<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; spam</title>
	<atom:link href="http://praetorianprefect.com/archives/tag/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Thu, 29 Jul 2010 16:38:31 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>A Festi-vous for the Rest of Us</title>
		<link>http://praetorianprefect.com/archives/2009/11/a-festi-vous-for-the-rest-of-us/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/a-festi-vous-for-the-rest-of-us/#comments</comments>
		<pubDate>Sat, 07 Nov 2009 02:48:24 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1468</guid>
		<description><![CDATA[On Thursday, Darren Lewis of MessageLabs, the venerable e-mail security firm now owned by Symantec, published findings for a new botnet called Festi which rocketed into a top ten spot in the rankings of the largest spam sending botnets in September. First classified in August, Festi rose in September to propagating a high water mark of around three billion spam messages per day.]]></description>
			<content:encoded><![CDATA[<p><a href="http://praetorianprefect.com/wp-content/uploads/2009/11/spam_thumb.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2009/11/spam_thumb-150x150.jpg" alt="spam_thumb" title="spam_thumb" width="150" height="150" class="alignleft size-thumbnail wp-image-1470" /></a>On Thursday, Darren Lewis of MessageLabs, the venerable e-mail security firm now owned by Symantec, published findings for a new botnet called Festi which rocketed into a top ten spot in the rankings of the largest spam sending botnets in September. First classified in August, Festi rose in September to propagating a high water mark of around three billion spam messages per day. The spam e-mails lead users back to web sites selling pharmaceutical products (primarily male enhancement) and watches/jewelry. The increase in spam messages tied to this botnet is due both to compromised bots sending out a larger number of spam messages as well as an increase in the number of infected machines: 60% of which are located in Asia, 18% in Europe, and 9% in North America.</p>

<h3>Propagation</h3>

<p>As detailed in the graph presented by MessageLabs, Festi&#8217;s responsibility for worldwide spam (as tracked by MessageLabs) spiked in a period of approximately one week in September, and after experiencing a slight drop off has started to sustain around a 5% share of worldwide spam.</p>

<div id="attachment_1511" class="wp-caption alignleft" style="width: 310px"><a href="http://praetorianprefect.com/wp-content/uploads/2009/11/festi_botnet.gif"><img src="http://praetorianprefect.com/wp-content/uploads/2009/11/festi_botnet-300x144.gif" alt="% of Spam: Festi &lt;i&gt;Source: MessageLabs&lt;/i&gt;" title="festi_botnet" width="300" height="144" class="size-medium wp-image-1511" /></a><p class="wp-caption-text">% of Spam: Festi - <i>Source: MessageLabs</i></p></div>

<h3>The Big Boys, et al.</h3>

<p>Most of the world&#8217;s spam originates from a handful of botnets. Below you can see approximately where Festi now fits into that list. While botnets get a good deal of attention based around the capability to carry out distributed denial of service (DDOS) attacks, their primary usage at this point appears to be sending out spam.</p>

<table>
<tr><td colspan="2"><b><i>Spam Messages per Day by Botnet</i></b></td></tr>
<tr><td><b>Name:</b></td><td><b>Messages:</b></td></tr>
<tr><td>Grum</td><td>39,882,623,356</td></tr>
<tr><td>Bobax</td><td>27,005,335,534</td></tr>
<tr><td>Cutwail/Pandex</td><td>19,093,814,547</td></tr>
<tr><td>Rustock</td><td>17,237,275,104</td></tr>
<tr><td>Bagle</td><td>14,018,452,695</td></tr>
<tr><td>Mega-D*</td><td>11,634,914,843</td></tr>
<tr><td><b>Festi</b></td><td><b>~3,000,000,000</b></td></tr>
<tr><td>Maazben</td><td>2,429,738,977</td></tr>
</table>

<p>*Note that Mega-D is apparently falling fast.</p>

<div id="attachment_1488" class="wp-caption alignleft" style="width: 761px"><a href="http://praetorianprefect.com/wp-content/uploads/2009/11/botnets_bysize.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2009/11/botnets_bysize.jpg" alt="Botnets by % of spam originated" title="botnets_bysize" width="751" height="363" class="size-full wp-image-1488" /></a><p class="wp-caption-text">Spam origination sources, Q3 2009 - <i>Data Source: MessageLabs</i></p></div>

<h3>Spam Messages</h3>

<h4>Variant 1</h4>

<p>MessageLabs noted two variants of Spam, the first e-mail type comes with subjects such as Paradise in your bed, Very-very Magic Stick, Strong Stick, Magic stick, Hard stick tonight, or All night long and sends you to a pharmaceutical site registered with a .cn (China) domain:</p>

<div id="attachment_1515" class="wp-caption alignnone" style="width: 310px"><a href="http://praetorianprefect.com/wp-content/uploads/2009/11/email.gif"><img src="http://praetorianprefect.com/wp-content/uploads/2009/11/email-300x205.gif" alt="First e-mail variant." title="email" width="300" height="205" class="size-medium wp-image-1515" /></a><p class="wp-caption-text">First e-mail variant.</p></div>

<div id="attachment_1516" class="wp-caption alignnone" style="width: 284px"><a href="http://praetorianprefect.com/wp-content/uploads/2009/11/canadian_online.gif"><img src="http://praetorianprefect.com/wp-content/uploads/2009/11/canadian_online-274x300.gif" alt="Pharmaceutical site the e-mail links to." title="canadian_online" width="274" height="300" class="size-medium wp-image-1516" /></a><p class="wp-caption-text">Pharmaceutical site the e-mail links to.</p></div>
<br /><br /></p>

<h4>Variant 2</h4>

<p>The second variant comes with subjects such as casablanca leather band, classic automatic, submariner limited coca cola edition, classic quartz, omega de ville co axial chronograph, or Hermes Watches and contains links to a web site selling watches and jewelry:</p>

<p><div id="attachment_1520" class="wp-caption alignnone" style="width: 310px"><a href="http://praetorianprefect.com/wp-content/uploads/2009/11/email1.gif"><img src="http://praetorianprefect.com/wp-content/uploads/2009/11/email1-300x192.gif" alt="Second e-mail variant." title="email1" width="300" height="192" class="size-medium wp-image-1520" /></a><p class="wp-caption-text">Second e-mail variant.</p></div>

<p><div id="attachment_1521" class="wp-caption alignnone" style="width: 301px"><a href="http://praetorianprefect.com/wp-content/uploads/2009/11/prestigereplicas.gif"><img src="http://praetorianprefect.com/wp-content/uploads/2009/11/prestigereplicas-291x300.gif" alt="Prestige Replicas site (watches/jewelry) the link in the e-mail opens." title="prestigereplicas" width="291" height="300" class="size-medium wp-image-1521" /></a><p class="wp-caption-text">Prestige Replicas site (watches/jewelry) the link in the e-mail opens.</p></div>
<br /><br /></p>

<h3>In Conclusion</h3>

<p><div id="attachment_1513" class="wp-caption alignnone" style="width: 310px"><a href="http://praetorianprefect.com/wp-content/uploads/2009/11/Festivus-Pole-from-Seinfeld.png"><img src="http://praetorianprefect.com/wp-content/uploads/2009/11/Festivus-Pole-from-Seinfeld-300x225.png" alt="It&#039;s getting to be that time of year." title="Festivus-Pole-from-Seinfeld" width="300" height="225" class="size-medium wp-image-1513" /></a><p class="wp-caption-text">It's getting to be that time of year.</p></div>
<br /><br />
Based on its relatively quick rise, Festi will get more attention in the near term and will be worth tracking to see where it eventually lands amongst the largest botnets globally.</p>

<p>Sorry, we couldn&#8217;t resist the title, its the first thing we thought of when we heard the name &#8216;Festi&#8217;. Now for the feats of strength&#8230;</p>

<h3>References</h3>

<ul>
<li><a href="http://www.symantec.com/connect/blogs/festi-botnet-spins-become-one-main-spamming-botnets">Festi Botnet spins up to become one of the main spamming botnets</a></li>
</ul>

<p><strong>Related Posts:</strong></p>
<ul>
</ul><br />
]]></content:encoded>
			<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/a-festi-vous-for-the-rest-of-us/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
