Re: Web host spam vs spam filters

Steve Atkins <[email protected]> Wed, 19 Jun 2013 17:51:52 -0700
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On Jun 18, 2013, at 1:30 PM, Martijn Grooten <[email protected]> wrote:

> So. I had promised I'd do some research into spam sent from web hosts. Which I did.
> 
> I used 64,000 spam messages sent between 27 April and 13 May 2013.
> 
> They were sent through 20 spam filters in parallel and real-time.
> 
> I defined a 'web host' as an IP address that was listening on port 80 around the time the email was sent.
> 
> About 30% of the spam in this corpus was sent from web hosts.
> 
> Web host spam bypasses a filter with a probability of 1.04%.
> 
> Other spam does so with a probability of 0.29%.
> 
> That's a significant difference. (Note that the spam I use tends to be easy to filter. Relatively little snowshoe spam and dodgy ESPs.)
> 
> There's the usual correlation versus causation disclaimer. It could well be that those spammers who use web hosts (most of which I assume to be compromised, but I didn't look into this) for sending spam are better at sending spam.

One obvious difference between a botnet compromised windows desktop and a botnet compromised unix webserver would seem to be that the webserver probably has a perfectly functional MTA, meaning that it'd be less likely to have some of the obvious giveaways (protocol and headers) that the mail from compromised desktops often has.

Cheers,
  Steve-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org