Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > Fast Flux for Rent

    Sep21
    11:37 am (UTC-7)   |    by

    It looks like the Storm botnet is renting its services to different websites. In this case, we caught emails in our storm honeypot that look like storm emails:

    Pharmacy Spam from Storm botnet

    The domain names are taken from a pool of about 10. They are all .com and are not recognizable word names or brands. They all resolve to different DNS names hosted by the botnet fast-flux network. This means that every time you access one of these websites, a different member of the botnet will point your browser to the same pharmacy-related website. These pharmacies are the clients of the botnet so they must be paying big for being advertised by means of spammed messages and for redirecting users from the emails to the website, whose real domain you never see. This is living proof of the economics behind botnets.

    Here’s a screenshot of the pharmacy site:

    Pharmacy site advertised by the Storm botnet





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    Comments are closed.



     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice