This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

spams from Google Groups

Hi all,
   Every day my company receiving a huge amount of spams coming from sender "mahmod rmdan  "
When I check Astaro mail manager I see these mails coming from a lot of Google Groups mail addresses like:
alshomou+bnccni9tistehcm0jp5bboeugfbnw@googlegroups.com

noorislamna+bnccotz7a6xbhcgnpt5bboepljibq@googlegroups.com
noorislamna+bnccotz7a6xbhcgnpt5bboepljibq@googlegroups.com
kalam-fyel7op+bncclnyoywnexcfvjl5bboepxivbg@googlegroups.com
panat-3man+bncclnyoywnexcevjl5bboerw215g@googlegroups.com
magm3t-googel+bncclnyoywnexcdvjl5bboetfgjia@googlegroups.com
masha3er-tefla+bncclnyoywnexcevjl5bboe6r82sg@googlegroups.com
kalam-fyel7op+bncclnyoywnexdrupl5bboexj9rtq@googlegroups.com
panat-3man+bncclnyoywnexdqupl5bboeydrnjg@googlegroups.com
magm3t-googel+bncclnyoywnexdoupl5bboeqtgrea@googlegroups.com
masha3er-tefla+bncclnyoywnexdpupl5bboe4v5qlw@googlegroups.com
kalam-fyel7op+bncclnyoywnexcuupl5bboet7gkig@googlegroups.com
panat-3man+bncclnyoywnexcsupl5bboeokiivw@googlegroups.com
masha3er-tefla+bncclnyoywnexctupl5bboeknjtoa@googlegroups.com
magm3t-googel+bncclnyoywnexcrupl5bboee1e1oq@googlegroups.com
noorislamna+bnccotz7a6xbhcewyn5bboedtewra@googlegroups.com
noorislamna+bnccotz7a6xbhcewyn5bboedtewra@googlegroups.com

and every day I see different mail address like the above.
How can I stop these spams?
Thanks,
Mostafa Aly


This thread was automatically locked due to age.
  • I've edited your post so that the information is not obscured by hyperlinking.

    It looks like you could blacklist *@googlegroups.com.  If you don't want to do that, you could start with:

    alshomou*@googlegroups.com
    kalam-fy*@googlegroups.com
    magm3t-g*@googlegroups.com
    masha3er*@googlegroups.com
    noorisla*@googlegroups.com
    panat-3m*@googlegroups.com



    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,
      I blacklisted what you recommended above, as attached,
    But the spams still passthrough ASTARO from these mail address,
    Kindly find the output of the log file related to these mails:

    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="magm3t-googel+bncclnyoywnexdxrit7bboeiyt-ma@googlegroups.com" to="sales@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-GA" size="6453"
    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="panat-3man+bncclnyoywnexdyrit7bboe5q7upg@googlegroups.com" to="ysedky@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-JE" size="6453"
    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="kalam-fyel7op+bncclnyoywnexd1rit7bboet6x3qw@googlegroups.com" to="jobs@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-Lw" size="6453"
    /var/log/smtp.log:2012:03:15-00:18:00 asg smtpd[1145]: SCANNER[1145]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.213.57" from="masha3er-tefla+bncclnyoywnexd0rit7bboejuz8pg@googlegroups.com" to="sales@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wW8-0000IT-DI" size="6453"

    Thanks,
    Mostafa Ahdy
  • Hi Bob,
      I blacklisted what you recommended above, as attached,
    But the spams still passthrough ASTARO from these mail address,
    Kindly find the output of the log file related to these mails:

    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="magm3t-googel+bncclnyoywnexdxrit7bboeiyt-ma@googlegroups.com" to="sales@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-GA" size="6453"
    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="panat-3man+bncclnyoywnexdyrit7bboe5q7upg@googlegroups.com" to="ysedky@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-JE" size="6453"
    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="kalam-fyel7op+bncclnyoywnexd1rit7bboet6x3qw@googlegroups.com" to="jobs@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-Lw" size="6453"
    /var/log/smtp.log:2012:03:15-00:18:00 asg smtpd[1145]: SCANNER[1145]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.213.57" from="masha3er-tefla+bncclnyoywnexd0rit7bboejuz8pg@googlegroups.com" to="sales@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wW8-0000IT-DI" size="6453"

    Thanks,
    Mostafa Ahdy
  • Hi Bob,
      I blacklisted what you recommended above, as attached,
    But the spams still passthrough ASTARO from these mail address,
    Kindly find the output of the log file related to these mails:

    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="magm3t-googel+bncclnyoywnexdxrit7bboeiyt-ma@googlegroups.com" to="sales@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-GA" size="6453"
    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="panat-3man+bncclnyoywnexdyrit7bboe5q7upg@googlegroups.com" to="ysedky@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-JE" size="6453"
    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="kalam-fyel7op+bncclnyoywnexd1rit7bboet6x3qw@googlegroups.com" to="jobs@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-Lw" size="6453"
    /var/log/smtp.log:2012:03:15-00:18:00 asg smtpd[1145]: SCANNER[1145]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.213.57" from="masha3er-tefla+bncclnyoywnexd0rit7bboejuz8pg@googlegroups.com" to="sales@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wW8-0000IT-DI" size="6453"

    Thanks,
    Mostafa Ahdy
  • Hi Bob,
      I blacklisted what you recommended above, as attached,
    But the spams still passthrough ASTARO from these mail address,
    Kindly find the output of the log file related to these mails:

    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="magm3t-googel+bncclnyoywnexdxrit7bboeiyt-ma@googlegroups.com" to="sales@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-GA" size="6453"
    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="panat-3man+bncclnyoywnexdyrit7bboe5q7upg@googlegroups.com" to="ysedky@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-JE" size="6453"
    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="kalam-fyel7op+bncclnyoywnexd1rit7bboet6x3qw@googlegroups.com" to="jobs@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-Lw" size="6453"
    /var/log/smtp.log:2012:03:15-00:18:00 asg smtpd[1145]: SCANNER[1145]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.213.57" from="masha3er-tefla+bncclnyoywnexd0rit7bboejuz8pg@googlegroups.com" to="sales@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wW8-0000IT-DI" size="6453"

    Thanks,
    Mostafa Ahdy
  • Hi Bob,
      I blacklisted what you recommended above, as attached,
    But the spams still passthrough ASTARO from these mail address,
    Kindly find the output of the log file related to these mails:

    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="magm3t-googel+bncclnyoywnexdxrit7bboeiyt-ma@googlegroups.com" to="sales@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-GA" size="6453"
    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="panat-3man+bncclnyoywnexdyrit7bboe5q7upg@googlegroups.com" to="ysedky@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-JE" size="6453"
    /var/log/smtp.log:2012:03:15-00:07:10 asg smtpd[443]: SCANNER[443]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.220.185" from="kalam-fyel7op+bncclnyoywnexd1rit7bboet6x3qw@googlegroups.com" to="jobs@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wLe-000079-Lw" size="6453"
    /var/log/smtp.log:2012:03:15-00:18:00 asg smtpd[1145]: SCANNER[1145]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="209.85.213.57" from="masha3er-tefla+bncclnyoywnexd0rit7bboejuz8pg@googlegroups.com" to="sales@mmm.com" subject="مساج للقضيب مع شرح تفصيلي .. للمتزوجات فقط" queueid="1S7wW8-0000IT-DI" size="6453"

    Thanks,
    Mostafa Ahdy
  • I got tired of international spam from google some time ago and have been blocking google groups with what Bob has recommended for you.

    It looks like you could blacklist *@googlegroups.com.

    That will take care of it completely once and for all.
  • Blacklist googlegroups at all is not a solution for me as there are so many googlegroups from which we may receive legal mails.
    Anyway,why we still receive spam mails from the above senders which I blacklisted, Is Astaro blacklist is not effective?!
  • I think your only solution is to do the blacklist I suggested and then whitelist the specific ones you want like most_ahdy*@googlegroups.om.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • But it is not a practical solution, because this way will block many many mails the may be important to our company,
    But what make me mad here is why googlegroups make all this mess with Astaro,
    Why Astaro blacklist can not stops this mails!!!!!!!!!!!!