
سكربت يساعدك على فهم سبب انتهاء بريدك الإلكتروني في البريد المزعج (Spam)
سواء كنت تحاول فهم سبب انتهاء بريد إلكتروني معيّن في مجلد الرسائل غير المرغوب فيها (SPAM/Junk) ضمن مهامك الإدارية اليومية أو لأغراض محاكاة التصيّد لفريق Red Team، فهذا السكربت موجود لمساعدتك!
جاءت الفكرة أثناء تنفيذ تمارين تجارية لمحاكاة التصيّد ضد بيئة MS Office365 E5 المزوّدة بـ MS Defender for Office365. وكما يمكنك أن تتخيّل، فهي حزمة أمنية صعبة جداً للتعامل معها من منظور محاكاة التصيّد. بعد البحث اليدوي في جميع ترويسات SMTP الخاصة بـ Office365 ومحاولة انتقاء قيم SCL هذه، حان الوقت لكتابة محلّل مناسب لترويسات SMTP.
ومع مرور الوقت، كنت أضيف دعماً للمزيد والمزيد من ترويسات SMTP - وها نحن ذا. أداة تفهم الآن عشرات الترويسات المختلفة.
تقبل هذه الأداة كمدخل ملفاً بصيغة *.EML أو *.txt يحتوي على جميع ترويسات SMTP. ثم تستخرج مجموعة فرعية من الترويسات المهمة وتحاول فك تشفيرها قدر الإمكان باستخدام أكثر من 105+ اختبار.
كما يستخرج هذا السكربت جميع عناوين IPv4 وأسماء النطاقات ويقوم بإجراء تحليل DNS كامل لها.
سيحتوي المخرجات الناتجة على معلومات مفيدة حول سبب احتمال حظر هذا البريد الإلكتروني.
من أجل تجميل كود HTML الخاص بالتصيّد قبل إرساله إلى عميلك، قد ترغب أيضاً في تغذيته إلى phishing-HTML-linter.py. فهو يقوم بعمل جيد جداً في العثور على الروائح السيئة في كود HTML الخاص بك والتي قد ترفع درجة البريد العشوائي لبريدك الإلكتروني.
Received محلّلة بشكل جيد):



py decode-spam-headers.py headers.txt -f html -o report.html):
الترويسات التي تتم معالجتها (يتم تحليل أكثر من 85+ ترويسة):
X-forefront-antispam-reportX-exchange-antispamX-exchange-antispam-mailbox-deliveryX-exchange-antispam-message-infoX-microsoft-antispam-report-cfa-testReceivedFromToSubjectThread-topicReceived-spfX-mailerX-originating-ipUser-agentX-forefront-antispam-reportX-microsoft-antispam-mailbox-deliveryX-microsoft-antispamX-exchange-antispam-report-cfa-testX-spam-statusX-spam-levelX-spam-flagX-spam-reportX-vr-spamcauseX-ovh-spam-reasonX-vr-spamscoreX-virus-scannedX-spam-checker-versionX-ironport-avX-ironport-anti-spam-filteredX-ironport-anti-spam-resultX-mimecast-spam-scoreSpamdiagnosticmetadataX-ms-exchange-atpmessagepropertiesX-msfblX-ms-exchange-transport-endtoendlatencyX-ms-oob-tlc-oobclassifiersX-ip-spam-verdictX-amp-resultX-ironport-remoteipX-ironport-reputationX-sbrsX-ironport-sendergroupX-policyX-ironport-mailflowpolicyX-remote-ipX-sea-spamX-fireeyeX-antiabuseX-tmase-versionX-tm-as-product-verX-tm-as-resultX-imss-scan-detailsX-tm-as-user-approved-senderX-tm-as-user-blocked-senderX-tmase-resultX-tmase-snap-resultX-imss-dkim-white-listX-tm-as-result-xfilterX-tm-as-smtpX-scanned-byX-mimecast-spam-signatureX-mimecast-bulk-signatureX-sender-ipX-forefront-antispam-report-untrustedX-microsoft-antispam-untrustedX-sophos-senderhistoryX-sophos-rescanX-MS-Exchange-CrossTenant-IdX-OriginatorOrgIronPort-DataIronPort-HdrOrdrX-DKIMDKIM-FilterX-SpamExperts-ClassX-SpamExperts-EvidenceX-Recommended-ActionX-AppInfoX-SpamX-TM-AS-MatchedIDX-MS-Exchange-EnableFirstContactSafetyTipX-MS-Exchange-Organization-BypassFocusedInboxX-MS-Exchange-SkipListedInternetSenderX-MS-Exchange-ExternalOriginalInternetSenderX-CNFS-AnalysisX-Authenticated-SenderX-Apparently-FromX-Env-SenderSenderمعظم هذه الترويسات ليست موثّقة بالكامل، لذلك لا يستطيع السكربت تحديد جميع التفاصيل، لكنه على الأقل يجمع كل ما تمكنت من العثور عليه عنها.
(5) Test: X-Forefront-Antispam-Report
HEADER: X-Forefront-Antispam-Report
VALUE: CIP:209.85.167.100;CTRY:US;LANG:de;SCL:5;SRV:;IPV:NLI;SFV:SPM;H:mail-lf1-f100.google.com;PTR:mail-l f1-f100.google.com;CAT:DIMP;SFTY:9.19;SFS:(4636009)(956004)(166002)(6916009)(356005)(336012)(19 625305002)(22186003)(5660300002)(4744005)(6666004)(35100500006)(82960400001)(26005)(7596003)(7636003)(554460 02)(224303003)(1096003)(58800400005)(86362001)(9686003)(43540500002);DIR:INB;SFTY:9.19;
[...]
- Message matched 24 Anti-Spam rules (SFS): <============ opaque anti-spam rules
- (1096003)
- (166002)
- (19625305002)
- (22186003)
- (224303003)
- (26005)
- (336012)
- (356005)
- (35100500006) - (SPAM) Message contained embedded image.
العملية يدوية بالكامل وتلجأ إلى إرسال رسائل بريد إلكتروني مصممة خصيصًا إلى خوادم بريد Office365 ثم مراجعة وربط القواعد التي تم جمعها يدويًا.
وبعد إرسال أكثر من 60 رسالة بالفعل، هذا ما يمكنني قوله الآن عن قواعد مايكروسوفت:```py
#
# Below rules were collected solely in a trial-and-error manner or by scraping any
# pieces of information from all around the Internet.
#
# They do not represent the actual Anti-Spam rule name or context and surely represent
# something close to what is understood (or they may have totally different meaning).
#
# Until we'll be able to review anti-spam rules documention, there is no viable mean to map
# rule ID to its meaning.
#
Anti_Spam_Rules_ReverseEngineered = \
{
'35100500006' : logger.colored('(SPAM) Message contained embedded image.', 'red'),
# https://docs.microsoft.com/en-us/answers/questions/416100/what-is-meanings-of-39x-microsoft-antispam-mailbox.html
'520007050' : logger.colored('(SPAM) Moved message to Spam and created Email Rule to move messages from this particular sender to Junk.', 'red'),
# triggered on an empty mail with subject being: "test123 - viagra"
'162623004' : 'Subject line contained suspicious words (like Viagra).',
# triggered on mail with subject "test123" and body being single word "viagra"
'19618925003' : 'Mail body contained suspicious words (like Viagra).',
# triggered on mail with empty body and subject "Click here"
'28233001' : 'Subject line contained suspicious words luring action (ex. "Click here"). ',