Spam drops as ISP is cut off from Internet

McColo is solo.

McColo, an ISP suspected of aiding cybercriminals in online scams and hosting child pornography has been at least partially disconnected from the Internet.

ISPs can connect with each other to exchange Internet traffic, a practice known as "peering." Hurricane Electric, an ISP that was one of the primary connections for McColo's traffic, has disconnected with McColo, one of a handful of so-called "bulletproof" hosting providers that provide a safe haven online for cybercriminals.

Global Crossing, an IP (Internet Protocol) network services provider also connected to McColo would not comment, however McColo's main website remains offline.

The shutdown coincides with a damming new report on McColo authored by several computer security researchers who detail how McColo and other questionable service providers are linked to spam and cybercrime.

McColo's shutdown "demonstrates that when presented with appropriate evidence of criminal activity, the Internet community can bring about the positive forces necessary to purge it," the analysts wrote.

McColo, whose servers were located within the US, at one time hosted up to 40 websites with child pornography, the report said.

McColo also played a big role in spam distribution, said Richard Cox, CIO of Spamhaus, which tracks spamming operations. It hosted websites that could infect people's computers with malicious software used for sending spam, he said.

Hacked computers then become part of a botnet, or networks of PCs that can be used to send spam or attack other websites.

McColo hosted the so-called command-and-control servers for botnets that are used to instruct PCs to send spam. The botnets included Rustock, Srizbi, Pushdo/Cutwail, Ozdok/Mega-D and Gheg, according to the report.

When it received complaints, McColo would shift around the suspect websites on its network and try to erase traces of wrongdoing, Cox said.

"Essentially, a lot of these providers know what their customers are doing and try to protect them," Cox said.

Analysts are predicting a drop in spam and botnet activity while McColo is offline. Joe Stewart, director of malware research for SecureWorks, said on Wednesday that he'd received only one spam message from the Rustock botnet, while on a normal day he might get up to 20.

McColo's demise is going "to be kind of a vindication for a lot of researchers that have been complaining about McColo for years and why law enforcement wasn't doing anything about it," Stewart said.

SecureWorks has tracked bad activity at McColo, but law enforcement has always been "tight-lipped" about investigations, he said.

But it may only be mere days before those who use hosting services from McColo find other bulletproof hosters. "There's all kinds of wanna-be McColos that are on the hacker forums, the spammer forums," Stewart said.

In fact, bad activity at McColo increased after the shutdown in September of Intercage, a California hosting company also known as Atrivo, Cox said. Intercage's upstream providers stopped carrying its traffic following years of complaints that the ISP supported spam and harmful websites.

McColo's increased activity showed spammers just moved from Intercage to there, and will likely move fast, Cox said. Cybercriminals probably have "hot stand-by" websites ready to go with other service providers to stay in business, Cox said.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Add your commentComments

Dante | Published: 14:43 GMT, 13 November 2008

Global Crossing. Now that's a familiar name. It's in all my kill filters. I'm surprised if any legitimate business actually use Global Crossing.

Michael W | Published: 14:33 GMT, 13 November 2008

Im at a loss as to why the internet community are unable to handle the spamming and criminal activity that is reaching Pandemic proportions. Were it speeding drivers the police would be all over them like a rash.

Related Security news

Hacker attacks on US military jump sharply in 2009

China source of most attacks, says report

Microsoft denies building security 'backdoor' in Windows 7

Privacy organisations shouldn't read too much into NSA involvement it says

Pentagon expands exclusive deal with McAfee

Department of Defense uses McAfee products

Police arrest pair over global banking web scam

Man and woman arrested in Manchester for using notorious Zeus Trojan



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Unlock the power of the mainframe

This whitepaper presents the notion of CICS as an integration hub based on a component-based, service-oriented architecture supporting Web services. Highlights will review the challenges and contrasted support for Web services natively in CICS.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Ride the express lane in the journey to speed ITIL adoption

Explore the challenges in making the journey to ITIL and the criteria for selecting consulting services
By following ITIL practices, your IT organisation will become more closely integrated with the business. We recommend making the journey to ITIL in a sequence of six incremental steps, the phases of which are driven through execution of a strategic transformational roadmap.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *