Re: Spam sent from compromised (web)hosts vs botnet spam

Paul Smith <[email protected]> Wed, 20 Mar 2013 17:46:38 +0000
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 20/03/2013 16:59, Martijn Grooten wrote:
> So, research.
>
> A few people (Chris a.o.) have mentioned the large volume of spam sent from compromised webhosts.
>
> Here someone looked at CBL's stats and found that the ten worst senders of spam are all hosting companies:
>
> http://www.mailchannels.com/blog/2013/03/worlds-largest-spam-sources-are-all-hosting-companies/
>
> I think this isn't just an interesting statistic about spam (like reports listing the ten worst spam-sending countries), but it may indicate a problem.

I've noticed this as well. I'm not convinced they're all 'compromised 
webhosts'. The ones I've noticed noticing are in big blocks of hosting 
company address space (eg aaa.bbb.ccc.130-254), and they all had valid 
SPF entries, and reverse-DNS names which don't look legitimate at all, 
but match the sender domain.

(If you get spam which has good SPF entries, it's sometimes worth 
investigating further)

Eg, on our internal 'DNSBL' we have 46.20.116.1-46.20.116.155 as a 'bad 
range' from last year.

These didn't seem to be running anything on port 80 or port 25 at the 
time, but were pumping out spam at a huge rate.

The IP range is owned by Peer 1 Hosting 
(http://en.wikipedia.org/wiki/Peer_1) who are quite big.

So, AFAICS either:
- someone hacked a big bank of servers (or a server with lots of IP 
addresses), and managed to set up reverse DNS for the addresses so that 
they could have good SPF results
- Peer 1 hosting gave lots of servers and/or lots of IP addresses to 
someone who paid for them with stolen card details, without doing 
adequate checks, or
- Peer 1 are colluding

(I'm not picking on Peer 1 here, that's just the example I came across 
first. We have also got big blacklisted ranges from Network Operations 
Centre, Inc (nocinc.com), SInglehop, DevilDogs Hosting and many other 
hosting companies)

My suspicion is that spammers are using stolen card details, setting up 
server(s) in a hosting company running them for a few days (with HUGE 
bandwidth) and then abandoning them when they get discovered

The sad thing is that the hosting companies don't seem to learn. I have 
lots of ranges from nocinc.com which have been used for spamming over 
many months. So, it looks as if the spammers just go back again and 
again with new stolen card details.

I've tried contacting several of these companies when I notice spam 
pouring in from their servers, but tend to get ignored (or at least, 
they never bother responding).

When we have requests for hosting on our own servers, we always take a 
look at the details. If we're suspicious we ask for more information 
(amazing how many people want to buy a commercial mail service, but only 
have a yahoo.fr email address with a postal address in New Zealand or 
somewhere). When we start checking up they tend to go away and we just 
refund the payment, but it looks as if the big hosting companies don't 
put as much effort in and bear the hit.



-

Paul Smith Computer Services
Tel: 01484 855800
Vat No: GB 685 6987 53
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org