Mrs Mubarak's IP addresses used by spammers

Posted by   Virus Bulletin on   Feb 1, 2011

Spammers finding new ways to obtain non-blacklisted addresses.

While not necessarily related to the current unrest in Egypt - which, among other things, led to the cutting off of most the country from the Internet - over 5,000 IP addresses belonging to the wife of the country's president have been hijacked by spammers.

The range of addresses was assigned to the Suzanne Mubarak Science Exploration Center several years ago and may well have been dormant for some time. However, spammers managed to hijack the range and have been using it to send spam pushing a number of dodgy web businesses.

IP blacklisting has been a major anti-spam tool for some years and thus for a spam campaign to be successful it helps a great deal if the emails are sent from addresses that have not (yet) been blacklisted. Stealing dormant IP ranges is a method that is becoming more popular among spammers; they manage to gain control of the addresses by registering expired domains or sending forged letters to the regional Internet registry.

With IPv4 addresses becoming scarcer, a secondary market of dormant but assigned IPv4 addresses is likely to arise and one can be certain that those with less honest intentions will find ways to benefit from this market too. Registries ought to be aware of this issue and those in the anti-spam business - particularly those running IP blacklists - should ensure they respond swiftly to the abuse of hijacked IP addresses.

More at the blog of security journalist Brian Krebs here, with information on Mrs Mubarak's IP range at The Spamhaus Project here.

Posted on 01 February 2011 by Virus Bulletin



Latest posts:

VB2016 paper: The TAO of Automated Iframe Injectors - Building Drive-by Platforms For Fun

We publish Aditya K. Sood's VB2016 paper on the use of iframe injectors by cybercriminals to deliver drive-by downloads.

“Cybersecurity is, at its core, a people problem,” says VB2016 keynote speaker

An interview with VB2016’s keynote speaker Christine Whalley - Director, Governance and IT Risk Management at Pfizer

Throwback Thursday: Following the Breadcrumbs

In 1999, Christine Orshesky described how one large organization decided to find out how and where the viruses within it were being obtained so it could do more to protect its networks.

VB2016 preview: Cryptography mistakes in malware

At VB2016, two talks will discuss mistakes made by malware authors in cryptographic implementations. Ben Herzog and Yaniv Balmas will present a paper in which they look at a number of these mistakes, while Malwarebytes researcher hasherezade will…

GPS technology is more at risk from cyber attack than ever before, security expert demonstrates at VB2016

Next month at VB2016, HPE Security's Oleg Petrovsky will speak about attacks on GPS. We conducted a short interview with Oleg and asked him about GPS, about the conference, and about his ultimate dinner party.