Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 12 November 2008

Unprecedented Drop in Spam

Posted on 10:22 by Unknown
Would you like to know exactly what time the peering providers for McColo pulled the plug? Its not hard to tell if you watch spam volumes. Brian Krebs, from the Washington Post, has been using his most excellent blog Security Fix to lead a public awareness crusade against some of the dirtiest Internet Landfills on the web. His journalistic efforts lead to the breakup of the Russian Business Networks, the closing of InterCage, the ICANN order against EstDomains, and most recently, the closing (at least for now) of McColo.

We know that in the long term such actions might be nothing more than turning on the light -- the roaches scatter, but resume their business somewhere else. The point is to set an example which, if enough people follow after it, will continue to bring inconvenience and expense to the spammers no matter where they resume their operations.

But for the moment, let's celebrate the possibly temporary drop in spam.

This morning at the UAB Spam Data Mine our spam volumes are decreased from normal volumes by between 65% and 70%! What happened? And can we make any generalizations from today's events?

Very little, if any, spam is actually sent from McColo. Why the shutdown of the McColo network had such a profound impact on spam is that the "Command & Control" servers for many of the world's largest spam-sending botnets resided at McColo. This exercise has shown what we have been arguing all along at UAB -- it is important to find out not just what TYPE of spam is being sent, but HOW it is being sent. I have to say I am even more excited than before about identifying the points of control for some of these other spam-sending botnets.



By isolating the McColo network (the proper term is "de-peering"), the Criminal can no longer update the server where the Botnet machines received their commands. If the bots can't find their controller, they complete their current task, and sit idle, testing from time to time to see if they can reach their Command & Control server. Until they can, they won't have any more spam to send.


Let's look at the immediate impact today of the spam-sending roaches who have been inconvenienced by the McColo shutdown.

There are several places that provide real-time or near real-time graphs of the volume of spam they are seeing. Let's look at a few of them.


(click for current MxLogic Threat Level)

MxLogic.com has been showing spam to be between 83.5% and 91.1% of spam for the past week. Yesterday between 1:00 and 4:00 spam dropped from 85% of their monitored mail volume to 71.93%. Currently they are seeing spam as being 64.1% of their email traffic, which I believe would be the lowest point for the entire year.


(click for current SpamCop Statistics)

SpamCop.net normally sees as many as 30 or 40 spam messages per second, and looked at more than 14 million spam emails in the past week. Yesterday spam dropped abruptly from 30 messages per second to around 8 messages per second, and currently spam volumes have not yet crossed the 15 message per second mark for the entire day.

Brian Krebs has updated his earlier post with news that he is receiving feedback from all around the globe of people who are seeing less spam today because of the disconnection of McColo.

If you have numbers or charts showing your own spam drop, please share them with me. I'd love to share them with our readers here: gar@cis.uab.edu
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • What about the Social Security Numbers? (The Utah Data Breach and your SSN)
    The Utah Data Breach This week the continuing saga of the Utah Medicaid Data Breach continued to unfold. If you haven't been following...
  • Stop the Rumors: Quit SMSing about WalMart Gang Initiations
    My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here...
  • Minipost: IPR Center celebrates Cyber Monday
    The National Intellectual Property Rights Center (IPR Center) announced today that in celebration of Cyber Monday, they have Seized 82 Domai...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Work at Home . . . for a Criminal?
    How do you tell if a "Work at Home" invitation is a scam? Here's a clue: It comes in your email. In today's Blog, I tho...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (101)
    • ►  December (7)
    • ▼  November (17)
      • Mumbai Bombings: Coordinated Bombings in India are...
      • Bank of America Demo Account - DO NOT CLICK
      • AsProx: The Phisher King?
      • Igor Klopov sentenced
      • Facebook Users Beware
      • Enlisting YOUR BANK to steal your identity
      • Post McColo Spam - What do we see?
      • Unprecedented Drop in Spam
      • Internet Landfill: McColo Corporation
      • Microsoft Reveals Malware and Spam Trends
      • Election Malware and Obama Pill Ads?
      • Election Malware Targets Sore Losers - McCain Vide...
      • Yesterday's Obama Spammer Now Imitates Colonial Bank
      • Computer Virus masquerades as Obama Acceptance Spe...
      • ICE: Operation Predator - Solving Intertwined Chil...
      • More Merger Malware Wachovia Wells Fargo
      • MS08-067: New RPC Worm from China
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile