Festi Botnet spins up to become one of the main spamming botnets
Posted on behalf of Dan Bleaken, Malware Data Analyst
MessageLabs Intelligence has been tracking a new botnet, ‘Festi’ since the beginning of August.
Gradually, Festi has steadily increased its output of spam from virtually insignificant volumes up to 3-6% of daily spam. In terms of spam volumes, 3-6% is estimated at a massive 1.5-3 billion spams per day globally. This increase in output has been achieved both by gradually increasing the amount of spam sent from each Festi bot, and by recruiting new bots to the botnet.
At the moment it is spewing out 2 variants of spam.
The first variant, is ‘male enhancement‘ type mails containing .cn domains, leading to a Canadian Pharmacy Website
Typical subjects such as:
Paradise in your bed
Very-very Magic Stick
Strong stick
Magic stick
Hard stick tonight
All night long
Website:
The other variant is geared more towards the Christmas product spamming season, it’s watch spam containing links to .com domains:
Typical subjects such as:
casablanca leather band
classic automatic
submariner limited coca cola edition
classic quartz
omega de ville co axial chronograph
Hermes Watches
Website:
In terms of Festi’s global ranking among the botnets, Festi has become one of the spamming heavyweights. Currently, Festi is fifth after the giant ‘Big-4’ botnets: Cutwail, Bagle, Grum and Rustock (which among them account for more than 80% of global spam). I wonder how Festi’s relative dominace will develop over the coming weeks...
- Daren Lewis's blog
- Login or register to post comments
- Comments RSS Feed
About MessageLabs Intelligence Blog
The MessageLabs Intelligence blog serves as a conduit for communicating MessageLabs Intelligence data, trends and statistics. MessageLabs Team Skeptic™ comprises many world-renowned malware and spam experts, who have a global view of threats across multiple communication protocols drawn from the billions of web pages, email and IM messages they monitor each day on behalf of 21,000 clients in more than 102 countries. Recent Blog Posts
- MarissaVicario - January 21, 2010
- Paul Wood - January 20, 2010
-
MarissaVicario
-
January 15, 2010
1 Replies
- Paul Wood - January 14, 2010
- Paul Wood - January 14, 2010
Recently on Twitter
- Join us February for our SaaS breakfast seminar focused on messaging security. Register here: http://cot.ag/50i476February 05, 2010 | 10:36AM
- The latest MessageLabs Intelligence Report and podcast for January 2010 has just been published here http://bit.ly/59o8ELJanuary 22, 2010 | 5:05AM
- Gumblar Botnet ramps us activity: http://bit.ly/7TsHeIJanuary 21, 2010 | 11:15AM
- Dan Bleaken has just posted an update on the MessageLabs Intelligence blog about the latest Haiti earthquake scams: http://bit.ly/4F3EyTJanuary 20, 2010 | 4:16AM
- In Boston, Chicago, Toronto, Houston? Attend our SaaS Messaging Security seminar. Register here: http://bit.ly/50i476January 19, 2010 | 10:01AM