phishing for active accounts

Discussion forum for Enterprise Edition.
Post Reply
dcol
Posts: 237
Joined: Fri May 26, 2017 11:25 pm

phishing for active accounts

Post by dcol »

I am seeing this sort of thing. Thousands a day from many IP's. I did block all the foreign ones, but there are plenty from the US which I cannot normally block in the firewall. My question is. Any way to stop this. Maybe set a limit on how many can come in before I invoke Access control?
Here is an example in the SMTP log. You can see these all come in within a few seconds. This is an attempt to find valid email accounts.
How to stop this? How about a filter script to catch 550 errors withing a certain period, then block the IP.

05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<enquires@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 3052
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<rhx4c0k8tchzz37a@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<zrzkryftoucxr6ez@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<daniella@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<giovanna@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<database@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<arobinson@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<ebrown@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<author@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<acampbell@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<sclark@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<nacho@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<lasse@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<franck@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<overseas@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<mba@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<lacey@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<das@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<princess@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<chill@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<juli@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<santi@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<nam@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<ejones@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<lincoln@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<greta@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<nataly@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<92kj03m7sb1qcw@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<accounts.payable@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<bernhard@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<jparker@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<unrecognizingly@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<advisor@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<rf@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<100@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<sri@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<remi@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<jrogers@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<jaclyn@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<produzione@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<ester@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<zakupki@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<premium@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<kf@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<tmqabwupgxcy@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<hoeggpp7i1412v@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<5iopu5qwrabyy@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<sma@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<slewis@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<fantocine@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<tf@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<manager2@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<mae@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<dharris@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<karima@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<jn@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<jed@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<donnie@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<vasilije@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<belen@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<aramos@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<ww@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<holiday@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<rana@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<mailmaster@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<jonah@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<nil1ns8275by@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<bing@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<zane@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<malik@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<eda@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<mrobinson@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<jai@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<gw@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<edp@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<tn@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<marks@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<liu@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<remy@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<randerson@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<girish@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<kaitlin@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<catalog@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<rosario@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<meyer@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<boxoffice@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<nir@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<naoresponda@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<jmorgan@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<song@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<gsa@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<nino@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<khan@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<donovan@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<first@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<3rlbnuq2fli13j3@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<envios@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<noelle@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:09:54 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<ban7vbxdxn1bu@myemail.com> 550 Requested action not taken: mailbox unavailable or not local. 67 0
05/23/23 00:10:02 SMTP-IN CAE4105643214271A5C71FC1A1FD8E10.MAI 2312 49.204.93.6 RCPT RCPT TO:<corinne@myemail.com> 250 Requested mail action okay, completed 43 0

Philb
Posts: 50
Joined: Fri Jul 25, 2003 11:02 pm
Location: Sydney, NSW, Australia

Re: phishing for active accounts

Post by Philb »

I've seen the same attempts but only a handful of source IPs. Using zen.spamhaus.org for DNSBL has caught them all.

See: https://www.mailenable.com/documentation/10.0/Standard/SMTP_props_-Security.html

"Drop a connection when the failed number of commands or recipients reaches"

Alternatively. "Restrict the number of recipients per email" may work, if you can do that in your environment.

dcol
Posts: 237
Joined: Fri May 26, 2017 11:25 pm

Re: phishing for active accounts

Post by dcol »

Thanks for the reply. I already did the security items, but not the blacklist, which I will try now. Setting the firewall to GeoIP restrict inbound SMTP also helped.

Issue is the harvesting never reaches the filters because they only issue some command that checks for valid accounts. Access blocking doesn't help because as soon as they get a good response, they change to another IP and start sending spam and phishing for passwords. I need a way to stop the multiple hits within the same inquiry. This is happening to me at least 50 times an hour, all from different IP's. It seems the source is mostly from Russia who have hacked into US servers and running their spam campaign from those accounts.

There must be a way to stop the email list from proceeding once it hits an invalid user. This is all incoming SMTP. Anyone have a script that could help?

Or how about a limit on the number of recipients from a non-local domain that can be used in an incoming email. There should only be one allowed at a time on my server. What mechanism can control this?

Post Reply