Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cloud
    • Cybersecurity
    • Virtualization

    Microsoft Uncovers 400K Tainted Email Addresses on Rustock Hard Drives

    Written by

    Fahmida Y. Rashid
    Published May 24, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Microsoft investigators have uncovered more than 400,000 email addresses from a single hard drive seized during the Rustock botnet takedown in March, according to court documents. The Rustock gang also had stolen credit card numbers.

      Microsoft outlined its investigation into the hard drives belonging to the botnet’s command and control servers in a status report to the United States District Court for the Western District of Washington on May 23. Microsoft researchers had been analyzing and studying the hardware seized by the U.S. Marshals Service and other law enforcement agencies during the March 17 raid, Network World reported May 24.

      The investigators uncovered “additional evidence” that the seized servers had been part of the botnet’s “spam-dissemination,” Microsoft told U.S. District Judge James Robart in the filing. The hard drives contained custom software that assembled spam messages and text files containing thousands of email addresses and username/password combinations. Microsoft also found evidence that criminals had used stolen credit card numbers to purchase hosting and email services.

      “One text file alone contained over 427,000 e-mail addresses,” Microsoft wrote.

      Microsoft has found a clue that hinted the Rustock owners were based in Russia. The payments for some of the hosting services were traced to a specific Webmoney account. Webmoney is an electronic money and online payment system very popular among Russian clients. Webmoney helped Microsoft trace the account back to a Vladimir Alexandrovich Shergin of Khimki, a city 14 miles northwest of Moscow.

      Microsoft acknowledged in the status filing that the actual person who bought the C&C servers’ hosting services may be someone else.

      “Microsoft is continuing its investigation to determine whether the name and contact information are authentic, whether this is a stolen identity and whether this person is associated with the events in this action,” the company said.

      Tracking down the botnet’s origins was a challenge because 18 of the 20 drives seized in the raid had been used as Tor nodes to anonymize Internet traffic. Tor routes Internet traffic through volunteer computers and is often used by activists to hide their activities from government censorship as well as by criminals hoping to avoid detection.

      The Rustock botnet is estimated to have had about 1 million compromised machines under its control and was capable of sending up to 30 billion spam messages per day. Microsoft obtained a restraining order from the U.S. District Court for the Western District of Washington giving the U.S. Marshals and other law enforcement authority to seize the C&C servers hosted in facilities in seven U.S. cities.

      However, it doesn’t appear that the March shutdown had any long-term impact on global spam levels. Spam levels declined 2 percent to 3 percent shortly after the takedown, but then returned to normal levels, Kaspersky Lab found in its quarterly spam report.

      Spam accounted for a little less than 80 percent of total email volume in the first quarter of 2011, which was 1.4 percent more than the last quarter of 2010, but 6.5 percent less than the first quarter of 2010. In its monthly spam report for April, Kaspersky Lab reported the amount of spam increased by 1.2 percentage points compared with March, and averaged 80.8 percent of total email volume.

      “The closure of the Rustock botnet command centres on 16 March 2011 did not impact spam traffic as dramatically as last year’s Pushdo, Cutwail and Bredolab closures,” Kaspersky researchers said in the quarterly report.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×