[tor-relays] Pony C&C

Yoriz tor at privshield.com
Sun Sep 1 19:43:14 UTC 2013


I have been running a Tor exit node for only 2 days on a fresh IP address. However, that IP address is now blocked by spamhaus because it apparently tried to contact the Command and Control server of the "pony" malware:

http://cbl.abuseat.org/lookup.cgi?ip=5.79.81.200

Other node operators, could you please try your IP address? Perhaps this could explain the recent increase in connections?

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 496 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <http://lists.torproject.org/pipermail/tor-relays/attachments/20130901/a598bc42/attachment.sig>


More information about the tor-relays mailing list