]> source.dussan.org Git - rspamd.git/commitdiff
[Minor] Rework composites for spam injected into compromised accounts
authortwesterhever <40121680+twesterhever@users.noreply.github.com>
Tue, 9 Apr 2024 10:55:24 +0000 (10:55 +0000)
committertwesterhever <40121680+twesterhever@users.noreply.github.com>
Tue, 9 Apr 2024 10:55:24 +0000 (10:55 +0000)
conf/composites.conf

index e38d64e6bfe3dc74e109d8814b2f525d70d9ecae..41cd7749f5528ba2bfa9bfd5df038eb07380fe9e 100644 (file)
@@ -174,11 +174,17 @@ composites {
     policy = "leave";
     description = "Message only contains a redirector URL";
   }
-  THREAD_HIJACKING_FROM_INJECTOR {
-    expression = "FAKE_REPLY & RCVD_VIA_SMTP_AUTH & (!RECEIVED_SPAMHAUS_PBL | RECEIVED_SPAMHAUS_XBL | RECEIVED_SPAMHAUS_SBL)";
+  SUSPICIOUS_AUTH_ORIGIN {
+    expression = "RCVD_VIA_SMTP_AUTH & (!RECEIVED_SPAMHAUS_PBL | RECEIVED_SPAMHAUS_XBL | RECEIVED_SPAMHAUS_SBL | RECEIVED_BLOCKLISTDE)";
+    score = 0.0;
+    policy = "leave";
+    description = "Message authenticated, but from a suspicios origin (potentially an injector)";
+  }
+  ABUSE_FROM_INJECTOR {
+    expression = "SUSPICIOUS_AUTH_ORIGIN & (FAKE_REPLY | HAS_IPFS_GATEWAY_URL | HTML_SHORT_LINK_IMG_1)";
     score = 2.0;
     policy = "leave";
-    description = "Fake reply exhibiting characteristics of being injected into a compromised mail server, possibly e-mail thread hijacking";
+    description = "Message is sent from a suspicios origin and showing signs of abuse, likely spam injected in compromised account";
     group = "compromised_hosts";
   }
   SUSPICIOUS_URL_IN_SUSPICIOUS_MESSAGE {