Feeds

Dead network provider arms Rustock botnet from the hereafter

McColo dials Russia as world sleeps

SANS - Survey on application security programs

McColo, a network provider that was yanked offline following reports it enabled more than half the world's spam, briefly returned from the dead over the weekend so it could hand-off command and control channels to a new source, security researchers said.

The rogue network provider regained connectivity for about 12 hours on Saturday by making use of a backup arrangement it had with Swedish internet service provider TeliaSonera. During that time, McColo was observed pushing as much as 15MB of data per second to servers located in Russia, according to Paul Ferguson, a security researcher for anti-virus software maker Trend Micro.

The brief resurrection allowed miscreants who rely on McColo to update a portion of the massive botnets they use to push spam and malware. Researchers from FireEye saw PCs infected by the Rustock botnet being updated so they'd report to a new server located at abilena.podolsk-mo.ru for instructions. That means the sharp drop in spam levels reported immediately after McColo's demise isn't likely to last.

"It's going to take a little while before we probably see the spam levels go back up again, at least from those botnets," Ferguson told The Register. Because McColo was cut off so quickly after regaining connectivity, botnet operators were probably not able to update as many nodes as hoped, he added. Rustock is capable of sending 30 billion spam messages per day, according to researchers from anti-virus provider Sophos, which also witnessed the Rustock transition.

The arrangement between the McColo and Telia had been in place for more than a year, according to an individual at Giglinx, a California-based reseller of wholesale bandwidth that brokered the deal. The IP address used to reconnect McColo had been allocated to the "CWIE Holding Company," which claimed to process credit cards. Telia quickly pulled the plug once researchers learned it was linked to McColo.

Ferguson said it was more than a mere coincidence that McColo waited until Saturday, more than four days after being disconnected, to use its backup link with Telia.

"It seems suspicious to me that they waited until Saturday afternoon on the assumption that people don't work on the weekends and it would take at least until Monday before somebody could actually take any action on it," he said. Ferguson's report, which was co-written by researcher Jart Armin, is available here (PDF alert). A video illustrating the incident is here. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.