Solved

how to find the trojan or botnet

Posted on 2013-06-20
2
1,136 Views
Last Modified: 2013-06-20
Hi Experts,

I have seen our IP address is listed at CBL and we cannot send emails with our domain.
Do you know a way how to repair this and find the trojan or bot net ?

 This was detected by a TCP/IP connection from 85.125.249.50 on port 50429 going to IP address 82.165.37.26 (the sinkhole) on port 80.

The botnet command and control domain for this connection was "uwet35fsd.in".
0
Comment
Question by:Eprs_Admin
2 Comments
 
LVL 22

Accepted Solution

by:
David Atkin earned 500 total points
ID: 39261734
How  many PC's do you have?

Check your router/firewall to see if you can see what internal IP addresses are connecting to the external address.

Check to see what PC's are sending emails by looking at the firewall connections or by doing a netstat -a on the PC's (look for lots of port 25 connections)

Make sure your server is not an internal relay by using the mxtoolbox.com SMTP test.
0
 

Author Comment

by:Eprs_Admin
ID: 39262498
thanks a lot.
the tool is very helpful.
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Suggested Solutions

Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This video discusses moving either the default database or any database to a new volume.

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now