Information Age: News, analysis & insight for IT & business leaders

 
20 March 2010

Spam botnet rebuilds itself after being shut down

28 November 2008  

Co-ordinated malware network found automatically generating new web addresses from which to operate after its host servers were removed from the Internet

In a demonstration of the mind-boggling sophistication of the technology behind malware and spam distribution, a spam botnet this week resurrected itself after the hosting provider whose servers it used was kicked off the Internet.

The Srizbi botnet uses around 100,000 PCs infected with a specific virus to send out millions of spam emails. It was shut down two weeks ago when a web hosting provider named McColo Corp., suspected of tolerating malicious sites, was cut off by its Internet service providers.

But according to security firm FireEye, the botnet reacted to being cut off by automatically generating new websites from which to co-ordinate the infected PCs. FireEye says that it found the algorithm that Srizbi was using to generate the web addresses, and for a while managed predict their domain names and register them before the bot net got round to it.

Eventually, however, this became too expensive and the bot-net began to direct the infected PCs to send out spam again.

Ironically, the sites now co-ordinating the botnet have been traced to a hosting provider located in Estonia, the home of NATO’s cyber-defence headquarters.

Further reading

Superhacker Gary McKinnon on corporate security’s weak spots
As he faces imminent extradition to the US for hacking into top-secret US military systems, Gary McKinnon tells Information Age about how his experiences highlight the security shortcomings of corporate IT

Book review
Schneier on Security
Crime watcher Bruce Schneier provides a refreshing take on the occasionally over-hyped dangers of the IT security industry

Find more stories in the Security & Continuity Briefing Room


Comments 

There are currently no comments on this article

People who read this also read...

Man linked to TJX Maxx cyber-theft jailed for 30 years

Ukrainian linked to theft of 40 million credit card numbers sent to Turkish prison

A service economy

Demand for IT service management software is rising fast, as vendors continue to innovate

Encryption key law comes into effect

Section 49 of RIPA activated this week.

 
Advertisement

White Papers

Read article

12 Key Points to Consider When Selecting a Network Scanning Solution

Whitepapers

Discover the 12 key points your company should consider before you evaluate and select a vulnerability assessment solution.

Read article

1Z0-040 Oracle Database 10G New Features for Administrators Practice Exam

Whitepapers

Oracle 9i administrators can certify on Oracle 10G by passing this exam. The ExamForce 1Z0-040 Oracle Database 10G New Features for Administrators practice exam provides their unique triple testing mode to instantly set a baseline of your knowledge and focus your study where you need it most.

Read article

70-680 Windows 7 Configuring Exam Prep Special Edition

Whitepapers

ExamForce's Windows 7, Configuring CramMaster will prepare you to pass the Microsoft 70-680 exam. CramMaster 70-680 practice exam provides their unique triple testing mode to instantly set a baseline of your knowledge and focus your study where you need it most.

More