Page 1 of 1

ABUSE Report after installing SoftEther VPN

Posted: Tue Mar 05, 2019 8:52 am
by foobyte
We installed the SoftEther VPN to one of our dedicated servers which is hosted in a datacenter. Shortly after, our datacenter informed us, that our system is infected with malware because it attempted the following connection:

"asn","ip","timestamp","malware","src_port","dst_ip","dst_port","dst_host","proto"
"8972","x.x.x.x","2019-02-21 02:45:41","zeus","64125","216.218.135.114","443","extrimtriptoislands.com","tcp"

The server was a clean installation, nothing other than the SoftEther VPN was installed.
The executable was downloaded from softether.org

Do you have an insight on why this is happening?
I know that my co worker seems to have activated to participant in the acadamic research project but even after deactivated it again, the ABUSE reports still keep coming in. Our provider is not happy about this and wants to cancel the contract...