We already block trash domains like .CYOU, but still my server was getting thousands of .CYOU spams to block each day.
It was playing whack-a-mole with blocking subnets.
That's when I stepped in and looked at it, turns out 100% of them, ALL OF THEM are coming from one hosting company.
Eonix Corporation in Las Vegas.
I blocked their entire ASN, which is 62904, and my .CYOU spam went to zero - instantly. This weekend I have pages and pages of green logs, no spam.
(just 2 random spams that are not related).
CYOU later, Eonix. You are now permanently blocked from any network I am in charge of.
If anyone else is experiencing this attack, I suggest you use this as a reference: https://asn.ipinfo.app/AS62904
Or hit me up and I will try and help.
This thread was automatically locked due to age.