<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
	<title>Comments for abuse.ch</title>
	
	<link>http://www.abuse.ch</link>
	<description>The Swiss Security Blog</description>
	<lastBuildDate>Fri, 07 Jun 2013 18:38:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/CommentsForAbusech" /><feedburner:info uri="commentsforabusech" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Comment on How Big is Big? Some Botnet Statistics by Collateral Damage: Microsoft Hits Security Researchers along with Citadel | abuse.ch</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/Z4Yt6OdsA8M/</link>
		<dc:creator>Collateral Damage: Microsoft Hits Security Researchers along with Citadel | abuse.ch</dc:creator>
		<pubDate>Fri, 07 Jun 2013 18:38:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=3294#comment-670440</guid>
		<description><![CDATA[[...] in researching botnets in my spare time, and abuse.ch is running such a sinkhole as well (in fact for years). The goal is simple: sinkhole malicious botnet domains (not only limited to any specific Trojan / [...]]]></description>
		<content:encoded><![CDATA[<p>[...] in researching botnets in my spare time, and abuse.ch is running such a sinkhole as well (in fact for years). The goal is simple: sinkhole malicious botnet domains (not only limited to any specific Trojan / [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/Z4Yt6OdsA8M" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=3294&amp;cpage=1#comment-670440</feedburner:origLink></item>
	<item>
		<title>Comment on Massive Drop in Number of Active Zeus C&amp;C Servers by Koobface Worm Doubles C&amp;C Servers in 48 Hours | Threatpost</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/fxijYxu836g/</link>
		<dc:creator>Koobface Worm Doubles C&amp;C Servers in 48 Hours | Threatpost</dc:creator>
		<pubDate>Thu, 02 May 2013 21:07:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=2417#comment-601707</guid>
		<description><![CDATA[[...] Yesterday&#8217;s shut down of Troyak-as was definitely good news for the whole IT security community. Seeing cybercriminals getting kicked out from the Internet and then trying to get back inside calls for popcorn and soda. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Yesterday&#8217;s shut down of Troyak-as was definitely good news for the whole IT security community. Seeing cybercriminals getting kicked out from the Internet and then trying to get back inside calls for popcorn and soda. [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/fxijYxu836g" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=2417&amp;cpage=1#comment-601707</feedburner:origLink></item>
	<item>
		<title>Comment on How Big is Big? Some Botnet Statistics by [WIP] Virus, antivirus: què són? Explicacions humanes | Construïnt Idees</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/v2Cutly9qtE/</link>
		<dc:creator>[WIP] Virus, antivirus: què són? Explicacions humanes | Construïnt Idees</dc:creator>
		<pubDate>Fri, 19 Apr 2013 15:43:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=3294#comment-571517</guid>
		<description><![CDATA[[...] La indústria del malware mou més diners que la indústria de les armes, l&#8217;autèntica mafia està posada al dia, i la majoria dels sysadmins no, i les botnets són immenses. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] La indústria del malware mou més diners que la indústria de les armes, l&#8217;autèntica mafia està posada al dia, i la majoria dels sysadmins no, i les botnets són immenses. [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/v2Cutly9qtE" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=3294&amp;cpage=1#comment-571517</feedburner:origLink></item>
	<item>
		<title>Comment on Scareware Locks Down Computer Due To Child Porn and Terrorism by Por el mundo tras el virus con placa - El periódico de hoy : El periódico de hoy</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/wHH2g4vLr6g/</link>
		<dc:creator>Por el mundo tras el virus con placa - El periódico de hoy : El periódico de hoy</dc:creator>
		<pubDate>Tue, 26 Mar 2013 21:58:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=3610#comment-548024</guid>
		<description><![CDATA[[...] hasta casa. La dirección IP contaminante sobre la que comenzó a trabajar el investigador era la 188.190.99.174, que localizó en Ucrania. Pero la banda se movía a una velocidad tremenda cambiando de servidores [...]]]></description>
		<content:encoded><![CDATA[<p>[...] hasta casa. La dirección IP contaminante sobre la que comenzó a trabajar el investigador era la 188.190.99.174, que localizó en Ucrania. Pero la banda se movía a una velocidad tremenda cambiando de servidores [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/wHH2g4vLr6g" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=3610&amp;cpage=1#comment-548024</feedburner:origLink></item>
	<item>
		<title>Comment on Massive Drop in Number of Active Zeus C&amp;C Servers by Koobface Worm Doubles C&amp;C Servers in 48 Hours | Threatpost</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/IHncN1dlEZU/</link>
		<dc:creator>Koobface Worm Doubles C&amp;C Servers in 48 Hours | Threatpost</dc:creator>
		<pubDate>Mon, 25 Mar 2013 01:25:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=2417#comment-546635</guid>
		<description><![CDATA[[...] Yesterday&#8217;s&#160;shut down of Troyak-as was definitely good news for the whole IT security community. Seeing cybercriminals getting kicked out from the Internet and then trying to get back inside calls for popcorn and soda. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Yesterday&#8217;s&nbsp;shut down of Troyak-as was definitely good news for the whole IT security community. Seeing cybercriminals getting kicked out from the Internet and then trying to get back inside calls for popcorn and soda. [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/IHncN1dlEZU" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=2417&amp;cpage=1#comment-546635</feedburner:origLink></item>
	<item>
		<title>Comment on Cybercriminals Moving Over To TLD .su by More Prominent Credit Reports Leaked As Agencies Explain How Hackers Did It | Elexonic.com | Breaking News</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/-1s_O4fOX6U/</link>
		<dc:creator>More Prominent Credit Reports Leaked As Agencies Explain How Hackers Did It | Elexonic.com | Breaking News</dc:creator>
		<pubDate>Thu, 21 Mar 2013 17:38:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=3581#comment-544589</guid>
		<description><![CDATA[[...] has the Soviet Union&#8217;s.su country code, a domain originally created in 1990 that has beenincreasingly used by cybercriminals.The website&#8217;s Twitter page (now suspended) contained what Russia Today called &#8220;bad [...]]]></description>
		<content:encoded><![CDATA[<p>[...] has the Soviet Union&#8217;s.su country code, a domain originally created in 1990 that has beenincreasingly used by cybercriminals.The website&#8217;s Twitter page (now suspended) contained what Russia Today called &#8220;bad [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/-1s_O4fOX6U" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=3581&amp;cpage=1#comment-544589</feedburner:origLink></item>
	<item>
		<title>Comment on Fake Swisscom And T-Mobile Emails Hitting CH and DE by Fake hotel.de Booking Emails Hitting CH and DE | abuse.ch</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/ADFItK4SiYY/</link>
		<dc:creator>Fake hotel.de Booking Emails Hitting CH and DE | abuse.ch</dc:creator>
		<pubDate>Mon, 18 Mar 2013 09:47:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=5193#comment-541676</guid>
		<description><![CDATA[[...] &#171; Fake Swisscom And T-Mobile Emails Hitting CH and DE [...]]]></description>
		<content:encoded><![CDATA[<p>[...] &laquo; Fake Swisscom And T-Mobile Emails Hitting CH and DE [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/ADFItK4SiYY" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=5193&amp;cpage=1#comment-541676</feedburner:origLink></item>
	<item>
		<title>Comment on Delta Airlines Spam Lead To Citadel by Se upp för hemsidor som är infekterade med zeroaccess och citadel | bredbandsbloggen</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/iCfVdUHNqVY/</link>
		<dc:creator>Se upp för hemsidor som är infekterade med zeroaccess och citadel | bredbandsbloggen</dc:creator>
		<pubDate>Sat, 23 Feb 2013 11:22:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=5075#comment-522612</guid>
		<description><![CDATA[[...] identitet och kamouflerar sig som vanlig användare med smartphone) och wannafind.dk. Se mer på delta airlines, black-list, Free Email Blacklist Check Se till att du har uppdaterat din Flashplayer och Java. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] identitet och kamouflerar sig som vanlig användare med smartphone) och wannafind.dk. Se mer på delta airlines, black-list, Free Email Blacklist Check Se till att du har uppdaterat din Flashplayer och Java. [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/iCfVdUHNqVY" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=5075&amp;cpage=1#comment-522612</feedburner:origLink></item>
	<item>
		<title>Comment on Dutch Spam Campaign Hits Switzerland With P2P ZeuS by Jay</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/yaIC2n8IJZQ/</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Mon, 04 Feb 2013 14:14:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=4990#comment-508384</guid>
		<description><![CDATA[Hi,

Even the dutch in the email is wrong, seems they used google translator or something like that.]]></description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Even the dutch in the email is wrong, seems they used google translator or something like that.</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/yaIC2n8IJZQ" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=4990&amp;cpage=1#comment-508384</feedburner:origLink></item>
	<item>
		<title>Comment on Dutch Spam Campaign Hits Switzerland With P2P ZeuS by Ole bin login</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/SzeTkfmcoWc/</link>
		<dc:creator>Ole bin login</dc:creator>
		<pubDate>Tue, 22 Jan 2013 20:27:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=4990#comment-489725</guid>
		<description><![CDATA[There is a primary controller to this bot located in russia.  I have removed many hosts from the network I secure this past fall and this one controller keeps attempting connections to those previously infected bots.  If someone from abuse.ch would like to contact me I will provide the IP to you.  

ole.]]></description>
		<content:encoded><![CDATA[<p>There is a primary controller to this bot located in russia.  I have removed many hosts from the network I secure this past fall and this one controller keeps attempting connections to those previously infected bots.  If someone from abuse.ch would like to contact me I will provide the IP to you.  </p>
<p>ole.</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/SzeTkfmcoWc" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=4990&amp;cpage=1#comment-489725</feedburner:origLink></item>
	<item>
		<title>Comment on ZeuS Gets More Sophisticated Using P2P Techniques by Detecting P2P Botnets with NetFlow (Part #1) - NetFlowKnights.com - NetFlow &amp; sFlow Network Monitoring - NetFlowKnights.com</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/HBSy6zVpdLQ/</link>
		<dc:creator>Detecting P2P Botnets with NetFlow (Part #1) - NetFlowKnights.com - NetFlow &amp; sFlow Network Monitoring - NetFlowKnights.com</dc:creator>
		<pubDate>Wed, 12 Dec 2012 00:09:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=3499#comment-421335</guid>
		<description><![CDATA[[...] services and other black-listing technology. While many botnets still use a traditional C2, a new breed of botnet has emerged that removes the need for a C2. These botnets make use of peer-to-peer technology to [...]]]></description>
		<content:encoded><![CDATA[<p>[...] services and other black-listing technology. While many botnets still use a traditional C2, a new breed of botnet has emerged that removes the need for a C2. These botnets make use of peer-to-peer technology to [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/HBSy6zVpdLQ" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=3499&amp;cpage=1#comment-421335</feedburner:origLink></item>
	<item>
		<title>Comment on A Quick Update On Spambot Kelihos by ‘Neergehaald’ botnet Kelihos sterker dan ooit | Tech-nieuws</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/NNeneeWoips/</link>
		<dc:creator>‘Neergehaald’ botnet Kelihos sterker dan ooit | Tech-nieuws</dc:creator>
		<pubDate>Mon, 10 Dec 2012 16:36:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=4878#comment-419680</guid>
		<description><![CDATA[[...] beveiligingsonderzoeker Roman Huessy verzendt Kelihos op dit moment dagelijks spam via 100.000 tot 150.000 unieke IP-adressen. De bende achter het botnet heeft gaandeweg dit jaar [...]]]></description>
		<content:encoded><![CDATA[<p>[...] beveiligingsonderzoeker Roman Huessy verzendt Kelihos op dit moment dagelijks spam via 100.000 tot 150.000 unieke IP-adressen. De bende achter het botnet heeft gaandeweg dit jaar [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/NNeneeWoips" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=4878&amp;cpage=1#comment-419680</feedburner:origLink></item>
	<item>
		<title>Comment on Phishing eBanking Credentials Using Web-Proxies by Is my webserver being abused for banking fraud? - Admins Goodies</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/dbGrnw6knm8/</link>
		<dc:creator>Is my webserver being abused for banking fraud? - Admins Goodies</dc:creator>
		<pubDate>Sun, 02 Dec 2012 17:29:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=2925#comment-409593</guid>
		<description><![CDATA[[...] The strange thing is that all these domains are domains of banks and 3 out of the 4 domains are also in the list of the bank frauding scheme described on: http://www.abuse.ch/?p=2925 [...]]]></description>
		<content:encoded><![CDATA[<p>[...] The strange thing is that all these domains are domains of banks and 3 out of the 4 domains are also in the list of the bank frauding scheme described on: <a href="http://www.abuse.ch/?p=2925">http://www.abuse.ch/?p=2925</a> [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/dbGrnw6knm8" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=2925&amp;cpage=1#comment-409593</feedburner:origLink></item>
	<item>
		<title>Comment on ZeuS Gets More Sophisticated Using P2P Techniques by ?????? ??? ?????? - ????? ??????? | Newsgeek</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/aDiw5vBjvjs/</link>
		<dc:creator>?????? ??? ?????? - ????? ??????? | Newsgeek</dc:creator>
		<pubDate>Tue, 09 Oct 2012 10:15:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=3499#comment-345872</guid>
		<description><![CDATA[[...] ??? ?????? &quot;???? ?????&quot; (Peer-to-Peer, P2P) ??????? ??? ??? ???? ???? ??????. ?? ???? ???? ?? ??????? ??????? ??? ?? ?? ?????? ?? [...]]]></description>
		<content:encoded><![CDATA[<p>[...] ??? ?????? &quot;???? ?????&quot; (Peer-to-Peer, P2P) ??????? ??? ??? ???? ???? ??????. ?? ???? ???? ?? ??????? ??????? ??? ?? ?? ?????? ?? [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/aDiw5vBjvjs" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=3499&amp;cpage=1#comment-345872</feedburner:origLink></item>
	<item>
		<title>Comment on Ransomware Gets Professional, Targeting Switzerland, Germany And Austria by Policie ?R vás sleduje! « VIRY.CZ</title>
		<link>http://feedproxy.google.com/~r/CommentsForAbusech/~3/GZ359VUZ6Ao/</link>
		<dc:creator>Policie ?R vás sleduje! « VIRY.CZ</dc:creator>
		<pubDate>Fri, 05 Oct 2012 13:00:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.abuse.ch/?p=3718#comment-342346</guid>
		<description><![CDATA[[...] Disorderly conduct: localized malware impersonates the police Ransomware Gets Professional, Targeting Switzerland, Germany And Austria [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Disorderly conduct: localized malware impersonates the police Ransomware Gets Professional, Targeting Switzerland, Germany And Austria [...]</p>
<img src="http://feeds.feedburner.com/~r/CommentsForAbusech/~4/GZ359VUZ6Ao" height="1" width="1"/>]]></content:encoded>
	<feedburner:origLink>http://www.abuse.ch/?p=3718&amp;cpage=1#comment-342346</feedburner:origLink></item>
</channel>
</rss>
