University of Pittsburgh Medical Center‘s
AS122 U-PGH-NET-AS
is #1 again in the
July 2013 worldwide medical
from CBL volume data.
It’s also been #1 in June 2013, when it also spiked over 1,000, Continue reading
University of Pittsburgh Medical Center‘s
AS122 U-PGH-NET-AS
is #1 again in the
July 2013 worldwide medical
from CBL volume data.
It’s also been #1 in June 2013, when it also spiked over 1,000, Continue reading
Good (Konkuk), improving (Cornell), and bad (eHealth)
in the
December 2012
country medical
.
First the good news:
Konkuk University Hospital went from 297 spam messages
last month to zero in
December 2012, removing
Korea from
the
country medical rankings.
Children’s Hospital & Health System
and
THE GOOD SAMARITAN HOSPITAL OF LEBANON PENNSYLVANIA
also went to zero, and
Yale-New Haven Health Services Corporation
and
Sutter Health
dropped enough to fall out of the
world top 10 medical ASNs
emitting spam in
.
Now the apparently bad news that turned good. Continue reading
The curve that took University of Pittsburgh Medical Center‘s AS 122 U-PGH-NET-AS
to number one
in the July 2012 U.S. SpamRankings.net from CBL data is almost completely explained by Festi botnet, except for one day, plus the small curve at the beginning of the month was apparently caused by Grum botnet.
AS 17311 ECMC-BGP was infested with Festi (blue curve on the right) at the same time as AS 122, and AS 17311 earlier had a Cutwail botnet
And this time it's #1
in the
July 2012 U.S. SpamRankings.net from CBL data:
AS 122 U-PGH-NET-AS in the same ranking over time:
2011
Mar |
Apr | May | Jun | Jul | Aug | Sep | Oct | Nov | Dec | 2012
Jan |
Feb | Mar | Apr | May | Jun | Jul |
34 | 32 | 32 | 8 | 31 | 8 | 4 | 29 | 32 | 33 | 30 | 32 | 29 | 6 | 5 | 9 | 1 |
University of Pittsburgh Medical Center's AS 122 U-PGH-NET-AS and
Erie County Medical Center's AS 17311 ECMC-BGP not only took #1 and #2,
they also spammed longer than other medical ASNs.
That jumped them up 8 ranks each in one month.
-jsq
1 | (2) | AS 8075 MICROSOFT-CORP—MSN-AS-BLOCK |
2 | (1) | AS 36692 OPENDNS |
3 | (-) | AS 26769 BANDCON |
4 | (-) | AS 22414 CRAIGS-NET-1 |
5 | (-) | AS 22822 LLNW |
6 | (-) | AS 10912 INTERNAP-BLK |
Beating even OPENDNS, Microsoft took #1 in U.S. PSBL June 2012 rankings.
Microsoft was last on top in the same rankings for April 2012. I thought Microsoft was a leader in Internet security?
In other news, Bell Canada’s AS 577 BACOM actually dropping off the Canadian June 2012 rankings from CBL data. Shaw took #1 and Iweb dropped to #2.
We have a new medical winner! It’s
Hartford Hospital’s AS 11047 HHCC-ASN1. Gaining altitude at the end of the month was Joan and Sanford I. Weill
Medical College and Graduate School of Medical Sciences of Cornell University with AS 20252 JSIWMC.
More on those and other developments in later blog posts.
-jsq
1 | (4) | AS 22093 CCF-NETWORK | ![]() |
2 | (-) | AS 27609 USC-UNIVERSITY-HOSPITAL | ![]() |
3 | (1) | AS 25611 NSLIJHS | ![]() |
4 | (-) | AS 19335 APRIA-HEALTHCARE | ![]() |
5 | (2) | AS 9208 WIN | ![]() |
6 | (7) | AS 122 U-PGH-NET-AS | ![]() |
Yet AS 22093 CCF-NETWORK dropped like a rock on 7 May 2012, going to zero
the next day, and staying there.
So Cleveland Clinic also was most improved for May 2012 medical organizations.
Congratulations, Cleveland Clinic!
This feat of IT security cleanliness shouldn’t have been hard for CCF, since AS 22093 CCF-NETWORK seems to have had a Lethic problem, which CBL saw on no more than 3 hosts. Sure, there could have been more hosts infected than that, and CBL just might not have seen them all. But 3 is far smaller than what CBL sees for a typical botnet infection, so the number of infected hosts probably was quite small. Which means it should have been easy for CCF to find them all and fix them.
Hm, maybe being #4 last month gave CCF some incentive?
-jsq
The three with more than 100 spam messages for the month were
Cedars-Sinai Health Systems‘
AS 22328 CSHS
came in
only seventh in PSBL data, with only 10 spam messages.
But in CBL data,
CSHS came in first, with 2,873 messages.
That’s not a lot, compared to, for example, Comcast,
which CBL saw spamming more than two million messages during the same month.
But what patients would prefer to see from medical organizations is
zero spam messages, since spam is a sneeze for infosec disease,
and who wants to think their hospital’s information security
or radiology computers might be infected?
Chances are CSHS will notice and clean it up pretty quick. Those other three medical orgs may have some sort of more chronic problem….
-jsq
In many developing countries, the absence of surface-based air pollution sensors makes it difficult, and in some cases impossible, to get even a rough estimate of the abundance of a subcategory of airborne particles that epidemiologists suspect contributes to millions of premature deaths each year. The problematic particles, called fine particulate matter (PM2.5), are 2.5 micrometers or less in diameter, about a tenth the fraction of human hair. These small particles can get past the body’s normal defenses and penetrate deep into the lungs.Even satellite measurements are difficult (clouds, snow, sand, elevation, etc.). But not impossible:
That’s in rankings from CBL data. PSBL shows much less data for medical organizations, yet nonetheless the same effect in both world and U.S. medical rankings.
No other rankings showed such a drop.
Did medical organizations actually clean up their act? Or did they just manage to whitelist their netblocks at CBL and PSBL?
Either way, it looks like they noticed SpamRankings.net.
-jsq
Fahmida Y. Rashid wrote in eWeek.com 8 June 2011, UT Researchers Launch SpamRankings to Flag Hospitals Hijacked by Spammers:
That’s a pretty good explanation for why outbound spam is a proxy for poor infosec.“Poor security measures are generally responsible for employee workstations getting compromised, either by spam or malicious Web content. Once the machine is compromised, the botnet herders can add it to its spam-spewing botnet to send out malware to even more people. The original employee or the organization rarely has any idea the machine has been hijacked for this purpose.”
-jsq