Mrs Mubarak's IP addresses used by spammers

Posted by   Virus Bulletin on   Feb 1, 2011

Spammers finding new ways to obtain non-blacklisted addresses.

While not necessarily related to the current unrest in Egypt - which, among other things, led to the cutting off of most the country from the Internet - over 5,000 IP addresses belonging to the wife of the country's president have been hijacked by spammers.

The range of addresses was assigned to the Suzanne Mubarak Science Exploration Center several years ago and may well have been dormant for some time. However, spammers managed to hijack the range and have been using it to send spam pushing a number of dodgy web businesses.

IP blacklisting has been a major anti-spam tool for some years and thus for a spam campaign to be successful it helps a great deal if the emails are sent from addresses that have not (yet) been blacklisted. Stealing dormant IP ranges is a method that is becoming more popular among spammers; they manage to gain control of the addresses by registering expired domains or sending forged letters to the regional Internet registry.

With IPv4 addresses becoming scarcer, a secondary market of dormant but assigned IPv4 addresses is likely to arise and one can be certain that those with less honest intentions will find ways to benefit from this market too. Registries ought to be aware of this issue and those in the anti-spam business - particularly those running IP blacklists - should ensure they respond swiftly to the abuse of hijacked IP addresses.

More at the blog of security journalist Brian Krebs here, with information on Mrs Mubarak's IP range at The Spamhaus Project here.

Posted on 01 February 2011 by Virus Bulletin

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

Virus Bulletin's job site for recruiters and job seekers

Virus Bulletin has relaunched its security job vacancy service and added a new section, in which job seekers can advertise their skills and experience.

Throwback Thursday: One_Half: The Lieutenant Commander?

In October 1994, a new multi-partite virus appeared, using some of the techniques developed by the Dark Avenger in Commander_Bomber. As if this were not enough, the One_Half virus could also encrypt vital parts of the fixed disk. Eugene Kaspersky…

Advertisements on Blogspot sites lead to support scam

Support scam pop-ups presented through malicious advertisements show that, next to vulnerable end points, gullible users remain an easy source of money for online criminals.

To make Tor work better on the web, we need to be honest about it

Many websites put barriers in front of visitors who use the Tor network. If we want to make the web more accessible through Tor, we need to be honest about why this is done, rather than cry wolf about a dislike for privacy, Martijn Grooten says.

Paper: How It Works: Steganography Hides Malware in Image Files

A new paper by CYREN researcher Lordian Mosuela takes a close look at Gatak, or Stegoloader, a piece of malware that was discovered last year and that is controlled via malicious code embedded in a PNG image, a technique known as steganography.