Mrs Mubarak's IP addresses used by spammers

Posted by   Virus Bulletin on   Feb 1, 2011

Spammers finding new ways to obtain non-blacklisted addresses.

While not necessarily related to the current unrest in Egypt - which, among other things, led to the cutting off of most the country from the Internet - over 5,000 IP addresses belonging to the wife of the country's president have been hijacked by spammers.

The range of addresses was assigned to the Suzanne Mubarak Science Exploration Center several years ago and may well have been dormant for some time. However, spammers managed to hijack the range and have been using it to send spam pushing a number of dodgy web businesses.

IP blacklisting has been a major anti-spam tool for some years and thus for a spam campaign to be successful it helps a great deal if the emails are sent from addresses that have not (yet) been blacklisted. Stealing dormant IP ranges is a method that is becoming more popular among spammers; they manage to gain control of the addresses by registering expired domains or sending forged letters to the regional Internet registry.

With IPv4 addresses becoming scarcer, a secondary market of dormant but assigned IPv4 addresses is likely to arise and one can be certain that those with less honest intentions will find ways to benefit from this market too. Registries ought to be aware of this issue and those in the anti-spam business - particularly those running IP blacklists - should ensure they respond swiftly to the abuse of hijacked IP addresses.

More at the blog of security journalist Brian Krebs here, with information on Mrs Mubarak's IP range at The Spamhaus Project here.

Posted on 01 February 2011 by Virus Bulletin

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

More on the Moose botnet at Botconf

At Botconf 2016 this week, GoSecure researchers Masarah Paquet-Clouston and Olivier Bilodeau presented their research on the Moose botnet - something Olivier Bilodeau previously spoke about at VB2015.

VB2016 paper: Defeating sandbox evasion: how to increase successful emulation rate in your virtualized environment

Today, we publish the VB2016 paper and presentation (recording) by Check Point Software researchers Alexander Chailytko and Stanislav Skuratovich, which focuses on the techniques used by malware to detect virtual environments, and provides detailed…

VB2016 paper: Mobile applications: a backdoor into the Internet of Things?

While the Internet of Things blossoms with newly connected objects every day, the security and privacy of these objects is often overlooked, making the IoT a major security concern. Unfortunately, reverse-engineering so-called smart devices is not an…

VB2016 paper: Wave your false flags! Deception tactics muddying attribution in targeted attacks

Today, we publish the VB2016 paper and presentation (recording) by Kaspersky Lab researchers Juan Andrés Guerrero-Saade and Brian Bartholomew, in which they look at some of the deception tactics used in targeted attacks.

Throwback Thursday: The Politics of Anti-Virus

President-elect of the United States Donald Trump made a number of promises about cybersecurity during his electoral campaign. What comes of those pledges remains to be seen, but one thing is certain: there will be a team of hard-working, dedicated…