Re: Spam sent from compromised (web)hosts vs botnet spam

Chris Lewis <[email protected]> Wed, 20 Mar 2013 17:32:13 -0400
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 13-03-20 01:46 PM, Paul Smith wrote:
> On 20/03/2013 16:59, Martijn Grooten wrote:

>> Here someone looked at CBL's stats and found that the ten worst
>> senders of spam are all hosting companies:
>>
>> http://www.mailchannels.com/blog/2013/03/worlds-largest-spam-sources-are-all-hosting-companies/
>>
>>
>> I think this isn't just an interesting statistic about spam (like
>> reports listing the ten worst spam-sending countries), but it may
>> indicate a problem.
> 
> I've noticed this as well. I'm not convinced they're all 'compromised
> webhosts'. The ones I've noticed noticing are in big blocks of hosting
> company address space (eg aaa.bbb.ccc.130-254), and they all had valid
> SPF entries, and reverse-DNS names which don't look legitimate at all,
> but match the sender domain.

The ones that mailchannels is talking about are truly infected webhosts
with direct-to-MX spam engines (usually written in PHP or Perl) that
have gotten onto the webhosts by compromised user credentials (hosted
website's owner's PeeCee got compromised) or an outright hole in a
unpatched version of Joomla, wordpress, Cpanel, Plesk or some other
similar thing.

I have copies of these spam tools.  They aren't real MTAs sending the
spam.  They don't _have_ to be web servers either.  I have encountered a
number that are *ix machines with a remotely controlled perl script with
_no_ web server.  The perl scripts are encrypted inside of executable
binaries and includes a proxy, a downloader, and a spam engine, and
don't need a web server.

The above spam engine can push in excess of 60 emails/second over wimpy
house-grade G wireless from a dual Atom laptop.  How do I know?  Because
I run it occasionally to see what it's sending ;-)

There's another class that's died down considerably by now.  It's a
"kit" dropped on hosting environments that contains a full spam suite -
real MTA etc.  This is real MTAS.  Up until about 5-6 months ago it was
the largest spam emitter by far.  We class this as snowshoe, because the
hosting is leased by the spammers.

But the former, compromised *IX, usually web servers, are about 50% of
all spam now.

-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org