were correctly highlighted.=20

I would have expected this to put up some sort of phishing alert. Do I =
need to enable Disarmed Modify Subject for this?

I disabled the Disarmed Modify  Subject because it was getting added to =
every single message with a hidden link, seemed like, many innocent =
messages.=20

=20

(I have since fixed my RBL checks, and I=E2=80=99ve set up another email =
address to bypass MailScanner so=E2=80=99s I can get my hands on the =
unaltered originals)

=20

2025-10-28T18:45:02.175284-07:00 sentry MailScanner[183011]: Found =
phishing fraud from =
https://www.prayers1.com/US/Kosciusko/863615230361694/WeeKids-Children%%2=
7s-Ministry?e=3D1602972382 =
<https://www.prayers1.com/US/Kosciusko/863615230361694/WeeKids-Children%2=
5%27s-Ministry?e=3D1602972382>  claiming to be www.facebook.com =
<http://www.facebook.com/>  in BC4DE84A9A.A1DD7

2025-10-28T18:45:02.243128-07:00 sentry MailScanner[182315]: Content =
Checks: Detected and have disarmed hidden, phishing tags in HTML message =
in BC4DE84A9A.A1DD7 from support-T+jlv20hwxlWk0Htik3J/[email protected] =
<mailto:support-T+jlv20hwxlWk0Htik3J/[email protected]>=20

=20

X-MyOrg-MailScanner-SpamCheck: not spam, SpamAssassin (not cached,

                score=3D2.706, required 4, DKIM_SIGNED 0.10, DKIM_VALID =
-0.10,

                DMARC_NONE 0.90, HTML_MESSAGE 0.00, HTTPS_HTTP_MISMATCH =
0.10,

                RCVD_IN_VALIDITY_CERTIFIED_BLOCKED 0.00,

                RCVD_IN_VALIDITY_RPBL_BLOCKED 0.00,

                RCVD_IN_VALIDITY_SAFE_BLOCKED 0.00, =
RCVD_IN_ZEN_BLOCKED_OPENDNS 0.00,

                SPF_HELO_NONE 0.00, URIBL_BLACK 1.70, URIBL_BLOCKED =
0.00,

                URIBL_DBL_BLOCKED_OPENDNS 0.00)

X-MyOrg-MailScanner-SpamScore: 2

=20

Thanks, Betsy

=20

Excerpts from MailScanner.conf:

(I haven=E2=80=99t touched the phishing*sites* files, beyond the =
automatic updates)

=20

=20

Allow Form Tags =3D disarm

Allow IFrame Tags =3D disarm

Allow Object Codebase Tags =3D disarm

Allow Script Tags =3D disarm

Allow WebBugs =3D yes

Also Find Numeric Phishing =3D yes

Content Modify Subject =3D start

Content Subject Text =3D {Dangerous Content?}

Convert Dangerous HTML To Text =3D no

Convert HTML To Text =3D no

Dangerous Content Scanning =3D yes

Disarmed Modify Subject =3D no

Disarmed Subject Text =3D {Disarmed}

Find Phishing Fraud =3D yes

Highlight Mailto Phishing =3D yes

Highlight Phishing Fraud =3D yes

Inline HTML External Warning =3D =
%report-dir%/inline.external.warning.html

Inline HTML Signature =3D %report-dir%/inline.sig.html

Inline HTML Warning =3D %report-dir%/inline.warning.html

Log Dangerous HTML Tags =3D no   <-- changing this to yes

Log Silent Viruses =3D yes

Phishing Bad Sites File =3D %etc-dir%/phishing.bad.sites.conf

Phishing Modify Subject =3D yes

Phishing Safe Sites File =3D %etc-dir%/phishing.safe.sites.conf

Phishing Subject Text =3D {Possible Phishing}

Quarantine Silent Viruses =3D no

Silent Viruses =3D HTML-IFrame All-Viruses

Still Deliver Silent Viruses =3D no

Still Deliver Silent Viruses Unmodified =3D no

Still Scan Silent Viruses =3D no

Use Stricter Phishing Net =3D yes

Virus Modify Subject =3D start

Virus Subject Text =3D {Virus?}

=20

MailWatch Version: 1.2.23
Operating System Version: Ubuntu 24.04.3 LTS (Noble Numbat)
Postfix Version: 3.8.6
MailScanner Version: 5.5.3
ClamAV Version: 1.4.3
SpamAssassin Version: 4.0.0
PHP Version: 8.3.6
MySQL Version: 10.11.13-MariaDB-0ubuntu0.24.04.1
GeoIP Database Version: No database downloaded


------=_NextPart_000_338D_01DC4865.AF7E2990
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta =
name=3DGenerator content=3D"Microsoft Word 15 (filtered =
medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	font-size:12.0pt;
	font-family:"Calibri",sans-serif;
	mso-ligatures:standardcontextual;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style></head><body lang=3DEN-US link=3D"#0563C1" vlink=3D"#954F72" =
style=3D'word-wrap:break-word'><div class=3DWordSection1><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>Got a piece of mail =
identified as ham, with no header changes. The Hidden URL=E2=80=99s were =
correctly highlighted. <o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>I would have expected this to put up some =
sort of phishing alert. Do I need to enable <b>Disarmed Modify =
Subject</b> for this?<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'> I disabled the Disarmed Modify =C2=A0Subject =
because it was getting added to every single message with a hidden link, =
seemed like, many innocent messages. <o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>(I have since fixed =
my RBL checks, and I=E2=80=99ve set up another email address to bypass =
MailScanner so=E2=80=99s I can get my hands on the unaltered =
originals)<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>2025-10-28T18:45:02.175284-07:00 sentry =
MailScanner[183011]: Found phishing fraud from <a =
href=3D"https://www.prayers1.com/US/Kosciusko/863615230361694/WeeKids-Chi=
ldren%25%27s-Ministry?e=3D1602972382" =
target=3D"_blank">https://www.prayers1.com/US/Kosciusko/863615230361694/W=
eeKids-Children%%27s-Ministry?e=3D1602972382</a> claiming to be <a =
href=3D"http://www.facebook.com/" target=3D"_blank">www.facebook.com</a> =
in BC4DE84A9A.A1DD7<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>2025-10-28T18:45:02.243128-07:00 sentry =
MailScanner[182315]: Content Checks: Detected and have disarmed hidden, =
phishing tags in HTML message in BC4DE84A9A.A1DD7 from <a =
href=3D"mailto:support-T+jlv20hwxlWk0Htik3J/[email protected]">support-T+jlv20hwxlWk0Htik3J/[email protected]</a><o:p></o:p><=
/span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>X-MyOrg-MailScanner-SpamCheck: not spam, =
SpamAssassin (not cached,<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 score=3D2.706, required 4, =
DKIM_SIGNED 0.10, DKIM_VALID -0.10,<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 DMARC_NONE 0.90, HTML_MESSAGE =
0.00, HTTPS_HTTP_MISMATCH 0.10,<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 =
RCVD_IN_VALIDITY_CERTIFIED_BLOCKED 0.00,<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 RCVD_IN_VALIDITY_RPBL_BLOCKED =
0.00,<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 RCVD_IN_VALIDITY_SAFE_BLOCKED =
0.00, RCVD_IN_ZEN_BLOCKED_OPENDNS 0.00,<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 SPF_HELO_NONE 0.00, =
URIBL_BLACK 1.70, URIBL_BLOCKED 0.00,<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 URIBL_DBL_BLOCKED_OPENDNS =
0.00)<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>X-MyOrg-MailScanner-SpamScore: =
2<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>Thanks, =
Betsy<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>Excerpts from =
MailScanner.conf:<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>(I haven=E2=80=99t touched the =
phishing*sites* files, beyond the automatic =
updates)<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>Allow Form Tags =3D =
disarm<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Allow IFrame Tags =3D =
disarm<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Allow Object Codebase Tags =3D =
disarm<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Allow Script Tags =3D =
disarm<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Allow WebBugs =3D yes<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>Also Find Numeric =
Phishing =3D yes<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Content Modify Subject =3D =
start<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Content Subject Text =3D {Dangerous =
Content?}<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Convert Dangerous HTML To Text =3D =
no<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Convert HTML To Text =3D =
no<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Dangerous Content Scanning =3D =
yes<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Disarmed Modify Subject =3D =
no<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Disarmed Subject Text =3D =
{Disarmed}<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Find Phishing Fraud =3D =
yes<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Highlight Mailto Phishing =3D =
yes<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Highlight Phishing Fraud =3D =
yes<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Inline HTML External Warning =3D =
%report-dir%/inline.external.warning.html<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>Inline HTML Signature =
=3D %report-dir%/inline.sig.html<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>Inline HTML Warning =
=3D %report-dir%/inline.warning.html<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>Log Dangerous HTML =
Tags =3D no=C2=A0=C2=A0 </span><span =
style=3D'font-size:11.0pt;font-family:Wingdings'>=C3=9F</span><span =
style=3D'font-size:11.0pt'> changing this to yes<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>Log Silent Viruses =
=3D yes<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Phishing Bad Sites File =3D =
%etc-dir%/phishing.bad.sites.conf<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>Phishing Modify =
Subject =3D yes<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Phishing Safe Sites File =3D =
%etc-dir%/phishing.safe.sites.conf<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>Phishing Subject Text =
=3D {Possible Phishing}<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Quarantine Silent Viruses =3D =
no<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Silent Viruses =3D HTML-IFrame =
All-Viruses<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Still Deliver Silent Viruses =3D =
no<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Still Deliver Silent Viruses Unmodified =3D =
no<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Still Scan Silent Viruses =3D =
no<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Use Stricter Phishing Net =3D =
yes<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Virus Modify Subject =3D =
start<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'>Virus Subject Text =3D =
{Virus?}<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt'>MailWatch Version: =
1.2.23<br>Operating System Version: Ubuntu 24.04.3 LTS (Noble =
Numbat)<br>Postfix Version: 3.8.6<br>MailScanner Version: =
5.5.3<br>ClamAV Version: 1.4.3<br>SpamAssassin Version: 4.0.0<br>PHP =
Version: 8.3.6<br>MySQL Version: =
10.11.13-MariaDB-0ubuntu0.24.04.1<br>GeoIP Database Version: No database =
downloaded<o:p></o:p></span></p></div></body></html>
------=_NextPart_000_338D_01DC4865.AF7E2990--


--===============2763809379379130116==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline



-- 
MailScanner mailing list
mailscanner-qhrM8SXbD5JTOyd/[email protected]
http://lists.mailscanner.info/mailman/listinfo/mailscanner


--===============2763809379379130116==--