Sooo... also wir denken, dass der Spuk jetzt vorbei ist. Seit 2 Tagen nicht mehr geblacklistet - und auch keine Anzeichen mehr dafür.
Laut unserem Admin haben wir nur 5 Rechner, die ohne Proxy mit Authentifizierung ins Netz dürfen. Diese wurden geprüft mit den Bot-Tools von www.botfrei.de und den Eset Online Scanner – seitdem ist Ruhe. Der Eset Scanner hat wohl als einziger etwas gefunden.
Sollte doch nochmal etwas passieren, melde ich mich nochmal - aber ich denke, es ist soweit erledigt. Vielen Dank für Euer Feedback.
PS: Übrigens sieht die Fehlermeldung von der Blacklist inzwischen anders aus - hier nochmal der Vollständigkeit halber:
Zitat:
IP Address XX.XXX.XXX.XX is not listed in the CBL.
It was previously listed, but was removed at 2014-03-24 09:47 GMT (2 days, 2 hours, 55 minutes ago)
At the time of removal, this was the explanation for this listing:
This IP address is infected with, or is NATting for a machine infected with a Trojan called Win32/Zbot (Microsoft), also known as "ZeuS" or "WSNPoem".
In this particular case, this host is infected with ZeuSv3, one of the most recent versions of ZeuS that is using peer-to-peer (P2P) command and control mechanisms. This version of Zeus is also known as "P2P ZeuS" or "Gameover malware".
ZeuSv3 takes advantage of P2P techniques by communicating with other nodes (=infected computers) on high ports (UDP and TCP).
To find an infected computer on a NATted network you will have to search through your firewall logs for connections from/to UDP port YYY.YYY.YYY.YYY. However, any process or host sending/receiving large numbers of UDP or TCP packets on high ports (10,000 and higher) should be looked at closely.
Zbot/Zeus is a banking trojan, and specializes in stealing personal information (passwords, account information, etc) from interactions with banking sites through the use of "formgrabs". Zeus is also a common vector for downloading and controlling of Cutwail (email spambot) and Pushdo (DDOS).
Further (technical) information about this Trojan type can be obtained here:
fbi.gov - Malware Targets Bank Accounts
abuse.ch - ZeuS Gets More Sophisticated Using P2P Techniques
cert.pl - ZeuS P2P+DGA variant mapping out and understanding the threat
|