Drop SMTP connection at HELO/EHLO matching machine name

Recently there has been many rogue incoming SMTP connections from different IP addresses with the same machine name – “ylmf-pc“. My guess is that these different machines were infected with malware and this malware is utilizing the machine to perform brute force password attack to gain authorization. My server is hosting cPanel and thus using … Read more