My Administrator/Webmaster inboxes are getting hammered with Ransomware spam on a daily basis. Place of origin is the usually the Federal District of Mexico and Indore India. I made some progress by blocking the airtelbroadband.in domain and IP address blocks (e.g.,182.70.XXX.XXX)
I set up User Level Filters to block these senders/attachments from people receiving them who wouldn't know any better to not open them up. As the headers are spoofed to appear as legit emails from familiar businesses, and so are the file names of the .zip/docm/.js attachments. It's amazing this day in age how people will still save or open files in an email client without even blinking.
No problems yet, but this is becoming a headache trying to stay on top of this.
What's your experience? Any suggestions?
I set up User Level Filters to block these senders/attachments from people receiving them who wouldn't know any better to not open them up. As the headers are spoofed to appear as legit emails from familiar businesses, and so are the file names of the .zip/docm/.js attachments. It's amazing this day in age how people will still save or open files in an email client without even blinking.
No problems yet, but this is becoming a headache trying to stay on top of this.
What's your experience? Any suggestions?
Comment