The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Dangerous spam attack with google.com accounts

Discussion in 'E-mail Discussions' started by mnavas, Dec 17, 2013.

  1. mnavas

    mnavas Member

    Joined:
    Jan 19, 2008
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    1
    Hi,

    I can see my cpanel is affected severe spam attack ..i can see many fake mails log as follows:-

    Code:
    -RSA-AES128-GCM-SHA256:128 C="250 2.0.0 OK 1387264961 s20si13325349igd.32 - gsmtp"
    2013-12-17 02:22:55 H=228-26.thezone.bg [85.217.228.26]:46653 F=<lootedrx810@google.com> rejected RCPT <aec06729@alsadara.com>: No Such User Here"
    2013-12-17 02:22:55 H=228-26.thezone.bg [85.217.228.26]:46654 F=<godless6@google.com> rejected RCPT <a9691d4fe3@alsadart>: No Such User Here"
    2013-12-17 02:22:55 H=228-26.thezone.bg [85.217.228.26]:46653 F=<trollopb68@google.com> rejected RCPT <kdnuispxn95@alsadar.com>: No Such User Here"
    2013-12-17 02:22:55 H=228-26.thezone.bg [85.217.228.26]:46654 F=<misinterpretedf1703@google.com> rejected RCPT <bef9ce13c3995@alsadar.com>: No Such User Here"
    2013-12-17 02:22:55 H=228-26.thezone.bg [85.217.228.26]:46653 F=<ensuresmp73@google.com> rejected RCPT <cgzfte353@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:56 H=228-26.thezone.bg [85.217.228.26]:46654 F=<fineryt769@google.com> rejected RCPT <jriygwjs643@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:56 H=228-26.thezone.bg [85.217.228.26]:46653 F=<barelyggg@google.com> rejected RCPT <cbed84f@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:56 H=228-26.thezone.bg [85.217.228.26]:46654 F=<truthfuln7@google.com> rejected RCPT <a639efc9f@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:56 H=228-26.thezone.bg [85.217.228.26]:46653 F=<ambiancesk@google.com> rejected RCPT <enwauub325@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:56 H=228-26.thezone.bg [85.217.228.26]:46654 F=<runaways36@google.com> rejected RCPT <maaijk644@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:56 H=228-26.thezone.bg [85.217.228.26]:46653 F=<charitablynv409@google.com> rejected RCPT <ae0df49a9@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:57 H=228-26.thezone.bg [85.217.228.26]:46654 F=<fizziestdz04@google.com> rejected RCPT <efqhja957@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:57 H=228-26.thezone.bg [85.217.228.26]:46653 F=<amphibiansx96@google.com> rejected RCPT <qmhziamvz243@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:57 H=228-26.thezone.bg [85.217.228.26]:46654 F=<coquettishhs58@google.com> rejected RCPT <omefc732@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:57 H=228-26.thezone.bg [85.217.228.26]:46653 F=<technicians@google.com> rejected RCPT <ayuxl651@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:57 H=228-26.thezone.bg [85.217.228.26]:46654 F=<hunsol251@google.com> rejected RCPT <ehfpsyd@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:58 H=228-26.thezone.bg [85.217.228.26]:46653 F=<predictionc65@google.com> rejected RCPT <d5f3d4a89e@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:58 H=228-26.thezone.bg [85.217.228.26]:46654 F=<potboilersly1@google.com> rejected RCPT <nmkmdvfv118@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:58 H=228-26.thezone.bg [85.217.228.26]:46653 F=<conducedt558@google.com> rejected RCPT <jwggmbu@alsadarah.net>: No Such User Here"
    2013-12-17 02:22:58 H=228-26.thezone.bg [85.217.228.26]:46654 F=<furrowing2@google.com> rejected RCPT <ksyyq@alsadarah.net>: No Such User Here"
     
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    676
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    Hello :)

    The "rejected RCPT" message indicates the emails were rejected and bounced to the original sender. Were you seeking some other additional action, or were you looking to enable additional measures to prevent outgoing SPAM from your server? This document may be of use:

    cPanel - Prevent Email Abuse

    Thank you.
     
  3. mnavas

    mnavas Member

    Joined:
    Jan 19, 2008
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    1
    All those steps done ...

    mainly its as below, also getting it from the same email ID

    Code:
    2013-12-17 23:47:12 1Vt92L-0003O0-AG <= cordialvkom88@google.com H=190-76-80-114.dyn.movilnet.com.ve [190.76.80.114]:43489 P=esmtp S=3930 id=4918061991.AS35O243388918@xxxxx.com T="Clean energy firm recruiting agents worldwide." for rchkaibane@xxxxxx.com
     
  4. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    676
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    The message getting bounced to the sender ensures it's not delivered to the email account. Could you elaborate on the additional action you would like to see?

    Thank you.
     
  5. mnavas

    mnavas Member

    Joined:
    Jan 19, 2008
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    1
    Hi,
    All these google.com email IDs re not real... its SMTP attack. Also some of the mails delivered by this IDs are getting in outlook as the mails from their own IDs. So its not the issue of not delivering,but need to get any remedy for blocking such big attack mailnly from *.google.com mail ids
     
  6. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    676
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    You may want to utilize the "Account Level Filtering" option in cPanel for the accounts that you want to block all google.com mail addresses. Also, review the options in:

    "WHM Home » Service Configuration » Exim Configuration Manager"

    There are several options here that can help block SPAM. It's up to you how agressive you want to be in blocking the messages.

    Thank you.
     
Loading...

Share This Page