[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Is my exit affected by a botnet?



hey folks.
 
i got an abuse-information from my provider, please see details attached.
could this propably be caused by some malware on my tor exit?
 
Any ideas on this?
 
Best,
volker
 
 

 

https://unity.abusehq.net/share/gFraliWxA_A-0uCFJvSxAkPRxYn536JoReAkl2MNUuCq3TNWJ8f4uXJVypwWAnVa

 

 

MAC Address               IP

f07959d25289             109.90.11.123

 

Date:

06.12.2016 11:16

 

Type:

bot-infection

 

Reporter:

security@xxxxxxxxxxxxxxxxx

 

IP address:

109.90.11.123

 

Incident part:

- malware family: virut

- destination ip: 148.81.111.121

- destination port: 80

- feeder: team cymru

- description: This host is most likely infected with malware.

 

Date:

05.12.2016 10:00

 

Type:

malware

 

Reporter:

reports@xxxxxxxxxxxxxxxxxxxx

 

IP address:

109.90.11.123

 

Incident part:

- malware: urlzone

- destination ip: 64.71.166.50

- destination port: 443

- destination hostname: didnadinka.net

- asn: 6830

 

Date:

02.12.2016 19:16

 

Type:

bot-infection

 

Reporter:

security@xxxxxxxxxxxxxxxxx

 

IP address:

109.90.11.123

 

Incident part:

- malware family: zeus

- destination ip: 87.106.18.112

- http request: /config

- destination port: 80

- destination domain name: mabqg.com

- feeder: shadowserver

- report type: botnet_drone

- description: This host is most likely infected with malware.

 

 

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
tor-relays mailing list
tor-relays@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays