[26762] in resnet

home help back first fref pref prev next nref lref last post

Re: Zeus botnet anyone?

daemon@ATHENA.MIT.EDU (James J J Hooper)
Fri Sep 16 13:14:23 2011

MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Message-ID:  <4E7382BC.1040704@bristol.ac.uk>
Date:         Fri, 16 Sep 2011 18:09:16 +0100
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: James J J Hooper <jjj.hooper@bristol.ac.uk>
To: RESNET-L@listserv.nd.edu
In-Reply-To:  <4F5F31A69D45B746B439BDA98B62378D9A898401E7@EXCMS.msu.montana.edu>

On 16/09/2011 17:56, Crowe, Sheila wrote:
> Hey Everyone,
>
> Does anyone have any experience with ridding your network of this scourge?
> We believe that one of our VLANs may include a “bot master” and he’s
> killing us over there. It has taken us this long to just find out what the
> problem is. Any tips, hints, references for Voodoo docs, questions…all are
> welcome.
>
> TIA,
>
> Sheila Crowe
>
> Montana State University ResNet

We have DNS blocks on malware via various DNSRBLs. Any web traffic is 
redirected to a box that via the resources at:
https://zeustracker.abuse.ch/
determines if the particular 'hit' is zeus.

Clients with more than 5 HTTP GETs, or any HTTP POSTs, that match Zeus are 
contacted (wired) or contacted+access revoked (wireless or VPN).

-James

___________________________________________________
You are subscribed to the ResNet-L mailing list.

To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________

home help back first fref pref prev next nref lref last post