CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Proactive Alerts: Am I a bot?

 
Post new topic   Reply to topic       All -> FavForums -> Happy Events [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Jan 30, 2008 7:43 pm    Post subject: Proactive Alerts: Am I a bot?
Reply with quote

Quote:
Welcome to CastleCops®. Your IP address [x] matches our records for possible malicious activity observed on the Internet at 2008-01-27 08:03:36 UTC. If that IP address belonged to you, then we suggest you follow our Malware Removal and Prevention Procedures. If not, then this alert may not affect you. Contact administration to have the alert removed. This notice is in cooperation with {organization}, whose records are kept here in confidence at CastleCops.


So we're teamed up with a few organizations and the idea materialized that we could use botnet data, etc, stored locally here at CastleCops and compare that to visitor IPs. All IP information stays on site. If your IP has been seen to conduct malicious activity on the Internet, we'll let you know. Here is what the current alert looks like (attached below).

Depending on the organization we're partnering to do this with, there may be a link to their site explaining in detail what was seen. For all alerts, we suggest stepping through our Malware Removal Prevention procedure:

http://wiki.castlecops.com/MRP

The IP list in its entirety will not be re-published here.

We're always looking to improve how we can make the world a better place, so feedback is always appreciated.

Thank you everyone.

Back to top
View users profile Send private message Send email Visit posters website
Mister2

SRT Team Lead
SRT Team Lead
Premium Member

Joined: Oct 28, 2004
Posts: 7329

Moderators MVP Premium SRT Team F@H

PostPosted: Wed Jan 30, 2008 7:59 pm    Post subject:
Reply with quote

That would be a great help to both site and visitor, and it sits well with the line below the notice:

Quote:
making the world a better place


I wonder if we should set up a separate forum solely for the purpose of requesting removal of an alert - either false alarms or after cleanup through MRP? Just thinking of the workload on Admin. Smile


_________________
Never stop learning
Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Jan 30, 2008 8:06 pm    Post subject:
Reply with quote

Sounds good to me, perhaps the MRP should reflect this new service?


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Cudni

Special Response Team


Joined: Dec 10, 2002
Posts: 3717
Location: Et In Arcadia ego
MIRT MVP SRT

PostPosted: Wed Jan 30, 2008 8:13 pm    Post subject:
Reply with quote

This sounds like a great service to the community, could there be a little note or a link to explain how to establish or what it means that an ip address belongs to somebody?

Cudni


_________________
Hecho en Mexico
Back to top
View users profile Send private message Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Jan 30, 2008 8:46 pm    Post subject:
Reply with quote

Absolutely. Perhaps that is something else that can be kept at the wiki which we can link to. Cudni you want to start that up?


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Cudni

Special Response Team


Joined: Dec 10, 2002
Posts: 3717
Location: Et In Arcadia ego
MIRT MVP SRT

PostPosted: Wed Jan 30, 2008 9:43 pm    Post subject:
Reply with quote

sure, i'll draft something up Smile

may we know what other organisation CC teamed up, or is that planned for later when links are established?

Cudni


_________________
Hecho en Mexico
Back to top
View users profile Send private message Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Jan 30, 2008 10:10 pm    Post subject:
Reply with quote

That is planned for later, the disclosure.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
blacklupine

Captain
Captain
Premium Member

Joined: Mar 17, 2005
Posts: 484
Location: Over The Hills And Far Away!
Premium

PostPosted: Fri Feb 08, 2008 10:22 pm    Post subject:
Reply with quote

Should you include an explanation as to the difference between a static and a dynamic IP address? Was thinking about visitors with a dynamic IP address who could get warnings relating to their current IP which had been used by another infected computer prior to them. They would then be under the impression that their computer was infected.

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Sun Feb 24, 2008 12:00 am    Post subject:
Reply with quote

This service was suspended about 1.5 weeks ago during the whole perf crisis. I hope to re-establish this soon as next week.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Tue Mar 11, 2008 5:43 pm    Post subject:
Reply with quote

This was re-enabled about a week ago partially.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
johnlgalt

Special Response Team
Premium Member

Joined: Feb 27, 2007
Posts: 1419

Premium SRT

PostPosted: Wed Mar 12, 2008 12:20 am    Post subject:
Reply with quote

Excellent - and I hope I *never* have to see tis message on any computer / network that I work on....

Of course, it will also help me work on said computers and networks - if I ever *do* see that message, the things come down and the cleaning begins.


_________________
<img src="http://www.castlecops.com/zx/johnlgalt/johnlgalt%20sig.png">

<img src="http://www.castlecops.com/zx/johnlgalt/John%20L.%20Galt%20%20CPU-Z.png">
Back to top
View users profile Send private message Visit posters website Yahoo Messenger MSN Messenger
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Fri Mar 14, 2008 6:31 pm    Post subject:
Reply with quote

Re-activated for Shadowserver Foundation.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Sat Mar 22, 2008 11:42 pm    Post subject:
Reply with quote

I have added a list from the SANS Internet Storm Center now.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Paul

CastleCops Founder


Joined: Feb