Cleaning up after the Nr 3 SPAM botnet and the worst prefix
By Erik Bais – RIPE75
1
October, 2017
Cleaning up after the Nr 3 SPAM botnet and the worst prefix By Erik - - PowerPoint PPT Presentation
Cleaning up after the Nr 3 SPAM botnet and the worst prefix By Erik Bais RIPE75 October, 2017 1 A bit of background Taking down of the largest GRUM bot network A nice read about this whole story :
By Erik Bais – RIPE75
1
October, 2017
Taking down of the largest GRUM bot network
unplugged/
effects..
2
Source: Symantec Message Labs
3
zombie’s …
4
(zombies) … dormant ..
with a signature.. Once per day .. And later per hour ..
be held responsible for that ..
5
6
7
Shadowserver for building the right infra for a new feed.
this infrastructure in place !!
8
9
– Report each hour on each unique IP connection.. Instead of each day.. – Use abuse mailbox info in the IRR DB’s and send each hour in x-arf.
10
11
12
didn’t matched the reports correctly to their ‘offending’ customers
– Lesson learned : don’t include the sinkhole IP in the abuse reports.
13
14
the LIR with IP space from a Dutch bulletproof hoster …
was planning to sell his IP space.
15
16
17
18
19
20
filtering for instance.
21
22
someone elses actions or lack of that..
23
after the IP transfer.
24
25
Almost all IP ranges can be cleaned .. But some historic issues, take a HUGE amount of time/effort to clean. And some people would be more than happy to help you.. You might be able to get a good deal as long as you don’t mind null-routing some of the old C&C IP’s in a /19 or so.
Feel free to contact us if you have any questions
27
ADDRESS
De Hoefsmid 13 1851PZ Heiloo The Netherlands
sales@prefixbroker.net
PHONE
+31 85 902 0417