Botnet army back to spamming

Photo credit Egon Endrenyi © 2004 Revolution Studios Distribution Co., LLC.

Photo credit Egon Endrenyi © 2004 Revolution Studios Distribution Co., LLC.

In Guillermo del Toro’s big screen adaptation of Hellboy, The protagonists meet Sammael, a monster that reincarnates into two new creatures everytime it is killed. They quickly realize that getting rid of the beast turns out to be a rather tedious task since it multiplies exponentially. The characters eventually manage to destroy the offspring by burning down the very nest of which the eggs keep coming out.

Two weeks ago, I wrote about Internet providers succeeding in cutting down spam traffic by 2/3 after shutting off some identified ill-regulated Web hosts. Computer World reports how the Srizbi botnets were cut off from the chain of command, the latter being hosted at McColo. It appears however that botnets were programmed to try and reconnect to the chain of command by registering one fallback domain from a list generated by algorithms. In a round-the-clock race, security experts registered the domains guessed after a reverse engineering of the algorithm, but they were eventually overtaken as the first bots began to feed the rest of the 100,000 infected machines with the updated malware. As a result, spam traffic is now back to what it was like two weeks ago.

Share/Save/Bookmark