[26762] in resnet
Re: Zeus botnet anyone?
daemon@ATHENA.MIT.EDU (James J J Hooper)
Fri Sep 16 13:14:23 2011
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Message-ID: <4E7382BC.1040704@bristol.ac.uk>
Date: Fri, 16 Sep 2011 18:09:16 +0100
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: James J J Hooper <jjj.hooper@bristol.ac.uk>
To: RESNET-L@listserv.nd.edu
In-Reply-To: <4F5F31A69D45B746B439BDA98B62378D9A898401E7@EXCMS.msu.montana.edu>
On 16/09/2011 17:56, Crowe, Sheila wrote:
> Hey Everyone,
>
> Does anyone have any experience with ridding your network of this scourge?
> We believe that one of our VLANs may include a “bot master” and he’s
> killing us over there. It has taken us this long to just find out what the
> problem is. Any tips, hints, references for Voodoo docs, questions…all are
> welcome.
>
> TIA,
>
> Sheila Crowe
>
> Montana State University ResNet
We have DNS blocks on malware via various DNSRBLs. Any web traffic is
redirected to a box that via the resources at:
https://zeustracker.abuse.ch/
determines if the particular 'hit' is zeus.
Clients with more than 5 HTTP GETs, or any HTTP POSTs, that match Zeus are
contacted (wired) or contacted+access revoked (wireless or VPN).
-James
___________________________________________________
You are subscribed to the ResNet-L mailing list.
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________