Вложений: 1
Вычислить зараженный компьютер в сети, который рассылает вирус
У меня стоит Kerio Mail Server 6.7.3
C недавнего времени мой внешний IP занесли три раза в BlackList CBL [url]http://www.abuseat.org/[/url]
Причина занесения вирус Ranybus. Как вычислить на каком ПК сидит зараза или откуда извне проникает злоумышленник.
Вот письмо о внесении в блэк лист. Во вложении лог с произвольного компьютера в сети (моего)
[COLOR=#000000][FONT=georgia]P Address 85.234.125.14 [B]is listed[/B] in the CBL. It shows signs of being infected with a spam sending trojan, malicious link or some other form of botnet.[/FONT][/COLOR]
[COLOR=#000000][FONT=georgia]It was last detected at 2016-12-13 11:00 GMT (+/- 30 minutes), approximately 1 days, 14 hours, 30 minutes ago.[/FONT][/COLOR]
[COLOR=#000000][FONT=georgia]It has been relisted following a previous removal at 2016-12-12 06:43 GMT (2 days, 19 hours, 15 minutes ago)[/FONT][/COLOR]
[COLOR=#000000][FONT=georgia]Perhaps the person who previously removed it didn't actually fix the problem.[/FONT][/COLOR]
[SIZE=+1][COLOR=#000000][FONT=georgia]This IP is infected with, or is NATting for a machine infected with s_ranbyus
Note: If you wish to look up this bot name via the web, remove the "s_" before you do your search.
This was detected by observing this IP attempting to make contact to a s_ranbyus Command and Control server, with contents unique to s_ranbyus C&C command protocols.
This detection corresponds to a connection at 2016-12-13 11:19:26 (GMT - this timestamp is believed accurate to within one second).
These infections are rated as a "severe threat" by Microsoft. It is a trojan downloader, and can download and execute ANY software on the infected computer.
You will need to find and eradicate the infection before delisting the IP address.
[/FONT][/COLOR][/SIZE]