Cutwail botnet sent 1.7 trillion spam messages

Posted by   Virus Bulletin on   Mar 18, 2011

Operators made several million through botnet.

Researchers from The Last Line of Defense and universities in Bochum and Santa Barbara have shared some insight into the workings of the Cutwail botnet (also known as Pushdo) after having managed to gain access to its command and control (C&C) servers.

Using the logs of the C&C servers to which they had access (estimated to represent between half and two-thirds of the total number of active Cutwail servers), the researchers were able to ascertain an exact figure for the number of spam emails sent. Between June 2009 and August 2010, these servers sent over 1.7 trillion spam messages - an average of well over 3 billion per day.

The fact that spammers have begun to care not just about sending but also about delivering messages could also be seen from the servers' logs, which recorded that 500 billion messages (just over 30% of the messages sent) were accepted during the SMTP transaction. Blacklists, invalid addresses and SMTP errors are likely to be the main reasons for the other messages not being delivered.

Even with only a small fraction of these 500 billion messages getting past spam filters and reaching users' inboxes, it is not surprising that the owners of Cutwail made a lot of money through renting out parts of their botnet. The researchers estimated the profits to be between $1.7 and $4.2 million.

As a result of the researchers' work the C&C servers to which they had access were taken offline, causing the amount of spam sent through Cutwail to drop significantly. However, the researchers showed little optimism about the long-term success of their efforts, suggesting the money to be made and the low risk, will always make crooks build ever more resilient botnets.

The full paper, which will be presented at the LEET '11 workshop later this month can be found here (PDF), while Threatpost has a long summary here.

Readers may also be interested in the article (requires free registration) by Fortinet's Kyle Yang on the Cutwail botnet, which was published in Virus Bulletin in February 2010.

Posted on 18 March 2011 by Virus Bulletin



Latest posts:

Standalone product test: FireEye Endpoint

Virus Bulletin ran a standalone test on FireEye's Endpoint Security solution.

VB2017 video: Consequences of bad security in health care

Jelena Milosevic, a nurse with a passion for IT security, is uniquely placed to witness poor security practices in the health care sector, and to fully understand the consequences. Today, we publish the recording of a presentation given by Jelena at…

Vulnerabilities play only a tiny role in the security risks that come with mobile phones

Both bad news (all devices were pwnd) and good news (pwning is increasingly difficult) came from the most recent mobile Pwn2Own competition. But the practical security risks that come with using mobile phones have little to do with vulnerabilities.

VB2017 paper: The (testing) world turned upside down

At VB2017 in Madrid, industry veteran and ESET Senior Research Fellow David Harley presented a paper on the state of security software testing. Today we publish David's paper in both HTML and PDF format.

VB2017 video: Turning Trickbot: decoding an encrypted command-and-control channel

Trickbot, a banking trojan which appeared this year, seems to be a new, more modular, and more extensible malware descendant of the notorious Dyre botnet trojan. At VB2017, Symantec researcher Andrew Brandt presented a walkthrough of a typical…