<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; botnet</title>
	<atom:link href="http://blog.mxlab.eu/tag/botnet/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; botnet</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Rustock is back online, spam levels rise again</title>
		<link>http://blog.mxlab.eu/2008/11/25/rustock-is-back-online-spam-levels-rise-again/</link>
		<comments>http://blog.mxlab.eu/2008/11/25/rustock-is-back-online-spam-levels-rise-again/#comments</comments>
		<pubDate>Tue, 25 Nov 2008 09:09:48 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[mccolo]]></category>
		<category><![CDATA[Rustock]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=293</guid>
		<description><![CDATA[UPDATE, Nov 27th: One of the new CnC servers, &#8216;sdx3Fs5B.info&#8217; was resolving to 72.233.114.74 at LayeredTech. FireEye sent an abuse notification to LayeredTech when the CnC servers went online and they have pulled out the server. &#8212;&#8212;&#8212;&#8212;&#8212;- Yesterday, Nov 24, 2008, I noticed a sudden spam rise. When checking some samples I found that the &#8216;Canadian Pharmacy&#8217; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=293&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>UPDATE, Nov 27th: One of the new CnC servers, &#8216;sdx3Fs5B.info&#8217; was resolving to 72.233.114.74 at LayeredTech. FireEye sent an abuse notification to LayeredTech when the CnC servers went online and they have pulled out the server.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>Yesterday, Nov 24, 2008, I noticed a sudden spam rise. When checking some samples I found that the &#8216;Canadian Pharmacy&#8217; spam is back and some new image based spam campaigns have been launched.</p>
<p>But the &#8216;Canadian Pharmacy&#8217; spam is where we should focus on. These spam campaigns are being sent by Rustock, so the conclusion is that these guys are back online and in business.</p>
<p>With subjects like Obama.s new plan, Food crisis in California or Bush.s last words they try to get their email opened to see the &#8216;Canadian Pharmacy&#8217; advertisment. URLs, like hxxp://alsi.kugusup.cn or hxxp://ppbka.kugusup.cn will redirect you to hxxp://beautythrow.com/ where the Canadian Pharmacy web site is hosted.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20081125_rustock_is_back.jpg" alt="" width="440" height="393" /></p>
<p>When looking for more information if Rustock is back I found that the Company FireEye Security has posted more details <a href="http://blog.fireeye.com/research/2008/11/rustock-selling-pills-again.html" target="_blank">on their blog</a>.</p>
<p>As expected, the bot admins learned from the shut down of McColo. They can now simply change DNS to make sure that their command and control server still can be accessed.</p>
<p>The new Rustock spam campaign is already having an impact on the spam levels. The image below is the graph for one of my domains and you can see the spam level drop when McColo was taken down. The red line is the global spam level.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20081125_rustock_is_back_2.jpg" alt="" width="440" height="122" /></p>
<p>We have a peak during the weekend, the absence of business emails, and a global spam level between 75% and 85% during the week. Yesterday we had a spam level of 89,4% and at the time of writting this article we are back at 93%. You can see the graph going up again after the re-activation of the Rustock C&amp;C servers.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/293/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=293&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/11/25/rustock-is-back-online-spam-levels-rise-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20081125_rustock_is_back.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20081125_rustock_is_back_2.jpg" medium="image" />
	</item>
		<item>
		<title>McColo up and down again, C&amp;C servers to Russia</title>
		<link>http://blog.mxlab.eu/2008/11/17/mccolo-up-and-down-again-cc-servers-to-russia/</link>
		<comments>http://blog.mxlab.eu/2008/11/17/mccolo-up-and-down-again-cc-servers-to-russia/#comments</comments>
		<pubDate>Mon, 17 Nov 2008 11:21:14 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[McColo Corp]]></category>
		<category><![CDATA[Rustock]]></category>
		<category><![CDATA[zombie]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=288</guid>
		<description><![CDATA[McColo, the ISP that has been taken down because of their malicious activities, was back online during a brief period thanks to the Swedish ISP TeliaSonara AB that has a router in San Jose. The peering was revoked after complaints to the abuse email address by security from Sophos and security researcher Atif Mushtaq. During this time Rustock [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=288&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>McColo, the ISP that has been taken down because of their malicious activities, was back online during a brief period thanks to the Swedish ISP TeliaSonara AB that has a router in San Jose. The peering was revoked after complaints to the abuse email address by <a href="http://www.sophos.com/security/blog/2008/11/1995.html?_log_from=rss" target="_blank">security from Sophos</a> and security researcher <a href="http://blog.fireeye.com/research/2008/11/mccolo-up-again.html" target="_blank">Atif Mushtaq</a>.</p>
<p>During this time Rustock admins did had time to update the Command And Control server with an IP of 208.66.194.22 at McColo to a <a href="http://blog.fireeye.com/research/2008/11/rustocks-new-home.html" target="_blank">new host in Russia</a>.</p>
<p>With the takedown of McColo the drop of spam volumes worldwide is still continuing but as we can see the botnet admins are gettings thing up and running again. It is my belief that sooner or later, perhaps sooner, the spam levels will rise again and tradionally the end of the year is very attractive for spammers.</p>
<p>The botnet admins will learn a lesson of this and make their systems more redundant with fall back servers and we could even see systems where the centralized Command And Control server is replaced by a structure more based on P2P. Taking down the command center will become more difficult.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/288/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/288/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/288/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/288/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/288/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/288/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/288/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/288/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/288/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/288/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=288&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/11/17/mccolo-up-and-down-again-cc-servers-to-russia/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Spam drops after McColo Corp taken offline</title>
		<link>http://blog.mxlab.eu/2008/11/13/spam-drops-after-mccolo-corp-taken-offline/</link>
		<comments>http://blog.mxlab.eu/2008/11/13/spam-drops-after-mccolo-corp-taken-offline/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 14:55:56 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Various]]></category>
		<category><![CDATA[Atrivo]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Intercage]]></category>
		<category><![CDATA[McColo Corp]]></category>
		<category><![CDATA[Security Fix]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=282</guid>
		<description><![CDATA[SMTP connections that involves spam have dropped 50% at MX Lab since yesterday. At first, we thought we faced a technical problem and all systems where checked to be sure but there where less SMTP conenctions that contained spam. Today we still noticed a very low level of spam volume. Several news sites report that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=282&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>SMTP connections that involves spam have dropped 50% at MX Lab since yesterday. At first, we thought we faced a technical problem and all systems where checked to be sure but there where less SMTP conenctions that contained spam. Today we still noticed a very low level of spam volume.</p>
<p>Several news sites report that the San-Jose, California, US based hosting firm McColo Corp. has been taken offline when its primary Internet providers severed its connection to the web.</p>
<p>McColo&#8217;s clients included cybercriminal groups that ran some of the biggest spam-spewing and malware-spreading botnets. McColo hosts the botnet command-and-control servers (Rustock, Srizbi, Pushdo/Cutwail, Ozdok/Mega-D and Gheg)  as well as other systems that ran malware distribution points and criminal payment services. McColo could be responsible for approx. 75% of all the spam traffic according to several sources.</p>
<p>Security Fix has gathered data about the activities of McColo over the past four months and has handed over some critical information towards the ISPs that offer the internet connection for McColo.</p>
<p><strong><span style="font-weight:normal;">Hurricane Electric</span></strong>, one of the major Internet providers for McColo, has shut down the internet connection towards the hosting provider within the hour.</p>
<p>In September another U.S.-based hosting service Intercage, also active under the name Atrivo, suspected of harboring spammers was shut down. Within three days, the dip had disappeared as others stepped in. So it is expected that the spam level will return to its usual levels within the next few days.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/282/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=282&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/11/13/spam-drops-after-mccolo-corp-taken-offline/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>