Skip to navigation
   
Davey Winder's Blog

Six bots deliver 85 percent of your spam

By Davey Winder in Editorial

Posted in Blog, Spam on February 29, 2008 at 9:47 am

Permalink | Author Profile

Ever wondered where all your spam comes from? The Marshal TRACE team reckon they have found out, and the answer is pretty much a total of just six botnets. Indeed, Marshal reports that these six botnets account for the distribution of a staggering 85 percent of all spam at the moment.

The trouble is that the actual botnets doing most trade, and the actual botnets involved per se, tends to change on a regular basis which makes nuking them a lot harder than you might imagine. For example, just three weeks ago it was the Mega-D botnet that ruled the spamming scumbag roost with a 39 percent distribution share, this week it has ‘just’ 21 percent and the Srizbi botnet is king of the (crap) heap with that 39 percent figure. The fluctuation has a lot to do with the discovery and subsequent active protection against the malware which provides these botnets with their zombie PCs. In the case of Mega-D, for example, as soon as researchers discovered that the 35,000 strong botnet was being fed by the Ozdok malware and the control servers traced back the spam distribution hit zero.

“This week, Mega-D returned again to represent 21 per cent of spam after a 10-day period of inactivity. Owing to the break, Mega-D only accounted for an average of 11% of spam during February.  At its peak last month, it was responsible for a third of all the spam we caught in our spam traps. While the recent publicity spooked the Mega-D spammers into taking their control servers offline, they have now clearly re-established themselves elsewhere,” said Bradley Anstis, Marshal VP of Products. “While Mega-D faltered, Srizbi emerged as the leading spam botnet in February. It is advanced and extremely stealthy malware. Lately, Srizbi has been particularly active in attempting to spread itself through spam campaigns using celebrities as lures,” added Anstis.

Strangely though, size isn’t everything in botnet land. Take the Storm botnet, the 85,000 zombie strong Storm botnet, which only manages to account for some three percent of the total spam distribution pool according to Marshal. “The size of a botnet, measured by how many bots it has, does not necessarily correlate with how much spam it sends. Our TRACE team has observed huge variations in the rate at which different spambots pump out spam,” said Anstis.

12345
Rated: 100% (2 votes)
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments
This article has no comments yet.

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

sick work VM Kill Switch Texas Instruments Government survey teleworking Bill Gates email search fun open source remote working universe service second life archiving network development Linux security avatar ISPA worker exploit christmas global USA standards Research gaming Zango Windows 7 storage Vista graphics virus Adobe CAPTCHA Eee PC Energy Software linkedin Lotus news privacy Microsoft report Supercomputer crime Blogging size Paris Hilton DNS library science Silverlight virtual world economics printing Project OS Google home staffing biometrics Battery statistics office FBI HPC holidays Business surveys e-commerce adware BOFH hacking migration Space Noro productivity Ballmer outsourcing black hat theft xmas digitise The Federation Firefox fool IBM scareware data money code MiniBook rootkits MessageLabs virtual machine workplace Microchip prison debian trust Texting MSN Eee ID Theft Apple help dumb Top 500 Mobile Phone millions compromise AMD hubdub Gartner Web Development MSNBC hacker Windows iPhone 3G copyright Health computing Finjan scan data protection web Internet chips XP politics transactional security Twitter payments symantec technology credit card fraud worm Trojan SSL iPhone botnet scam computer books betting hardware Yahoo banking Funny BSI green payment server InfoSec NASA man-in-the-middle tech patch management carbon copy Rant Big Brother Programming Performance computing Mars Olympics mobile fraud museum phishing policy Application Deal VPN Digg world of warcraft spam stupidity NBC broadband Video Hack social networking remote students Jesus Phone banks Facebook shopping stupid Steve Jobs environment documentation hypervisor China terrorism IDC ecommerce malware SMS Death Obama IP Flash ASUS OCR Russia web 2.0 Rumour
Advertisement
Advertisement
Advertisement