The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Getting hit with .zip file emails with viruses.

Discussion in 'E-mail Discussions' started by TogaDave, Nov 23, 2005.

  1. TogaDave

    TogaDave Well-Known Member

    Joined:
    Apr 13, 2003
    Messages:
    135
    Likes Received:
    0
    Trophy Points:
    16
    During the past 48 hours many of the accounts on my server, including myself and several customers, have started receiving a bunch of bogus emails, all of them having a .zip file attached which of course contains an executable.

    The addresses it's from are spoofed - some of them appear to be coming from ourselves, some of them are coming from fake addresses like these:

    admin@cia.gov
    postman@ms-mss-04.nyroc.rr.com
    postman@sba.gov
    admin@fbi.gov
    info@yahoo.com

    The attached files are usually named one of the following:

    reg_pass.zip
    mail_body.zip
    list.zip
    downloadm.zip
    mail.zip
    question_list975.zip

    The thing is there seems to be no correlation/connection between any of us who are receiving the emails, it just seems like someone has managed to be able to target any email address for any account hosted on my server.

    Has anyone else been hit with this? Does anyone know of a good solution?

    I have temporarily blocked .zip files from exim, but obviously that is not a good solution because my customers need to be able to email zips.

    I'm incredibly frustrated at this point and not sure what to do, thanks for any advice,
    Dave
     
  2. nyjimbo

    nyjimbo Well-Known Member

    Joined:
    Jan 25, 2003
    Messages:
    1,125
    Likes Received:
    0
    Trophy Points:
    36
    Location:
    New York
    This week has been really rough. We are getting hit from all sides. Lots of returns are coming from someone spamming senators and congressmen with the similiar zip files. I think this is a co-ordinated effort and may be intended to be done during this quiet holiday week where there are less people around to report spam or fix problems.
     
  3. Brandonm

    Brandonm Active Member

    Joined:
    Aug 31, 2003
    Messages:
    42
    Likes Received:
    0
    Trophy Points:
    6
    Our machines are also being hit with this same type of emails. Some clients reporting upward of 3000 emails per day.
     
  4. chirpy

    chirpy Well-Known Member

    Joined:
    Jun 15, 2002
    Messages:
    13,475
    Likes Received:
    20
    Trophy Points:
    38
    Location:
    Go on, have a guess
    I would suggest that you seriously look into a server-side anti-virus/anti-spam solution (other than the inbuilt cPanel offering). There's a good one from rvskin and MailScanner will stop these dead. I haven't had a single virus get through it.
     
  5. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,468
    Likes Received:
    196
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    Me either. And I have seen them show up in mailwatch. MS swats them down like flies.
     
  6. fikse

    fikse Well-Known Member

    Joined:
    May 10, 2003
    Messages:
    112
    Likes Received:
    0
    Trophy Points:
    16
    you can also use the clamav connector... although the latest round of viruses have been getting through it....
     
Loading...

Share This Page