Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
decode-spam-headers — 이메일이 스팸으로 분류된 이유를 이해하는 데 도움이 되는 스크립트 | Kitploit
도구/GitHubGitHub/mgeeky/decode-spam-headers
Phishing ToolsInformation GatheringRed TeamingEmail SecurityLog Analysis
GitHubmgeeky/decode-spam-headers

decode-spam-headers

이메일이 스팸으로 분류된 이유를 이해하는 데 도움이 되는 스크립트

저장소 보기
69898277개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

decode-spam-headers.py

일상적인 관리 업무를 위해 특정 이메일이 스팸/정크함에 들어간 이유를 이해하려고 하든, 레드팀 피싱 시뮬레이션 목적으로 이해하려고 하든, 이 스크립트가 도움을 드릴 수 있습니다!

아이디어는 MS Office365 E5 환경(MS Defender for Office365 탑재)을 대상으로 상업용 피싱 시뮬레이션을 진행하던 중 떠올랐습니다. 짐작하시겠지만, 피싱 시뮬레이션 관점에서 보면 상당히 까다로운 보안 스택입니다. 이 모든 Office365 SMTP 헤더를 수동으로 파고들어 SCL 값을 골라내려던 끝에, SMTP 헤더용 제대로 된 파서를 만들 때가 왔다는 결론에 도달했습니다.

시간이 지나면서 점점 더 많은 SMTP 헤더에 대한 지원을 추가하게 되었고, 그래서 이 도구가 탄생했습니다. 이제 수십 가지의 다양한 헤더를 이해하는 도구입니다.

정보

이 도구는 입력으로 모든 SMTP 헤더가 포함된 *.EML 또는 *.txt 파일을 받습니다. 그런 다음 흥미로운 헤더의 하위 집합을 추출하고 105개 이상의 테스트를 사용하여 가능한 한 많이 디코딩을 시도합니다.

이 스크립트는 또한 모든 IPv4 주소와 도메인 이름을 추출하여 전체 DNS 조회를 수행합니다.

결과 출력에는 이 이메일이 차단되었을 수 있는 이유에 대한 유용한 정보가 포함됩니다.

클라이언트에게 보내기 전에 피싱 HTML 코드를 다듬고 싶다면, 제 phishing-HTML-linter.py에 입력으로 넣는 것도 고려해 보세요. HTML에서 스팸 점수를 높일 수 있는 악취 를 찾아내는 데 꽤 괜찮은 성능을 발휘합니다.

예시 스크린샷

  • MTA 서버 체인(깔끔하게 파싱된 Received 헤더):

1.png

  • 공개 문서에 따라 최대한 디코딩된 다양한 헤더(여기서는 Office365 ForeFront Spam Report):

2.png

  • 스팸 분류 단서를 적극적으로 검증하고 찾기 위해 구현된 다양한 사용자 정의 휴리스틱, 여기서는 도메인 가장 을 감지하는 로직:

3.png

  • 스크립트는 Office365 안티스팸 규칙 중 일부를 리버스 엔지니어링하고 문서화하는 동시에, 다른 불투명한 안티스팸 헤더에 대한 공개 지식을 수집하려고 시도합니다:

4.png

  • 보고서는 보기 좋은 HTML로 생성할 수 있습니다(사용법: py decode-spam-headers.py headers.txt -f html -o report.html):

5.png

처리되는 헤더

처리되는 헤더(85개 이상의 헤더가 파싱됨):

  • X-forefront-antispam-report
  • X-exchange-antispam
  • X-exchange-antispam-mailbox-delivery
  • X-exchange-antispam-message-info
  • X-microsoft-antispam-report-cfa-test
  • Received
  • From
  • To
  • Subject
  • Thread-topic
  • Received-spf
  • X-mailer
  • X-originating-ip
  • User-agent
  • X-forefront-antispam-report
  • X-microsoft-antispam-mailbox-delivery
  • X-microsoft-antispam
  • X-exchange-antispam-report-cfa-test
  • X-spam-status
  • X-spam-level
  • X-spam-flag
  • X-spam-report
  • X-vr-spamcause
  • X-ovh-spam-reason
  • X-vr-spamscore
  • X-virus-scanned
  • X-spam-checker-version
  • X-ironport-av
  • X-ironport-anti-spam-filtered
  • X-ironport-anti-spam-result
  • X-mimecast-spam-score
  • Spamdiagnosticmetadata
  • X-ms-exchange-atpmessageproperties
  • X-msfbl
  • X-ms-exchange-transport-endtoendlatency
  • X-ms-oob-tlc-oobclassifiers
  • X-ip-spam-verdict
  • X-amp-result
  • X-ironport-remoteip
  • X-ironport-reputation
  • X-sbrs
  • X-ironport-sendergroup
  • X-policy
  • X-ironport-mailflowpolicy
  • X-remote-ip
  • X-sea-spam
  • X-fireeye
  • X-antiabuse
  • X-tmase-version
  • X-tm-as-product-ver
  • X-tm-as-result
  • X-imss-scan-details
  • X-tm-as-user-approved-sender
  • X-tm-as-user-blocked-sender
  • X-tmase-result
  • X-tmase-snap-result
  • X-imss-dkim-white-list
  • X-tm-as-result-xfilter
  • X-tm-as-smtp
  • X-scanned-by
  • X-mimecast-spam-signature
  • X-mimecast-bulk-signature
  • X-sender-ip
  • X-forefront-antispam-report-untrusted
  • X-microsoft-antispam-untrusted
  • X-sophos-senderhistory
  • X-sophos-rescan
  • X-MS-Exchange-CrossTenant-Id
  • X-OriginatorOrg
  • IronPort-Data
  • IronPort-HdrOrdr
  • X-DKIM
  • DKIM-Filter
  • X-SpamExperts-Class
  • X-SpamExperts-Evidence
  • X-Recommended-Action
  • X-AppInfo
  • X-Spam
  • X-TM-AS-MatchedID
  • X-MS-Exchange-EnableFirstContactSafetyTip
  • X-MS-Exchange-Organization-BypassFocusedInbox
  • X-MS-Exchange-SkipListedInternetSender
  • X-MS-Exchange-ExternalOriginalInternetSender
  • X-CNFS-Analysis
  • X-Authenticated-Sender
  • X-Apparently-From
  • X-Env-Sender
  • Sender

이 헤더들 대부분은 완전히 문서화되어 있지 않으므로, 이 스크립트가 모든 세부 사항을 정확히 집어내지는 못하지만, 적어도 제가 찾을 수 있는 모든 정보를 수집합니다.

리버스 엔지니어링 노력

저는 공개적으로 문서화되지 않은 다양한 Office365 ForeFront 안티스팸 규칙(SFS, ENG)을 찾아내고 이해하기 위해 상당한 노력을 기울이고 있습니다.```

(5) Test: X-Forefront-Antispam-Report

HEADER: X-Forefront-Antispam-Report

VALUE: CIP:209.85.167.100;CTRY:US;LANG:de;SCL:5;SRV:;IPV:NLI;SFV:SPM;H:mail-lf1-f100.google.com;PTR:mail-l f1-f100.google.com;CAT:DIMP;SFTY:9.19;SFS:(4636009)(956004)(166002)(6916009)(356005)(336012)(19 625305002)(22186003)(5660300002)(4744005)(6666004)(35100500006)(82960400001)(26005)(7596003)(7636003)(554460 02)(224303003)(1096003)(58800400005)(86362001)(9686003)(43540500002);DIR:INB;SFTY:9.19;

[...]

    - Message matched 24 Anti-Spam rules (SFS):           <============ opaque anti-spam rules
            - (1096003)
            - (166002)
            - (19625305002)
            - (22186003)
            - (224303003)
            - (26005)
            - (336012)
            - (356005)
            - (35100500006)         - (SPAM) Message contained embedded image.
이 프로세스는 순전히 수동으로 진행되며, 특별히 설계된 메일을 Office365 메일 서버로 전송한 다음 수집된 규칙을 수동으로 검토하고 연관시키는 방식입니다.

이미 60개 이상의 메일을 보냈으며, 지금까지 Microsoft의 규칙에 대해 알 수 있었던 내용은 다음과 같습니다:```py

    #
    # Below rules were collected solely in a trial-and-error manner or by scraping any 
    # pieces of information from all around the Internet.
    #
    # They do not represent the actual Anti-Spam rule name or context and surely represent 
    # something close to what is understood (or they may have totally different meaning).
    # 
    # Until we'll be able to review anti-spam rules documention, there is no viable mean to map
    # rule ID to its meaning.
    #

    Anti_Spam_Rules_ReverseEngineered = \
    {
        '35100500006' : logger.colored('(SPAM) Message contained embedded image.', 'red'),

        # https://docs.microsoft.com/en-us/answers/questions/416100/what-is-meanings-of-39x-microsoft-antispam-mailbox.html
        '520007050' : logger.colored('(SPAM) Moved message to Spam and created Email Rule to move messages from this particular sender to Junk.', 'red'),

        # triggered on an empty mail with subject being: "test123 - viagra"
        '162623004' : 'Subject line contained suspicious words (like Viagra).',

        # triggered on mail with subject "test123" and body being single word "viagra"
        '19618925003' : 'Mail body contained suspicious words (like Viagra).',

        # triggered on mail with empty body and subject "Click here"
        '28233001' : 'Subject line contained suspicious words luring action (ex. "Click here"). ',

        # triggered on a mail with test subject and 1500 words of http://nietzsche-ipsum.com/
        '30864003' : 'Mail body contained a lot of text (more than 10.000 characters).',

        # mails that had simple message such as "Hello world" triggered this rule, whereas mails with
        # more than 150 words did not.
        '564344004' : 'HTML mail body with less than 150 words of text (not sure how much less though)',

        # message was sent with a basic html and only one <u> tag in body.
        '67856001' : 'HTML mail body contained underline <u> tag.',

        # message with html,head,body and body containing simple text with no b/i/u formatting.
        '579124003' : 'HTML mail body contained text, but no text formatting (<b>, <i>, <u>) was present',

        # This is a strong signal. Mails without <a> doesnt have this rule.
        '166002' : 'HTML mail body contained URL <a> link.',
도구 다운로드