Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Clustering and Replication
    • Endpoint Management & Virtualization
    • Storage Management
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
MessageLabs IntelligenceRSS

Mega-D (aka Ozdok) crippled

Daren Lewis
November 11th, 2009
Tags: Hosted Mail Security, Security, Spam, Spam, MessageLabs Intelligence
Facebook Twitter

This post is made on behalf of my colleague Mathew Nisbet, Malware Data Analyst

Researchers at the Fireeye intelligence lab recently decided to attempt to take down the Mega-D botnet after doing detailed analysis of its inner workings. It seems their actions have been very successful indeed, as our monitoring shows a huge decline in this previously prolific botnet’s activity.

Mega-D was the botnet that took the biggest advantage of the takedown of the McColo ISP in November 2008, becoming the biggest of all the spam botnets. Since then, others (such as Rustock, Bagle, Grum, and Cutwail) have gained strength, but Mega-D has consistently been in the top 10 spam bots. Or at least it was, until the 4th of November, when it was hit, and hit hard.

This shows the number of unique IP’s seen on our systems on a daily basis for the Mega-D botnet. Normally between 600 and 1600 IP’s are seen each day, but you can see quite clearly that after the 4th that it plummeted down to less than 50.

20091111_01B.gif

Competition for Spam ‘market share’ has always been fierce among the top botnets, with the top spammer often changing hourly, but there are a few usual suspects which are always in the top 10. Consistent with the above chart, this shows how Mega-D’s ‘market share’ has now dropped to a mere fraction of a percent. It now barely registers as existing, with only a few spam seen each day, rather than thousands.

20091111_02B.gif

It is unlikely that the botnet will ever be completely wiped out, but the efforts of the Fireeye team have crippled Mega-D to the point where it will be a long time (if indeed, ever) before it is able to regain its former standing.

0 votes
  • Daren Lewis's blog
  • Login or register to post comments
  • Comments RSS Feed

About MessageLabs Intelligence Blog

The MessageLabs Intelligence blog serves as a conduit for communicating MessageLabs Intelligence data, trends and statistics. MessageLabs Team Skeptic™ comprises many world-renowned malware and spam experts, who have a global view of threats across multiple communication protocols drawn from the billions of web pages, email and IM messages they monitor each day on behalf of 21,000 clients in more than 102 countries.
Filter by:

Recent Blog Posts

  • Gumblar Botnet Ramps Up Activity
    MarissaVicario - January 21, 2010
  • As Haiti earthquake relief efforts continue, so do the spammers, phishers and scammers
    Paul Wood - January 20, 2010
  • MessageLabs Intelligence Tracks New Botnet
    MarissaVicario - January 15, 2010
    1 Replies
  • 419-Style Scammers Seeking to Exploit Appeal for Donations to Support Victims of Haitian Earthquake
    Paul Wood - January 14, 2010
  • 419-Style Scam Seeks "Muslim Brother or Sister" to Retrieve Funds from Alleged Christmas Airline Bomber
    Paul Wood - January 14, 2010

Recently on Twitter

messagelabs
  • Interested in learning how to apply a #SaaS strategy for messaging security? Register to attend our breakfast seminar: http://cot.ag/50i476
    February 09, 2010 | 10:01AM
  • Join us February for our SaaS breakfast seminar focused on messaging security. Register here: http://cot.ag/50i476
    February 05, 2010 | 10:36AM
  • The latest MessageLabs Intelligence Report and podcast for January 2010 has just been published here http://bit.ly/59o8EL
    January 22, 2010 | 5:05AM
  • Gumblar Botnet ramps us activity: http://bit.ly/7TsHeI
    January 21, 2010 | 11:15AM
  • Dan Bleaken has just posted an update on the MessageLabs Intelligence blog about the latest Haiti earthquake scams: http://bit.ly/4F3EyT
    January 20, 2010 | 4:16AM

Blog Tags

Backup and Archiving Emerging Threats Evolution of Security Hosted Mail Security Malicious Code Online Backup Online Fraud Online Storage for Backup Exec Security Security Security Risks Spam Vulnerabilities & Exploits
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Newsletter
  • Privacy Policy
  • Symantec.com