All the latest UK technology news, reviews and analysis

Team of academics cripples PushDo botnet

by Iain Thomson

More from this author

28 Aug 2010

Be the first to comment

  • Tweet this
Spam

An international team of academics researching global spam has managed to cripple a botnet as a by-product of its research.

The team, made up of professors and PhD students at the University of California, Santa Barbara and Germany's Ruhr-University Bochum, was conducting a joint research project analysing spam distribution.

Part of this was running several honeypots (open machines online designed to catch malware) and looking for patterns in the data.

By matching some of the malware discovered against the free databases maintained by Anubis the team was able to identify the 30 command and control servers used by the PushDo botnet, which is responsible for large volumes of spam.

"Pushdo has a long history of badness, and some analysis reports date back to as far as 2007," said assistant professor Thorsten Holz.

"This piece of malware acts as a dropper, and downloads additional components which can then carry out different tasks, like for example the Cutwail component which sends out spam mails."

After making sure of its evidence the group went to the hosting companies and informed them of the situation. In all, 20 of the 30 servers identified were shut down and security researchers at M86 said that the botnet has been crippled.

"This co-ordinated takedown has had an immediate impact on Pushdo's spam output," said Phil Hay, lead security researcher at M86.

"Pushdo has been responsible for wave after wave of malicious spam campaigns in recent months. Still, we must sound a note of caution. Previous experience has taught us that these botnet take downs are short lived."

Holz told V3.co.uk that the hosting companies were helpful in taking down the servers, but agreed that the botnet might not be out of commission for long.

"Spammers are making a lot of money," he said. "It's very likely that the controllers will work to re-establish themselves and will move their infrastructure elsewhere."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Project Manager -Commodities,Oil,Gas,Agriculture,Power- £90,000

Project Manager, London - Software Solutions (Project...

Project Manager - Hampshire - up to £32K FTC

Project Manager - Hampshire - up to £32K - Fixed Term...

Senior Customer Support Consultant - 2nd/3rd Line Support - SAS

Senior Customer Support Consultant - 2nd/3rd Line Support...

Front Office Application Developer - Investment Banking - Londo

C++/C#/Java developer for a global investment bank within...

To send to more than one email address, simply separate each address with a comma.