Noxiweb
16/09/2011, 20h35
Envoyé par fritz2cat
: host mx.scarlet.be[193.74.71.108] said: 550 5.7.1 message
p853i3ff025816 from 87.98.147.xx rejected: URL sip-plongee.be listed in
sbl.spamhaus.org -
http://www.scarlet.be/pm/?e=f22&p=21...p853i3ff025816 (in reply
to end of DATA command)
213.186.33.19/32 is listed on the Spamhaus Block List (SBL)
02-Sep-2011 20:46 GMT | SR29
ZeuS botnet controller @213.186.33.19 [hijacked website]
The host at this IP address is being used as a Command&Control Server (C&C) for the ZeuS Trojan.
ZeuS (also known as zbot/WSNPoem is a banking Trojan used to steal credentials for online banking accounts from the victims computer:
McAfee: http://vil.nai.com/vil/content/v_255218.htm
Symantec: http://www.symantec.com/security_res...011016-3514-99
$ dig projet-equinoxe.com +short @8.8.8.8
213.186.33.19
ZeuS C&C is located at 213.186.33.19:
IP Address : 213.186.33.19
AS number : AS16276
AS description : OVH OVH
projet-equinoxe.com has address 213.186.33.19
projet-equinoxe.com/skype.exe (binary)
More information about this malware:
MD5 hash: 598d633d0ebfcaf9cfef6ffb4dfa1ef4
-> Anubis: http://anubis.iseclab.org/?action=re...1b537e7657edef
More information on ZeuS Tracker
--------------------------------------------------------------------------------
Removal Procedure
To have record SBL116615 (213.186.33.19/32) removed from the SBL, the Abuse/Security representative of ovh.net (or the Internet Service Provider responsible for supplying connectivity to 213.186.33.19/32) needs to contact the SBL Team by email (use this link) to explain how the spam problem has been terminated (we need to know exactly how the issue has been dealt with and that this spam problem is fully terminated). If the spam problem that caused this listing has been terminated we will normally remove the listing from the SBL without delay.
It is essential that emails to the SBL Team about this SBL listing include this exact ticket information in the email Subject:
If you are a representative of ovh.net, you also need to see: Current Live ovh.net SBL Listings
--------------------------------------------------------------------------------
The SBL is an international anti-spam system maintained by The Spamhaus Project and used by Internet networks to protect users from spam sources and spam services. The SBL lists only IP addresses (not domains, email addresses, names or anything else). If you are unable to send email to someone due to this SBL listing, please contact your Internet Service Provider and show them this page - your Service Provider needs to contact the Spamhaus SBL team to resolve the issue (if you are not the Internet Service Provider, please do not contact us.)