Category Archives: Reputation Systems

Snowshoe took all top 7 in May U.S. CBL SpamRankings.net

Snowshoe appeared to have been the source for spam from all of the top seven spamming organizations in the May 2012 top 10 SpamRankings.net for the U.S. from CBL data. Only 3 were traditional ISPs (two cable companies, Comcast and Charter, plus Global Crossing). Snowshoe spam accounted for all but about 5% of spam from the U.S. top 10. And we already knew snowshoe is not just for hosting companies anymore.

At what point is snowshoe spam no longer a temporary black swan phenomenon, and becomes a prevailing trend?

-jsq

A few bad stones can darken an organization’s SpamRankings.net

Apparently a few infested computers can push a whole hosting service into the top 10 SpamRankings.net for its country. That’s bad, but on the other hand a few addresses should be easy to find and fix. If the infested organization wants to do so.

Take Stone Internet Services AS 39234 STONE-IS, which is the green line climbing to the top of the Belgium April 2012 rankings in the graph. On 30 April CBL caught more than 8,000 spam messages coming from STONE-IS, yet CBL only saw spam coming from a max of 3 STONE-IS IP addresses during that month. If those messages came evenly from each of those 3 addresses, that would be about 2,600 messages from each address, and more likely one of those addresses is the real culprit. Of course, that was almost certainly nowhere near all the spam that came from that ASN that month, and maybe not all the IP addresses sending them.

But compare to the number one source of spam from Belgium for Continue reading

Congratulations to Israel and Spain for dropping out of April World SpamRankings.net!

Israel Israel and Spain Spain were the only two countries to drop out of the world top 20 spammers from CBL data in April 2012. Congratulations!

Not so lucky were the U.K. U.K. and Turkey Turkey, which joined the top 20.

Also, Korea, South Korea got to #2 in the second and third week of the month. and placed third overall, up from fifth in March.

April 2012 Monthly Countries Countries ∀ All SpamRankings.net from CBL Volume
(Previous Month)

Rank (Previous)CountryPopulationVolume% of top 20
1 (1) United States US 310,232,863 104,308,126 17.1%
2 (2) India IN 1,173,108,018 68,811,807 11.3%
3 (5) Korea, South KR 48,422,644 58,983,193 9.66%
4 (6) Vietnam VN 89,571,130 51,301,264 8.4%
5 (3) Brazil BR 201,103,330 38,033,087 6.23%
6 (4) Russian Federation RU 140,702,000 36,167,764 5.92%
7 (8) Taiwan TW 22,894,384 33,163,766 5.43%
8 (7) Poland PL 38,500,000 32,507,068 5.32%
9 (9) Romania RO 21,959,278 24,545,877 4.02%
10 (12) Belarus BY 9,685,000 23,895,403 3.91%
11 (13) China CN 1,330,044,000 18,743,935 3.07%
12 (14) Peru PE 29,907,003 17,293,193 2.83%
13 (11) Ukraine UA 45,415,596 16,062,362 2.63%
14 (18) Kazakhstan KZ 15,340,000 14,924,036 2.44%
15 (15) Argentina AR 41,343,201 13,819,396 2.26%
16 (-) United Kingdom GB 62,348,447 13,638,509 2.23%
17 (17) Pakistan PK 184,404,791 12,320,247 2.02%
18 (10) Indonesia ID 242,968,342 10,899,369 1.78%
19 (-) Turkey TR 77,804,122 10,675,444 1.75%
20 (19) Colombia CO 44,205,293 10,651,199 1.74%
    Total   610,745,045 100%
 
  In Previous  
(16) Spain ES 46,505,963 15,819,585  
(20) Israel IL 7,353,985 11,349,660  

-jsq

An ISP snowshoes ahead in spamming

Continuing the question of Ogee snowshoe: black swan or new strategy? let’s look at Ogee snowshoe spam in the first week of May 2012.

The two dotted lines trending down together in the middle are AS 29131 and AS 28178, and they both fit the traditional profile for snowshoe spam hosting sites, because they advertise hosting or colocation as their main services. AS 29131 is registered to RapidSwitch, which advertises dedicated servers, cloud solutions, and colocation. AS 28178, registered as Network Operations Center (NOC), which keeps on rolling waves of snowshoe spam, appears to be operating under the name BurstNet, which offers managed servers and co-location as its first two services.

However, the dotted line rising to the top right that pulled the solid overall snowshoe volume line back up is not a hosting center: it’s an ISP. CDM’s AS 6428 appears to be operating as Primary Network, whose first services are T-1 Internet access and metro Internet. And Primary Network is not alone. We’ve pulled out a list of all the ASNs affected by Ogee snowshoe so far, and quite a few of them are ISPs, some of them very well known ISPs.

Snowshoe: it’s not just for hosting centers anymore.

-jsq

Microsoft, world leader in Internet security: and spamming?

Microsoft, world leader in Internet security, will doubtless clean up its spamming act when it sees its AS 8075 is #1 for outbound spam in the U.S. for April 2012 in rankings from PSBL data, pushing the U.S. to #1 worldwide. Other rankings don’t show Microsoft high, but does MSFT really want to show up in any of these rankings?

Rank (Previous)CountryPopulationSpam
Volume
Percent
of top 10
1 (3) US 310,232,863 673,30618.2%
2 (2) IN 1,173,108,018 506,39713.7%
3 (1) CN 1,330,044,000 413,08911.2%
    Total   3,689,376100%

These rankings that show Microsoft high are derived by SpamRankings.net from PSBL blocklist data. The April 2012 SpamRankings.net from CBL blocklist data do not show Microsoft in the top 10. Apparently PSBL’s spam traps happened to be in the line of spam from Microsoft, while CBL’s were not.

And of course Microsoft probably doesn’t mean to be sending any of that spam. More likely botnets exploited a MSFT security vulnerability. Here’s hoping they clean it up soon!

-jsq

Ogee snowshoe: black swan or new strategy? SpamRankings.net

A week ago you may recall most of March’s crop of Ogee spamming ASNs had subsided. Yet there were some contenders coming up from the bottom right corner of the graph.

Some correspondents say snowshoe spamming such as Ogee is a black swan, unanticipated and short-lived. I say it may be a change in strategy. Others say the actual spam coming out of Ogee is not the same campaigns as we’ve seen from botnets, so spammers are not moving over. To which I say: yet. And if snowshoe spam is big enough to change worldwide SpamRankings.net, and if it continues, that’s a strategy change. We’ll see how all that goes.

Meanwhile, what’s happened in the last week or two?

Top 10 ASNs showing Ogee spam 2012-03-01 to 2012-04-25, SpamRankings.net.

A few of those contenders were just flashes in the pan. But others are still spamming increasingly more.

-jsq

eCrime Summit in Prague 25-27 April 2012

These ecrime meetings are always interesting and useful. -jsq

Press release of 29 March:

Containing the Global Cybercrime Threat is Focus of Counter eCrime Operations Summit (CeCOS VI) in Prague, April 25-27

CeCOS VI, in Prague, Czech Republic, to focus on harmonizing operational issues, cybercrime data exchange, and industrial policies to strengthen and unify the global counter-ecrime effort.

CAMBRIDGE, Mass.—(BUSINESS WIRE)—The 6th annual Counter eCrime Operations Summit (CeCOS VI) will convene in Prague, Czech Republic, April 25-27, 2012, as the APWG gathers global leaders from the financial services, technology, government, law enforcement, communications sectors, and research centers to define common goals and harmonize resources to strengthen the global counter-cybercrime effort.

CeCOS VI Prague will review the development of response systems and resources available to counter-cybercrime managers and forensic professionals from around the world.

Specific goals of this high-level, multi-national conference are to identify common forensic needs, in terms of the data, tools, and communications protocols required to harmonize cybercrime response across borders and between private sector financial and industrial sector responders and public sector policy professionals and law enforcement.

Key presentations will include:

Continue reading

Which ASNs showed most Ogee snowshoe spam in March and early April?

Snowshoe spamming begins to look like a rising tide.

Peaking at the end of March 2012, the Ogee snowshoe spam winner is AS 16226 GNAXNET-AS – Global Net Access LLC. GNAXNet actually placed another Autonomous System in the same time frame, AS 3595.

U.S. Brinkster’s AS 33055 BCC-65-182-96-0-PHX finally cleaned up its act and went to zero Ogee volume 11 April 2012. Canada’s AS 32613 IWeb also went to zero on 23 March 2012.

On the other hand, it looks like a new surge of snowshoe spam is starting mid-April, including some organizations maybe not usually considered hosting companies, such as Cogent’s AS 174.

Meanwhile, Belarus’ AS 6697 BELPAK-AS already went from #7 to #5 worldwide in March, pushing Belarus up from #16 to #12 among countries.

And NOC’s AS 21788 keeps on rolling waves of snowshoe spam.

All these volume numbers and rankings are provisional, especially considering we’re seeing so many ASes and netblocks that were previously not spamming that we’re tuning our database to be sure we’re properly accounting for them all.

Nonetheless, it looks like snowshoe may be a rising spamming strategy.

-jsq

Ogee pushed iWeb and Canada up SpamRankings.net in March 2012

AS 32613 IWEB-AS was far ahead of the Canadian spamming pack in the March 2012 SpamRankings.net. iWeb improved a lot towards the end of the month, but will it stay improved? AS 14366 MTNCABLE plateaued early, dropped, then took first at the end of the month. Could they have the same problem?

Why yes, both iWeb and MTNCABLE appear to be infested by Ogee snowshoe spamming.

This problem is bad enough that Canada rose from country #46 in January to #34 in February and #25 in March. You can’t see that on the countries top 10, like you can for the U.S., which snowshoe spamming pushed to #1 worldwide in March, but internally SpamRankings.net keeps track of rankings of all countries worldwide, and indeed Canada went form #46 in January to #25 in March.

-jsq

Snowshoe spamming pushed the U.S. to #1 worldwide in March 2012 SpamRankings.net

Previously unseen Brinkster’s AS 33055 BCC-65-182-96-0-PHX took first place. AS 10439 CARINET leapt from #8 last month to #4 for March for the U.S., and was up to second place at the end of the month. Six ASNs joined the U.S. top 10: were they all due to snowshoe spam, too? Brinkster was so bad it made #8 on the world top 10!

Last month’s winner AS 21788 NOC finally cleaned up its act a bit, dropping from #1 to #5. Six ASNs dropped out of the top 10. Four of them (Webhost-ASN-1, LIMESTONENETWORKS, PEER1, and ATMLINK) popped to the top 10 last month due to snowshoe spam. The other two (NTT and Charter’s ASNs) didn’t even have to spam less to drop out, because this month’s top 10 had so much more spam.

But the US ASNs that got worse pushed the U.S. to #1 spamming country. The slope of that U.S. world top 10 curve for the last dozen days of March looks just like the Brinkster and CARINET ASN curves in the U.S. top 10. Very impressive, to drive the whole country into the countries top 10!

-jsq