pete Posted June 15, 2015 Posted June 15, 2015 So the invoice scam situation is beginning to take the michael. Has anyone got a handy powershell script / scheduled report that... Checks tracking logs and: Reports on all emails with attachments sent by an external sender to N+1 internal recipients and sends that info to a chosen mailbox. Does the above, but if one of the internal recipients doesn't exist it quarantines all of the emails?
sukh Posted June 17, 2015 Posted June 17, 2015 Spam email? Look into root of issue. Blacklist/IP blocks/ filtering etc....
pete Posted June 18, 2015 Author Posted June 18, 2015 Spam email? Look into root of issue. Blacklist/IP blocks/ filtering etc.... Yup, done all that. There's filtering upstream and locally and we're using SpamHaus Zen and we're much more intolerant in terms of quarantine rules than we were a year ago - if it even looks iffy it gets quarantined But the root of the issue is "loads of invoice scams with dridex/cryptolocker downloader variants that are brand new (just hours hold) and no-one's picking up on yet". I've noticed a trend of them being blasted out on the weekend too. In-school the download won't work (proxy will catch it). Out of school.......? I'm reliant on the end-user's grasp of e-safety. -- However, I know (based on email traffic trends) that if someone's emailing $person_with_a_mailbox and $person_who's_left with an attachment, there's a 95% chance they're either: a) A Spammer b) Invoice scam So if I could write a rule that does what I'm having to do manually, it would make my life easier.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now