Jump to content

Recommended Posts

Posted

So the invoice scam situation is beginning to take the michael.

 

Has anyone got a handy powershell script / scheduled report that...

 

Checks tracking logs and:

 

Reports on all emails with attachments sent by an external sender to N+1 internal recipients and sends that info to a chosen mailbox.

 

Does the above, but if one of the internal recipients doesn't exist it quarantines all of the emails?

Posted
Spam email? Look into root of issue. Blacklist/IP blocks/ filtering etc....

 

Yup, done all that. There's filtering upstream and locally and we're using SpamHaus Zen and we're much more intolerant in terms of quarantine rules than we were a year ago - if it even looks iffy it gets quarantined

 

But the root of the issue is "loads of invoice scams with dridex/cryptolocker downloader variants that are brand new (just hours hold) and no-one's picking up on yet".

 

I've noticed a trend of them being blasted out on the weekend too.

 

In-school the download won't work (proxy will catch it). Out of school.......? I'm reliant on the end-user's grasp of e-safety.

 

--

 

However, I know (based on email traffic trends) that if someone's emailing $person_with_a_mailbox and $person_who's_left with an attachment, there's a 95% chance they're either:

 

a) A Spammer

b) Invoice scam

 

So if I could write a rule that does what I'm having to do manually, it would make my life easier.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...