Solved

Receive many anonymos mails with attachements .zip

Posted on 2016-09-22
6
37 Views
Last Modified: 2016-09-23
Hi,

I have a mailbox (Exchange 2013) receive always many anonymos emails with zip attachements, of course i guess it's malisious mails how can i block the flow of this emails
I enabled and configured the native anti-spam and the mailware protection on Exchange but my problem not resolved
Example of mail:

Earl <Earl.eddington5@cornishcastle.co.uk>
mer. 21/09/2016 15:54
À :
******;
 1 pièce jointe
_23806_361456.zip

Your message is ready to be sent with the following file or link
attachments:

  _23806_361456

Note: To protect against computer viruses, e-mail programs may prevent
sending or receiving certain types of file attachments.  Check your e-mail
security settings to determine how attachments are handled.
0
Comment
Question by:Mohamed Amine LIMAME
  • 2
  • 2
  • 2
6 Comments
 
LVL 18

Expert Comment

by:hopeleonie
Comment Utility
Which Anti-spam solution do you use?
0
 
LVL 23

Accepted Solution

by:
Dr. Klahn earned 500 total points
Comment Utility
If your SMTP receiver is not already doing this, consider add blocking using the active spam blocking lists.  This should cut the size of the problem down significantly, possibly to a level where it can be handled by the unfortunate recipients.

Using the following four lists, the amount of spam getting through has fallen by 90% on my server.

  • zen.spamhaus.org
  • bl.spamcop.net
  • cbl.abuseat.org
  • dnsbl-1.uceprotect.net

Blocking all email containing ZIP file attachments is certainly possible, but it cripples anyone who wants to send a compressed attachment.
0
 
LVL 18

Expert Comment

by:hopeleonie
Comment Utility
We use Barracuda to block our Spam. It has reduced 99% of our Spam. The MS inbuilt solution was not enough for us.
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 

Author Comment

by:Mohamed Amine LIMAME
Comment Utility
@Dr. Klahn

I configured the:

zen.spamhaus.org
bl.spamcop.net

but problem not solved
0
 
LVL 23

Expert Comment

by:Dr. Klahn
Comment Utility
Does the mail receiver's log show emails being refused as spam?  If not, add uceprotect.net.   That will certainly cause some incoming email to be rejected.  If it does not, then it is possible the blocks are not actually active.

Also check the full header expansion of several of the spams to see where the routing shows it came from.  Note that this can be deceptive as much spam tries to obfuscate the actual source.  If (for example) the routing shows that it is emanating from within your network, then it is might be bypassing all filters; in that case, find the infected machine(s) and shut them down.
0
 

Author Comment

by:Mohamed Amine LIMAME
Comment Utility
I configured the:
Connection Filtering Agent in FrontEND

http://clintboessen.blogspot.com/2014/05/rbl-providers-and-exchange-2013.html

and i configured also the IPBlockListProvider:

zen.spamhaus.org
bl.spamcop.net
cbl.abuseat.org
dnsbl-1.uceprotect.net

problem almost solved  90% but i continue to receive some a few mails
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now