Botnets responsible for majority of Spam says MessageLabs report
by Steve Ragan - Oct 1 2009, 16:34The latest MessageLabs Intelligence report covering Q3 2009 reports that over 150 billion email messages are being sent by bots every day. The volume of Spam being generated by bots accounted for nearly 88-percent of all Spam for the quarter. In addition, three new botnets are grabbing attention, as they grow in size and scope online.
Grum, Bobax, and Maazben, are the three most active botnets, sending a fair amount more spam than some of their forefathers in the Spam and Malware scene. According to MessageLabs, Grum was the worst offender, responsible for 23-percent of the world’s Spam on its own.
Bobax, which overtook Cutwail as the top botnet, moved 15.7-percent of the world’s Spam. Bobax started small, known as one of the less active botnets online, but thanks to the closure of rogue ISPs, McColo, PriceWert, and Real Host, which hurt the Cutwail and Srizbi botnets, Bobax has almost quadrupled in size.
Maazben, the newest botnet in the arena, is flagged by MessageLabs as one to watch. This botnet focuses its Spam on casino related themes, but keeps its output low, so it doesn’t appear too high up on the detection radar.
What about the old botnets?
According to the report, they are just as vibrant as ever. Rustock, viewed as the largest botnet of them all, with 1.3 to 1.9 million hosts under its control, has doubled in size since June, but has throttled its daily output.
However, recent research into its activities shows that it activates to send Spam like clockwork, with an automated cycle starting at about 3:00 a.m. EST, with a peak at 7:00 a.m. EST. The cycle starts to taper off at about 7:00 p.m. EST, only to repeat again eight hours later.
Mega D, another botnet with some age and experience, has been rapidly losing bots. The resulting loss of infected systems means that the hosts still under its control are working overtime. Mega D’s output is second only to Bobax in Spam per bot per minute.
Other highlights from the MessageLabs Q3 intelligence report outline the slight decrease in Spam that came complete with its very own Virus (1:399.2), as well as the slight decrease in Phishing-related emails (1:437.1), among the 21,000 customers they monitor for their reports. Malicious websites also fell some 33-percent since August, to 2,337 per day. Of the malicious domains blocked by MessageLabs, 33.5-percent were new.
The entire report is online here.

Comment on this Story