@Peter (Atkin)

The link I shared specifically tracks Zeus NOT SpyEye!
Here is the link sent earlier: https://zeustracker.abuse.ch/index.php

And this is what I posted:
**************************************************************
Zeus is one of the most successful financial botnets in the history of
botnets.
Its very sophisticated and hard to detect let alone decisively deal with.
It was has been used to hit mainly financial institutions but the recent
trend is hitting any corporate organization.

Why should you worry?

There is a command and control (C&C) server in Rwanda and its been there
since last year.
https://zeustracker.abuse.ch/index.php
The ISP serving this server happens to be MTN Rwandacell.

Our UGCERT could start watching for any traffic terminating to that server
(IP: 41.186.24.58)  just in case that turns out to be the regional C&C .

For the CIOs, check your network logs just in case...

Cheers,

--
- Phillip.

****************************************************************


The links you have provided however track SpyEye and indeed there isn't any
SpyEye C&C on that server in Rwanda.

I think your were using looking for the wrong thing here...


-- 
- Phillip.

“Aoccdrnig to rscheearch at an Elingsh uinervtisy, it deosn't mttaer in waht
oredr the ltteers in a wrod are, the olny iprmoetnt tihng is taht the frist
and lsat ltteer are in the rghit pclae.
 The rset can be a toatl mses  and
you can sitll raed it wouthit a porbelm. Tihs is bcuseae we do not raed
ervey lteter by it slef but the wrod as a wlohe and the biran fguiers it
out aynawy."
_______________________________________________
The Uganda Linux User Group: http://linux.or.ug

Send messages to this mailing list by addressing e-mails to: [email protected]
Mailing list archives: http://www.mail-archive.com/[email protected]/
Mailing list settings: http://kym.net/mailman/listinfo/lug
To unsubscribe: http://kym.net/mailman/options/lug

The Uganda LUG mailing list is generously hosted by INFOCOM: 
http://www.infocom.co.ug/

The above comments and data are owned by whoever posted them (including 
attachments if any). The mailing list host is not responsible for them in any 
way.

Reply via email to