McColo on the move?

by certifiedbug on November 13, 2008

in Security

This still shows.

CIDR Report for AS26780
26780 MCCOLO - McColo Corporation
Adjacency: 1 Upstream: 1 Downstream: 0
Upstream Adjacent AS list
AS3549 GBLX Global Crossing Ltd.

Steve Linford from Spamhaus responding to a topic at Google Groups,
McColo Corp

Andreas Kohlbach wrote:

> Mccolo will (under a different name) find a new peer at some
> point, or already has, and in a couple of hours or days all is back where
> it was.

They already have, McColo are now coming back up on retn.net (AKA
Eltel, the old timers will remember that name, a very dirty Russian
network well known for hosting spammers and malware).

Which is a pity, as spam volumes dropped by 30% after McColo went off
the net late Tuesday as vast amounts of bots could no longer contact
their control boxes on McColo IPs and whole botnets went dark. Eltel
(retn.net) will be reactivating the McColo IPs anytime now allowing
the botnets to contact their masters and the spam will flow again.

Spamhaus is preparing to SBL Eltel (retn.net) as soon as we have
confirmation that they have brought McColo’s botnet control machines
back on line.

Steve Linford
The Spamhaus Project
http://www.spamhaus.org

Updates
Washington Post, A Closer Look at McColo

TRACE Blog
Srizbi Stopped, for now

FireEye Malware Intelligence Lab
http://blog.fireeye.com/research/2008/11/index.html

{ 0 comments… add one now }

Leave a Comment

You can use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Previous post: Firefox 3.0.4 Released

Next post: Thunderbird 2.0.0.17 released