Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Clustering and Replication
    • Endpoint Management & Virtualization
    • Storage Management
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
MessageLabs IntelligenceRSS

Festi Botnet spins up to become one of the main spamming botnets

Daren Lewis
November 5th, 2009
Tags: Hosted Mail Security, Security, Spam, Spam, MessageLabs Intelligence
Facebook Twitter

Posted on behalf of Dan Bleaken, Malware Data Analyst

MessageLabs Intelligence has been tracking a new botnet, ‘Festi’ since the beginning of August.

Gradually, Festi has steadily increased its output of spam from virtually insignificant volumes up to 3-6% of daily spam.  In terms of spam volumes, 3-6% is estimated at a massive 1.5-3 billion spams per day globally.  This increase in output has been achieved both by gradually increasing the amount of spam sent from each Festi bot, and by recruiting new bots to the botnet.

20091105_01.gif

At the moment it is spewing out 2 variants of spam. 

The first variant, is ‘male enhancement‘ type mails containing .cn domains, leading to a Canadian Pharmacy Website

 20091105_02.gif

Typical subjects such as:
Paradise in your bed
Very-very Magic Stick
Strong stick
Magic stick
Hard stick tonight
All night long

Website:
20091105_03.gif 

The other variant is geared more towards the Christmas product spamming season, it’s watch spam containing links to .com domains:

 20091105_04.gif

Typical subjects such as:
casablanca leather band
classic automatic
submariner limited coca cola edition
classic quartz
omega de ville co axial chronograph
Hermes Watches

Website:
20091105_05.gif 

In terms of Festi’s global ranking among the botnets, Festi has become one of the spamming heavyweights.  Currently, Festi is fifth after the giant ‘Big-4’ botnets: Cutwail, Bagle, Grum and Rustock (which among them account for more than 80% of global spam).  I wonder how Festi’s relative dominace will develop over the coming weeks...

0 votes
  • Daren Lewis's blog
  • Login or register to post comments
  • Comments RSS Feed

About MessageLabs Intelligence Blog

The MessageLabs Intelligence blog serves as a conduit for communicating MessageLabs Intelligence data, trends and statistics. MessageLabs Team Skeptic™ comprises many world-renowned malware and spam experts, who have a global view of threats across multiple communication protocols drawn from the billions of web pages, email and IM messages they monitor each day on behalf of 21,000 clients in more than 102 countries.
Filter by:

Recent Blog Posts

  • Gumblar Botnet Ramps Up Activity
    MarissaVicario - January 21, 2010
  • As Haiti earthquake relief efforts continue, so do the spammers, phishers and scammers
    Paul Wood - January 20, 2010
  • MessageLabs Intelligence Tracks New Botnet
    MarissaVicario - January 15, 2010
    1 Replies
  • 419-Style Scammers Seeking to Exploit Appeal for Donations to Support Victims of Haitian Earthquake
    Paul Wood - January 14, 2010
  • 419-Style Scam Seeks "Muslim Brother or Sister" to Retrieve Funds from Alleged Christmas Airline Bomber
    Paul Wood - January 14, 2010

Recently on Twitter

messagelabs
  • Join us February for our SaaS breakfast seminar focused on messaging security. Register here: http://cot.ag/50i476
    February 05, 2010 | 10:36AM
  • The latest MessageLabs Intelligence Report and podcast for January 2010 has just been published here http://bit.ly/59o8EL
    January 22, 2010 | 5:05AM
  • Gumblar Botnet ramps us activity: http://bit.ly/7TsHeI
    January 21, 2010 | 11:15AM
  • Dan Bleaken has just posted an update on the MessageLabs Intelligence blog about the latest Haiti earthquake scams: http://bit.ly/4F3EyT
    January 20, 2010 | 4:16AM
  • In Boston, Chicago, Toronto, Houston? Attend our SaaS Messaging Security seminar. Register here: http://bit.ly/50i476
    January 19, 2010 | 10:01AM

Blog Tags

Backup and Archiving Emerging Threats Evolution of Security Hosted Mail Security Malicious Code Online Backup Online Fraud Online Storage for Backup Exec Security Security Security Risks Spam Vulnerabilities & Exploits
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Newsletter
  • Privacy Policy
  • Symantec.com