40% of all spam comes from just one source

Posted by Alex on 17th, 2008

spambots_feb08a1.JPG

Six bots are responsible for 85% of all spam, according to an analysis by Marshal. The Srizbi botnet is the largest single source of spam - accounting for 39% of junk mail messages – followed by the Rustock botnet, responsible for 21% of the spam. Spam coming from the Mega-D botnet was temporarily stemmed after control servers were taken out in mid-February. The estimated 35,000 zombie clients associated with the Mega-D botnet were infected with the Ozdok Trojan. After 10 days of inactivity, spam from compromised hosts began flowing again earlier this week, after hackers re-established control. Despite the short offline period, Spam-D accounted for an estimated 11% of junk mail in February. Other active spam botnets include Hacktool.Spammer (AKA Spam-Mailer) and botnets associated with the Pushdo (AKA Pandex) family of malware. The infamous Storm botnet, estimated to have about 85,000 compromised hosts, is thought to be responsible for only 3% of spam.

Most of the times, spammers have access to multiple botnets and they have been simultaneously sending spam promoting Express Herbals, a line of male enhancement pills. (almost 70% of spam promotes male enhancement pills)

According to February statistics from Network Box, a managed security firm, the US continued to pump out the most spam and spread the most viruses. The country accounted for 13 % of all viruses and was the source of 15% of all spam (that is 2.5 times more than its closest junk mail rival, Turkey).

Popularity: 45% [?]

If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!

Some related posts

RSS feed | Trackback URI

27 Comments »

Comment by Sarah
2008-03-17 09:31:15

I dont believe this.

 
Comment by TelevisionSpy
2008-03-17 10:23:01

It makes sense, actually looking at some of these spam messages yield a lot of them are ads for the same site with varying referral addresses. It almost seems like the site could be suffixing referral urls like ?ref=[id] just so they can always say that some spammer is spamming their url, when infact it’s probably them.

 
Comment by Mark
2008-03-17 13:32:43

These pills really do work. I have been munching on them for just 3 months and I now have a 3.5 ft long penis.

Comment by Mark's Mother
2008-03-17 13:56:56

Trust me, Mark does have an enormous wang. These pills perform miracles.

 
Comment by Rick
2008-03-17 14:07:08

Those pills don’t work, they cause confusion. That’s not your penis, that’s your leg dork!!!

Comment by JC
2008-03-17 15:40:06

Thanks to your comment all the new spam is going to say, “You want enormous leg dork?!”

(Comments wont nest below this level)
 
 
 
Comment by JJ Subscribed to comments via email
2008-03-17 13:35:51

Great. now is there a way to block these bots somehow?

Comment by Daniel
2008-03-17 15:21:53

ask them kindly

 
 
Comment by tao54nyc
2008-03-17 13:40:48

Good thing the US gov’t doesn’t declare “war on spam”…the botnets would triple in size and output!

 
Comment by Nick
2008-03-17 13:54:40

yeah this isn’t exactly right, id say this is a chart for just bot spam. There are tons of actually companies that send out spam based on contracts with these other websites. The spam industry is pretty weird. i know cuz i’ve worked for a few of these companies as a graphic person.

 
 
Comment by Tony
2008-03-17 15:32:42

Those pills just made me grow another penis. And now I’m the highest paid DP’er in the biz.

 
Comment by joker
2008-03-17 15:35:20

Believe this…the spam is not there to sell male enhancement, but to inhibit anonymous communication via open relay servers. It is a sham perpetrated by the US Government in order to protect certain security interests.

 
Comment by Mouring
2008-03-17 15:47:02

I can believe that.. From around July 1st, 2007 to just a few days ago (I expect it will pick back up). I’ve had a botnet that used my email address as its “from:” resulting in an average 5,000 to 15,000 email a day worth of bounce back mail. Not sure why there has been almost perfect 3 days calm (heck I’m down to 3 legit spams, and no bounce backs an hour!), but I’m expecting I’ll be paying for it soon.

I can only imagine how many valid emails were sent that didn’t bounce back.

- Ben

 
Comment by Jeremy Steele Subscribed to comments via email
2008-03-17 15:59:59

Don’t know why this would be a surprise to anyone, it’s been well known for years that most spam comes from just a few sources.

 
Comment by suppor guhc
2008-03-17 16:22:54

My penis is small

 
Comment by Dazed
2008-03-17 16:29:22

So, Who are these 15000+ morons with infected PCs? Why can’t we just take their computer away?

Comment by Saulius
2008-03-21 13:12:31

Because it would put a serious threat to Microsoft software sales, I suppose

 
 
Comment by jamie
2008-03-17 16:42:08

It’s interesting to see how little exposure the storm bot net has. I remember when this network was first exposed it was expected that it would have a huge presence, but it looks like not much has really come from it.

 
Comment by subcorpus
2008-03-17 16:52:27

we know who sends spam …
we know how much spam they send …
heck we can draw pie charts and stuff from what we know …
so can someone please make them stop …
seriously … i dont wanna delete 50 emails twice everyday …

 
Comment by James Penis
2008-03-17 17:03:44

I have not received any offers for a larger penis. Do the Bot networks dislike me or something. Do I look funny or smell bad.

Hello Bot Net’s… send me a larger penis.

 
Comment by Robot
2008-03-18 00:32:50

Notice how the comment box says “Your comment; smaller size larger size? perhaps it should say, Your penis (Smaller size | Larger size)

 
Comment by DazzlinDonna
2008-03-18 00:32:51

subcorpus, try forwarding all your email to a gmail account first, and then grab the email from there using gmail’s pop feature. gmail does a fairly good job of filtering out the spam. i’ve gone from about 1000 spam mails per day, coming into my email client down to just 2 or 3.

 
Comment by :|
2008-03-18 06:01:25

bots suckers!

 
Comment by Cameron Subscribed to comments via email
2008-03-18 10:49:08

The Herbal King spammer leads the fools to a “bullet proof hosting” place ZBYD (#3) off of Great Wall Broadband. Just imagine, if we had Net Neutrality, all the big consumer broadband companies wouldn’t be allowed to block ZBYD and shut the whole thing down. Oh, wait a minute, they don’t do that now. They only block sites that oppose their wiretap immunity bill.

 
Comment by Lucho
2008-03-20 15:06:47

Wow! Very powerfull this bots. Unfortunately, the spam problem won’t finish so soon. :(

 
Comment by Bob
2008-03-23 23:26:12

So shut down the freaking companies that are selling penis poppers and the spammers will have no reason to continue.

Where is 4chan when you need them? Shut down the websites of the companies selling this crap.

Send them to Gitmo, I really don’t care. Spammers deserve a nice long vacation.

Thanks for the info!!

 
Name (required)
E-mail (required - never shown publicly)
URI
Subscribe to comments via email
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.


Search


Add to Technorati Favorites

Subscribe with Bloglines

  • Recent Posts