Category Archives: CBL

Festi botnet in July 2012 U.S. Medical from CBL

AS 122 U-PGH-NET-AS The curve that took University of Pittsburgh Medical Center‘s AS 122 U-PGH-NET-AS to number one in the July 2012 U.S. from CBL data is almost completely explained by Festi botnet, except for one day, plus the small curve at the beginning of the month was apparently caused by Grum botnet.

AS 17311 ECMC-BGP was infested with Festi (blue curve on the right) at the same time as AS 122, and AS 17311 earlier had a Cutwail botnet

Continue reading

Pittsburgh back in the top 10 for spam from U.S. medical organizations

And this time it's #1 in the July 2012 U.S. from CBL data:

AS 122 U-PGH-NET-AS in the same ranking over time:

Apr May Jun Jul Aug Sep Oct Nov Dec 2012
Feb Mar Apr May Jun Jul
34 32 32 8 31 8 4 29 32 33 30 32 29 6 5 9 1

University of Pittsburgh Medical Center's AS 122 U-PGH-NET-AS and Erie County Medical Center's AS 17311 ECMC-BGP not only took #1 and #2, they also spammed longer than other medical ASNs. That jumped them up 8 ranks each in one month.