Take-down of rogue ISP sees temporary drop in spam levels
Spam levels back to normal within a few days.
The take-down of the rogue ISP Real Host on 1 August saw spam levels temporarily drop by more than a third, Messagelabs claims in its monthly Intelligence Report.

The provider, based in Riga, Latvia, was linked with various kinds of malicious activity. In particular, it is believed to have hosted the command-and-control centres of the Cutwail botnet (also known as Pandex or Pushdo), which is responsible for about 15 to 20 per cent of the spam sent out worldwide. After the take-down the total spam levels dropped by 38%.
After Atrivo (InterCage), McColo and Pricewert (3FN), Real Host is the fourth major rogue provider to have successfully been taken down.
In the well-reported case of the McColo take-down, it was several months before spam levels recovered, however in this case it took just three days for spam levels to recover - suggesting that botnets have become less dependent on their ISPs. (It should also be noted that a measured drop in spam levels is not felt the same by everyone.)
In the same report, MessageLabs also discussed the ongoing popularity of URL-shortening services in spam campaigns. On one day in July, more than 9 per cent of all spam contained a shortened URL.
The full report can be downloaded as a PDF here, with comments on the AllSpammedUp blog here and from Damballa's Gunter Ollmann, about the ambiguities involved in measuring botnet sizes, here.
28 August 2009
Tags:
botnet, spam.
del.icio.us
digg this
1 comment
with the cell phone co.s over charging, play cosly games,selling phone number list, that rackup expencive minnets. give and sell phone hacking software that realy get the cash moving. no let the co. pay as part of the servises.
by one cent, 10 September 2009, 11:03
Leave a comment
ARF published as IETF standard
Abuse report format helps auto-handling of email complaints
02 September 2010
Microsoft releases new fix for DLL vulnerability
Earlier workaround believed to be too complex for most users.
01 September 2010
Malicious tweets link to fake TweetDeck update
Twitter resets passwords for accounts that appear to have been hacked.
01 September 2010
94% of Internet users befriend unknown 'good-looking woman'
Sensitiva data shared after two-hour chat. (1 comment)
31 August 2010
Investment boost for Quick Heal
Indian security firm gets hefty cash injection.
27 August 2010

Quick Links
![]() |
Poll
When do you install software updates?Leave a comment
View 12 comments

1 hour ago
5 hours ago
VB100 certification
With another epic haul of 54 products to test this month, the VB test team could
have done without the bad behaviour of a number of products: terrible product
design, lack of accountability for activities, blatant false alarms in major
software, numerous problems detecting the WildList set, and some horrendous
instability under pressure. Happily, there were also some good performances to
balance things out. John Hawes has the details.
See full results.
Virus Bulletin currently has 208,221 registered users.



