(no title)
jschuur | 6 years ago
I run macOS only and as far as I can tell Nymaim is Windows only. Still, I ran an malware scan on my Macbooks and nothing popped up, so I'm pretty sure nothing infected my devices.
Still, I wonder if I ended up hitting the sinkhole, Virgin was somehow notified and this triggered their email? Or maybe it's just a complete coincidence.
Edit: Sure looks like Virgin works with Shadowserver: https://www.ukfast.co.uk/it-security-news/virgin-media-to-in...
hsivonen|6 years ago
Although my server wasn't infected, it had connected to a Shadowserver sinkhole.
While it's good that there are folks who work to sinkhole botnets, the next step of accusing others of being infected based of what the sinkhole sees needs more care. I'm disappointed that, evidently, my expression of these concerns to the German authorities three years ago hasn't lead to a substantial change at the Shadowserver end.
As can be seen from your case (and mine), you can get blamed even if the software at your end of the connection wasn't the botnet software. Considering how a basic premise of the Web is that it's safe to dereference a URL and everyone runs software that does so (Web browsers!), it's a bad idea that Shadowserver doesn't require a narrower indicator of compromise.
There'd be less chance of folks weaponising this system against bystanders by framing them as botnet-infected if the Shadowserver Foundation sinkhole required the other end of the connection to exhibit more specific hallmarks of the botnet software.
rkangel|6 years ago
I'm unaware of this particular international cooperation arrangement but it's great to see.
jschuur|6 years ago
mlindner|6 years ago