This Boris comes from the USSR and other states that have no interest in your website other than abusing it. This is a short case study on why it is wise to remain alert.
Invitation to make some changes
On a few sites where I know there is very little annual activity on the behalf of the website owners, I help out from time to time adding a message here and there. Typically this year it has related to coronavirus shut down/ reopening messages. I received a message from one of my clients and proceeded to make the changes yesterday.
On entering the website there was an exclamation mark next to a plugin warning me there was a problem. I investigated, it related to an SMTP plugin which is used to handle sending messages on behalf of the website. This is usually more reliable than sending via PHP the native method in WordPress. By using an SMTP plugin the website connects to an SMTP (outgoing mailserver) and sends the message out through an email account.
In this case it warned me that error messages had been returned from the mail server. It invited me to send a test message to check it. Which I did. The first attempt returned an error, the second attempt a few seconds later was successful, the third attempt returned an error.
What was happening?
I have been down this path a few times, and suspected that the hosting company was limiting messages coming through the mail box, probably because of spam like activity. I raised a ticket with the hosting company and asked them to check and verify.
They never answered the question but requested access to the website to see the fault for themselves. They missed key points in the questions I had raised to them, so I tried again.
Second time around they blamed the plugin for the problem claiming there were no error messages in the hosting relating to failed email attempts. (But still did not answer the question whether they were blocking it or not). So I tried again.
On the third request they did find error messages in the email log which also mentioned suspected spamming activity through the contact form on this website.
Website Log
At this point I checked the log of website accesses to see if I could spot anything there. Sure enough something was probing the website 4 times a minute over less than a 2 second period. Humans do not work that fast, so it had to be a bot (computer program running on a compromised server somewhere).
All accesses were from this IP address: 5.188.210.4. Checking that IP address it turns out to a server in Russia. Probably a legitimate server that has been compromised by someone.
Why should you be concerned about this?
From the first time around 7 years ago now, when I started to turn on security monitoring and you could actually see beyond normal website usage, I was surprised to see the volume of illegitimate attempts to access websites.
One of the most common is sledgehammer approach password guessing routines which try to get into your website.
In this case, something was probing the contact us page and attempting to use it to send spam. It later turned out that the website owner had received 257 spam messages, but they had all been trapped in the email program they were using.
Whatever it was trying to do, it was triggering a safety function in the hosting which was stopping or rate limiting messages from this website. So while it may have tried to send thousands of messages, only a few got out. BUT…. it also means that this Russian computer was hitting the website so hard, that it would have affected any legitimate messages coming in through the contact us page.
When I did my test, it failed, then passed, and then failed for another 10 attempts.
So, if your junk mail rises for any reason beyond a few messages a day, be suspicious. Someone may be targeting your website, and they may be impacting your website’s ability to send messages. Or said another way, your clients to reach you through your website. The main problem here is there is no warning given, no messages of failed delivery.
How to fix it
In all of my cases, I work locally in the UK, the audience with a few exceptions are all UK based, and in most cases probably within 50 miles of the location of the entity or charity. Therefore your website would not be of any interest to someone in India, China or Russia.
The hosting control panel has some country blocking options. You can block by country. In this case I blocked several countries including Russia from this site. It is not a bombproof solution, there are ways around it from the attackers point of view, they could return through a VPN or some other path from the dark web. But in most cases it will work.
In this case some 12 hours later, the server in Russia is still probing the website every minute, which just goes to prove it is a hackers program that is doing this running on a remote server, and probably probing hundreds of sites. However in our case it is blocked at the server before it reaches the website.
If you are affected…
If you suddenly see an uptick in spam messages, and they all seem to be related (Russian or Chinese for example) send me a message and I will check. They are a nuisance, but there are ways of stopping them, both at the hosting, preventing access to the site, and adding spam filtering if there are some common themes if you are affected by direct email.
However do not ignore it. If the spam is originating via your website contact form, this may impact your other users. Send me a message through the contact us page if you want me to check.