[nsp-sec] spyeye infected drones

Serge Droz serge.droz at switch.ch
Fri Mar 18 06:21:44 EDT 2011


ACK ASN 559, 15600, 21040, 21232, 15623, 39544, 41549, 25375, 8404, 15517,
1836, 31736, 21466, 39440, 8821, 8803, 12350, 50609, 8758, 34781, 6730, 15547,
12620, 29201, 39640, 44885, 24889, 9044, 31662, 6772, 41715, 41872, 13030, 44147

If any of these are on the list, please contact me directly
Serge

On 17/3/11 15:18, Dirk Stander wrote:
> ----------- nsp-security Confidential --------
> 
> 
> 
> 
> Hi Teams,
> 
> please find attached a list of drones, which contacted one of the
> domains mentioned here:
> http://ddanchev.blogspot.com/2011/03/more-spamvertised-dhl-notifications.html
> 
> The drones are using a unique User-Agent string, "Opera/10.80 Pesto/2.2.30"
> 
> The format of the list is:
> ASN | IP | CC | date first seen 
> 
>     kind regards, Dirk Stander (1&1 Internet AG) :.
> 
> 
> 
> 
> 
> _______________________________________________
> nsp-security mailing list
> nsp-security at puck.nether.net
> https://puck.nether.net/mailman/listinfo/nsp-security
> 
> Please do not Forward, CC, or BCC this E-mail outside of the nsp-security
> community. Confidentiality is essential for effective Internet security counter-measures.
> _______________________________________________

-- 
SWITCH
Serving Swiss Universities
--------------------------
Serge Droz, SWITCH-CERT
Werdstrasse 2, P.O. Box, 8021 Zurich, Switzerland
phone +41 44 268 15 63, fax +41 44 268 15 78
serge.droz at switch.ch, http://www.switch.ch



More information about the nsp-security mailing list