Silent Rustock

There has been a significant observed drop in worldwide SPAM levels during the last month or so.  M86 thinks it's due to Rustock, the world's largest spam botnet, suddenly stopped sending spam for unknown reasons.   McAfee has expressed a different point of view. According to them, the steep drop in spam levels is due to recent attempts to shutdown Pushdo.D, another famous spam botnet.  It's clear that spam levels are dropping, so let's look behind the curtain and try to find the actual reasons for the statistical observations.

I can think of two possible reasons why a major spam botnet would suddenly stop sending spam:

1. There was an attempt to shutdown the botnet by taking down its CnC servers.

2. The bot herders are running out of business i.e no one is paying them to send SPAM.

Continue reading »

Srizbi and Rustock: Family Feud or Sibling Rivalry? Part II

FireEye recently dove into the world of spam email Botnets to further strengthen our belief that Botnets like Srizbi, Pushdo, and Rustock, although having completely different C&C architectures, are operated by same group.

This go around, we looked at the servers that control these Botnets and spam created from live Bots in our lab. As part of this investigation, we analyzed multiple malware samples of these Botnets in our both virtual and real lab environments to extract the relevant C&C locations. When we compared the C&C IPs being used by these three Botnets, we were surprised to see that all three were using servers in the same colocation facility, and that this facility was fairly well known (by a quick Google search) to have been used for malicious activities in the past.

Continue reading »