Spammers move from China to Russia

Stricter rules on registering .cn domains leads to increase in malicious .ru domains.

A change in the rules of the organization responsible for registering .cn domains has resulted in a drop in the number of spam messages referencing Chinese top-level domains, with Russian domains moving in to fill the gap.

Advertise on www.virusbtn.com

Until recently, a large proportion of the URLs found in spam messages contained a Chinese .cn top-level domain; these domains were both cheap and very easy to register, making them ideal for spammers.

However, in December the China Internet Network Information Center (CNNIC) - the organization responsible for handing out .cn domains - changed its rules. It is now no longer possible to register a .cn domain unless one has a bona fide business license. Meanwhile, the CNNIC has also announced that it intends to verify previously registered .cn domains.

As soon as the new rules came into effect, the relative occurrence of .cn domains in spam messages dropped significantly. Now, new research by Symantec has shown that .cn domains have almost completely disappeared from spam messages. Instead, spammers appear to be turning to Russian .ru domains to advertise their wares - on some days 40% of spam messages contain such a domain.

While the CNNIC's new regulations seem to have done little harm to spammers, the changes are good news for the reputation of .cn domains and for the large number of legitimate users using such domains: they are now less likely to see their emails and websites blocked by over-zealous filters. For the large number of genuine businesses and end-users using .ru domains, one can only hope that similar stricter regulations will be brought in soon.

Read more at Symantec's blog here, while information about the CNNIC's new regulations can be found at the Global Times here.

24 February 2009

Tags: china, cnnic, domains, russia, spam.    del.icio.us  digg this! digg this

0 comments

Leave a comment

Quick Links



Poll

When do you install software updates?
As soon as they are released
As soon as I have some time
I take my time, but I always install them eventually
Only when I feel it is absolutely necessary
Never
Leave a comment
View 12 comments

Jobs Recruit Sidebar

Twitter Feed

virusbtn: RT @emailsecmatters: The typical spam message has sources as diverse as the spam lunch meat: http://ht.ly/2yucd
1 hour ago


virusbtn: Can anyone write a rap about our RAP tests (http://bit.ly/255ySQ) and submit it to the Symantec competition http://bit.ly/bOJg8r
4 hours ago


Virus Bulletin

In this month's magazine:
  • VB100 – Windows Vista Business Edition Service Pack 2
  • Apple pie order?
  • Anti-unpacker tricks – part eleven
  • Advanced exploit framework lab set-up
  • HTML structure-based proactive phishing detection
  • What’s the deal with sender authentication? Part 3
Virus Bulletin 08 2010
Subscribe now!
Virus Bulletin currently has 208,221 registered users.