Hello,
We have web service. For the last month, some web-spammers are registered fake accounts on our system. They programmed a robot that automatically create accounts on our website. Registration need mail validation. (I think) they also programmed a robot for Hotmail and Gmail. They automatically create Hotmail accounts and register account with us, then they receive the validation information from mails we sent to their Hotmail address. Because of this robot attack, we start to send about 10.000 mails a day to Hotmail. After I realize the attack, I wrote some code to our website and disabled this attack. They can't open accounts now.
However, (I think because of the bulk validation mails) Hotmail and Yahoo added our IP address to blacklist.
Spamhaus says that we're in CBL. I queried our IP and this message is shown:
Only port 25, 53, 80, 443 is open for our servers.
We have postfix, courrier and cyrus installed.
I searched for Torpig but I couldn't find detailed information. But I think that it's a Windows trojan. I can't find any information for Torpig & FreeBSD.
Wikipedia says Torpig is installed on MBR.
Our mail server is in FreeBSD jail. And don't have a MBR.
All of our ports are up to date.
I'm not sure about whether if our mail server is really infected with Torpig trojan, or the blacklists thought that it's a trojan because of the rise at the mails we sent.
I'm waiting help from you.
If it's not about a trojan, if it's about the bulk mails because of the validation-mails I will be happy.
Thank you for your time.
We have web service. For the last month, some web-spammers are registered fake accounts on our system. They programmed a robot that automatically create accounts on our website. Registration need mail validation. (I think) they also programmed a robot for Hotmail and Gmail. They automatically create Hotmail accounts and register account with us, then they receive the validation information from mails we sent to their Hotmail address. Because of this robot attack, we start to send about 10.000 mails a day to Hotmail. After I realize the attack, I wrote some code to our website and disabled this attack. They can't open accounts now.
However, (I think because of the bulk validation mails) Hotmail and Yahoo added our IP address to blacklist.
Spamhaus says that we're in CBL. I queried our IP and this message is shown:
This IP is infected with, or is NATting for a machine infected with Torpig, also known by Symantec as Anserin.
This was detected by observing this IP attempting to make contact to a Torpig Command and Control server at 91.20.214.119, with contents unique to Torpig C&C command protocols.
Only port 25, 53, 80, 443 is open for our servers.
We have postfix, courrier and cyrus installed.
I searched for Torpig but I couldn't find detailed information. But I think that it's a Windows trojan. I can't find any information for Torpig & FreeBSD.
Wikipedia says Torpig is installed on MBR.
Our mail server is in FreeBSD jail. And don't have a MBR.
All of our ports are up to date.
I'm not sure about whether if our mail server is really infected with Torpig trojan, or the blacklists thought that it's a trojan because of the rise at the mails we sent.
I'm waiting help from you.
If it's not about a trojan, if it's about the bulk mails because of the validation-mails I will be happy.
Thank you for your time.