Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
decode-spam-headers — メールがスパムに振り分けられた理由を理解するのに役立つスクリプト | Kitploit
ツール/GitHubGitHub/mgeeky/decode-spam-headers
フィッシングツール情報収集レッドチーミングメールセキュリティログ分析
GitHubmgeeky/decode-spam-headers

decode-spam-headers

メールがスパムに振り分けられた理由を理解するのに役立つスクリプト

リポジトリを見る
69898277ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

decode-spam-headers.py

日々の管理業務で特定のメールが SPAM/迷惑メールに振り分けられた理由を理解したい場合でも、Red-Team のフィッシングシミュレーションの目的であっても、このスクリプトは役立ちます!

このアイデアは、MS Defender for Office365 を備えた商用 MS Office365 E5 環境を対象に、商用フィッシングシミュレーション演習を実施した際に生まれました。想像がつくと思いますが、フィッシングシミュレーションの観点から見ると、かなり強固なセキュリティスタックです。 手作業でこれらすべての Office365 SMTP ヘッダーを調べ、SCL 値を選り分けようとした後、SMTP ヘッダー用の適切なパーサーを作成する時が来ました。

時が経つにつれ、私はさらに多くの SMTP ヘッダーへの対応を追加していき、そしてここに完成形があります。現在では数十種類の異なるヘッダーを解釈するツールです。

情報

このツールは、すべての SMTP ヘッダーを含む *.EML または *.txt ファイルを入力として受け取ります。次に、興味深いヘッダーのサブセットを抽出し、105+ のテストを使用して、それらを可能な限りデコードしようとします。

このスクリプトはまた、すべての IPv4 アドレスとドメイン名を抽出し、それらの完全な DNS 解決を実行します。

結果として得られる出力には、このメールがブロックされた可能性がある理由に関する有用な情報が含まれます。

クライアントに送信する前にフィッシング HTML コードを装飾したい場合は、私の phishing-HTML-linter.py に通すこともできます。このツールは、メールのスパムスコアを上昇させる HTML 内の 悪い匂い を見つけるのにかなり優れた仕事をします。

スクリーンショットの例

  • MTAサーバーのチェーン (Received ヘッダーを見やすく解析):

1.png

  • 公開されているドキュメントに従って、さまざまなヘッダーを可能な限りデコード (ここでは Office365 ForeFront Spam Report):

2.png

  • スパム分類の手がかりを積極的に検証および探索するために実装されたさまざまなカスタムヒューリスティック。ここでは ドメイン偽装 (Domain Impersonation) を検出するロジック:

3.png

  • スクリプトは、Office365 アンチスパムルールの一部をリバースエンジニアリングして文書化しようと試み、他の不透明なアンチスパムヘッダーに関する公開知識も収集します:

4.png

  • レポートは見栄えの良い HTML に生成できます (使用法: py decode-spam-headers.py headers.txt -f html -o report.html):

5.png

処理されるヘッダー

処理されるヘッダー (85+ 以上のヘッダーが解析されます):

  • X-forefront-antispam-report
  • X-exchange-antispam
  • X-exchange-antispam-mailbox-delivery
  • X-exchange-antispam-message-info
  • X-microsoft-antispam-report-cfa-test
  • Received
  • From
  • To
  • Subject
  • Thread-topic
  • Received-spf
  • X-mailer
  • X-originating-ip
  • User-agent
  • X-forefront-antispam-report
  • X-microsoft-antispam-mailbox-delivery
  • X-microsoft-antispam
  • X-exchange-antispam-report-cfa-test
  • X-spam-status
  • X-spam-level
  • X-spam-flag
  • X-spam-report
  • X-vr-spamcause
  • X-ovh-spam-reason
  • X-vr-spamscore
  • X-virus-scanned
  • X-spam-checker-version
  • X-ironport-av
  • X-ironport-anti-spam-filtered
  • X-ironport-anti-spam-result
  • X-mimecast-spam-score
  • Spamdiagnosticmetadata
  • X-ms-exchange-atpmessageproperties
  • X-msfbl
  • X-ms-exchange-transport-endtoendlatency
  • X-ms-oob-tlc-oobclassifiers
  • X-ip-spam-verdict
  • X-amp-result
  • X-ironport-remoteip
  • X-ironport-reputation
  • X-sbrs
  • X-ironport-sendergroup
  • X-policy
  • X-ironport-mailflowpolicy
  • X-remote-ip
  • X-sea-spam
  • X-fireeye
  • X-antiabuse
  • X-tmase-version
  • X-tm-as-product-ver
  • X-tm-as-result
  • X-imss-scan-details
  • X-tm-as-user-approved-sender
  • X-tm-as-user-blocked-sender
  • X-tmase-result
  • X-tmase-snap-result
  • X-imss-dkim-white-list
  • X-tm-as-result-xfilter
  • X-tm-as-smtp
  • X-scanned-by
  • X-mimecast-spam-signature
  • X-mimecast-bulk-signature
  • X-sender-ip
  • X-forefront-antispam-report-untrusted
  • X-microsoft-antispam-untrusted
  • X-sophos-senderhistory
  • X-sophos-rescan
  • X-MS-Exchange-CrossTenant-Id
  • X-OriginatorOrg
  • IronPort-Data
  • IronPort-HdrOrdr
  • X-DKIM
  • DKIM-Filter
  • X-SpamExperts-Class
  • X-SpamExperts-Evidence
  • X-Recommended-Action
  • X-AppInfo
  • X-Spam
  • X-TM-AS-MatchedID
  • X-MS-Exchange-EnableFirstContactSafetyTip
  • X-MS-Exchange-Organization-BypassFocusedInbox
  • X-MS-Exchange-SkipListedInternetSender
  • X-MS-Exchange-ExternalOriginalInternetSender
  • X-CNFS-Analysis
  • X-Authenticated-Sender
  • X-Apparently-From
  • X-Env-Sender
  • Sender

これらのヘッダーのほとんどは完全には文書化されていないため、スクリプトはすべての詳細を正確に特定することはできませんが、少なくとも見つけられたすべての情報を収集します。

リバースエンジニアリングの取り組み

私は、Office365 ForeFront アンチスパムルール (SFS、ENG) が公開文書化されていないにもかかわらず、それらを特定して理解するための多大な努力を払っています。```

(5) Test: X-Forefront-Antispam-Report

HEADER: X-Forefront-Antispam-Report

VALUE: CIP:209.85.167.100;CTRY:US;LANG:de;SCL:5;SRV:;IPV:NLI;SFV:SPM;H:mail-lf1-f100.google.com;PTR:mail-l f1-f100.google.com;CAT:DIMP;SFTY:9.19;SFS:(4636009)(956004)(166002)(6916009)(356005)(336012)(19 625305002)(22186003)(5660300002)(4744005)(6666004)(35100500006)(82960400001)(26005)(7596003)(7636003)(554460 02)(224303003)(1096003)(58800400005)(86362001)(9686003)(43540500002);DIR:INB;SFTY:9.19;

[...]

    - Message matched 24 Anti-Spam rules (SFS):           <============ opaque anti-spam rules
            - (1096003)
            - (166002)
            - (19625305002)
            - (22186003)
            - (224303003)
            - (26005)
            - (336012)
            - (356005)
            - (35100500006)         - (SPAM) Message contained embedded image.
このプロセスは完全に手動であり、特別に設計されたメールをOffice365メールサーバーに送信し、その後、収集したルールを手動でレビューして関連付けます。

すでに60通以上のメールを送信しましたが、現時点でMicrosoftのルールについて言えることは次のとおりです。```py

    #
    # Below rules were collected solely in a trial-and-error manner or by scraping any 
    # pieces of information from all around the Internet.
    #
    # They do not represent the actual Anti-Spam rule name or context and surely represent 
    # something close to what is understood (or they may have totally different meaning).
    # 
    # Until we'll be able to review anti-spam rules documention, there is no viable mean to map
    # rule ID to its meaning.
    #

    Anti_Spam_Rules_ReverseEngineered = \
    {
        '35100500006' : logger.colored('(SPAM) Message contained embedded image.', 'red'),

        # https://docs.microsoft.com/en-us/answers/questions/416100/what-is-meanings-of-39x-microsoft-antispam-mailbox.html
        '520007050' : logger.colored('(SPAM) Moved message to Spam and created Email Rule to move messages from this particular sender to Junk.', 'red'),

        # triggered on an empty mail with subject being: "test123 - viagra"
        '162623004' : 'Subject line contained suspicious words (like Viagra).',

        # triggered on mail with subject "test123" and body being single word "viagra"
        '19618925003' : 'Mail body contained suspicious words (like Viagra).',

        # triggered on mail with empty body and subject "Click here"
        '28233001' : 'Subject line contained suspicious words luring action (ex. "Click here"). ',

        # triggered on a mail with test subject and 1500 words of http://nietzsche-ipsum.com/
        '30864003' : 'Mail body contained a lot of text (more than 10.000 characters).',

        # mails that had simple message such as "Hello world" triggered this rule, whereas mails with
        # more than 150 words did not.
        '564344004' : 'HTML mail body with less than 150 words of text (not sure how much less though)',

        # message was sent with a basic html and only one <u> tag in body.
        '67856001' : 'HTML mail body contained underline <u> tag.',

        # message with html,head,body and body containing simple text with no b/i/u formatting.
        '579124003' : 'HTML mail body contained text, but no text formatting (<b>, <i>, <u>) was present',

        # This is a strong signal. Mails without <a> doesnt have this rule.
        '166002' : 'HTML mail body contained URL <a> link.',
ツールをダウンロード