Where do I get such a thing?
A large portion of my incoming spam seems to be coming from "xxxxx.onmicrososoft.com", which sounds like it might be what you're talking about.
Where do I get such a thing?
A large portion of my incoming spam seems to be coming from "xxxxx.onmicrososoft.com", which sounds like it might be what you're talking about.
To get started: 41a71966-4fa6-4839-a87d-034d66bdda33 d931cb4a-3984-4328-9fb6-96d7d7fd51b0 e85f2c00-2730-4ca5-b8d8-609b15bd4746
(all seen-in-the-wild compromised instances in the past 14 days)
I have tried sending Microsoft reports, but have not heard back, and the spam continues.
But, if you can, record the `X-MS-Exchange-CrossTenant-Id` header value for the spam you receive. If it ends in 'aaaa', that means it comes from the public outlook.com/hotmail.com service, and you'll need to do text content/from-address filtering to get rid of spam.
But otherwise, deny-listing the GUID you get, will do wonders to eliminate future spam from that source...
https://gist.github.com/digitalresistor/03ea1b8798c519a71f06...
Edit: moved list to Gist.
I check my junk folder every other day to make sure that legitimate mail does not go through because I've set my rspamd config pretty tight.
So all of these are classified correctly as spam by human eyes.
These are not that easy to filter due to the risk of false positives, but in general, a sender with a From: header matching '.*\d{1,}@(outlook|gmail|aol|yahoo|hotmail)\.com`, no To: header matching the actual recipient, and a number of keywords in the message text can be safely rejected as bizdev/SEO spam.
The big-brand spam is actually pretty easy to filter, as there are always 'tells' in the message structure. Even just requiring a match between From: display names and domains yields pretty good results, especially if you normalize the display name to eliminate homoglyphs and nearly-similar spellings.