Very Large BOT activates

As of about 36 hours ago, another large bot activated in order to send spam and perform dictionary attacks. And as usual, this could have been mitigated if more ISP’s blocked port 25 outbound. This BOT was substantial enough to almost double a mail servers bandwidth, even when rejecting the message in the SMTP layer.

This BOT is only slightly interesting from a technical nature, as the BOT uses ‘CamelCase’ SMTP commands, and uses the same MAIL FROM as the RCPT TO.

For Example:

Issues EHLO (not HELO)
Mail From: <someuser@localdomain.com>
Rcpt To: <someuser@localdomain.com>

There are a lot of invalid email addresses tested as well, so this bot can also be considered a form of dictionary attack to identify legitimate email addresses as well.

(This is one more reason to NEVER whitelist your own email address or domain)

Also, the bot is active on windows machines themselves, rather than a CPE compromise. It also doesn’t follow standard practices, or handle rejections for invalid users, terminating the connection rather than sending a quit in response to invalid users.

The BOT itself is trivial to detect as spam, and shouldn’t affect anyone’s inboxes, but it does consume resources and bandwidth.

BTW, just to give you an idea of one ISP who should lock down their dynamic IP SPace, here is some of their infected space:

180.180.80.175 node-fxr.pool-180-180.dynamic.totbb.net
180.180.94.134 node-io6.pool-180-180.dynamic.totbb.net
180.180.130.146 node-psi.pool-180-180.dynamic.totbb.net
180.180.166.94 node-wv2.pool-180-180.dynamic.totbb.net
182.52.255.206 node-1ej2.pool-182-52.dynamic.totbb.net
182.53.4.181 node-xh.pool-182-53.dynamic.totbb.net
182.53.26.14 node-55a.pool-182-53.dynamic.totbb.net
182.53.26.158 node-59a.pool-182-53.dynamic.totbb.net
182.53.47.202 node-9fu.pool-182-53.dynamic.totbb.net
182.53.54.217 node-au1.pool-182-53.dynamic.totbb.net
182.53.63.9 node-cg9.pool-182-53.dynamic.totbb.net
182.53.76.0 node-f0g.pool-182-53.dynamic.totbb.net
182.53.83.253 node-gl9.pool-182-53.dynamic.totbb.net
182.53.97.25 node-j6h.pool-182-53.dynamic.totbb.net
182.53.104.254 node-kqm.pool-182-53.dynamic.totbb.net
182.53.134.93 node-qjh.pool-182-53.dynamic.totbb.net
182.53.135.13 node-qod.pool-182-53.dynamic.totbb.net
182.53.137.57 node-r3t.pool-182-53.dynamic.totbb.net
182.53.157.141 node-v4d.pool-182-53.dynamic.totbb.net
182.53.189.63 node-11dr.pool-182-53.dynamic.totbb.net
182.53.205.228 node-14o4.pool-182-53.dynamic.totbb.net
182.53.223.36 node-182s.pool-182-53.dynamic.totbb.net
182.53.229.207 node-19e7.pool-182-53.dynamic.totbb.net
182.53.255.4 node-1edg.pool-182-53.dynamic.totbb.net
1.0.128.203 node-5n.pool-1-0.dynamic.totbb.net
1.0.138.190 node-24e.pool-1-0.dynamic.totbb.net
1.0.199.94 node-e3i.pool-1-0.dynamic.totbb.net
1.0.205.96 node-fa8.pool-1-0.dynamic.totbb.net
1.0.212.91 node-gnv.pool-1-0.dynamic.totbb.net
1.0.218.229 node-hyd.pool-1-0.dynamic.totbb.net
1.0.233.45 node-krx.pool-1-0.dynamic.totbb.net
1.1.130.129 node-ht.pool-1-1.dynamic.totbb.net
1.1.132.142 node-we.pool-1-1.dynamic.totbb.net
1.1.173.223 node-927.pool-1-1.dynamic.totbb.net
1.1.190.214 node-ceu.pool-1-1.dynamic.totbb.net
1.1.195.36 node-d9g.pool-1-1.dynamic.totbb.net
1.1.197.45 node-dnx.pool-1-1.dynamic.totbb.net
1.1.220.179 node-ib7.pool-1-1.dynamic.totbb.net
1.1.225.129 node-j9d.pool-1-1.dynamic.totbb.net
1.1.252.230 node-oo6.pool-1-1.dynamic.totbb.net
1.2.135.14 node-1e6.pool-1-2.dynamic.totbb.net
1.2.140.141 node-2h9.pool-1-2.dynamic.totbb.net
1.2.173.115 node-8z7.pool-1-2.dynamic.totbb.net
1.2.194.253 node-d8d.pool-1-2.dynamic.totbb.net
1.2.216.197 node-hj9.pool-1-2.dynamic.totbb.net
1.4.129.86 node-9i.pool-1-4.dynamic.totbb.net
1.4.141.192 node-2ps.pool-1-4.dynamic.totbb.net
1.4.152.215 node-4wn.pool-1-4.dynamic.totbb.net
1.4.154.0 node-54w.pool-1-4.dynamic.totbb.net
1.4.163.207 node-72n.pool-1-4.dynamic.totbb.net
1.4.186.70 node-bie.pool-1-4.dynamic.totbb.net
1.4.190.50 node-caa.pool-1-4.dynamic.totbb.net
1.4.203.233 node-ezt.pool-1-4.dynamic.totbb.net
1.4.204.159 node-f4v.pool-1-4.dynamic.totbb.net
1.4.204.160 node-f4w.pool-1-4.dynamic.totbb.net
1.4.205.179 node-fcj.pool-1-4.dynamic.totbb.net
1.10.193.12 node-cuk.pool-1-10.dynamic.totbb.net
1.10.195.70 node-dae.pool-1-10.dynamic.totbb.net
1.10.199.38 node-e1y.pool-1-10.dynamic.totbb.net
1.10.199.207 node-e6n.pool-1-10.dynamic.totbb.net
1.10.201.24 node-efs.pool-1-10.dynamic.totbb.net
1.10.201.38 node-eg6.pool-1-10.dynamic.totbb.net
1.10.201.147 node-ej7.pool-1-10.dynamic.totbb.net
1.10.203.9 node-etl.pool-1-10.dynamic.totbb.net
1.10.203.48 node-euo.pool-1-10.dynamic.totbb.net
1.10.205.60 node-f98.pool-1-10.dynamic.totbb.net
1.10.209.17 node-g0h.pool-1-10.dynamic.totbb.net
1.10.209.98 node-g2q.pool-1-10.dynamic.totbb.net
1.10.218.123 node-hvf.pool-1-10.dynamic.totbb.net
1.10.223.77 node-itp.pool-1-10.dynamic.totbb.net
1.10.223.127 node-iv3.pool-1-10.dynamic.totbb.net
1.10.229.164 node-k2s.pool-1-10.dynamic.totbb.net
1.10.244.23 node-mxj.pool-1-10.dynamic.totbb.net
1.10.247.98 node-nky.pool-1-10.dynamic.totbb.net
1.10.249.29 node-nx9.pool-1-10.dynamic.totbb.net
1.10.249.34 node-nxe.pool-1-10.dynamic.totbb.net
1.10.253.82 node-or6.pool-1-10.dynamic.totbb.net
1.10.255.4 node-p38.pool-1-10.dynamic.totbb.net
1.10.255.6 node-p3a.pool-1-10.dynamic.totbb.net
1.10.255.22 node-p3q.pool-1-10.dynamic.totbb.net
101.51.1.91 node-9n.pool-101-51.dynamic.totbb.net
101.51.7.226 node-1k2.pool-101-51.dynamic.totbb.net
101.51.18.125 node-3nh.pool-101-51.dynamic.totbb.net
101.51.18.164 node-3ok.pool-101-51.dynamic.totbb.net
101.51.28.108 node-5m4.pool-101-51.dynamic.totbb.net
101.51.35.87 node-6zb.pool-101-51.dynamic.totbb.net
101.51.36.61 node-75p.pool-101-51.dynamic.totbb.net
101.51.58.85 node-bit.pool-101-51.dynamic.totbb.net
101.51.58.178 node-ble.pool-101-51.dynamic.totbb.net
101.51.68.192 node-dkw.pool-101-51.dynamic.totbb.net
101.51.73.92 node-eho.pool-101-51.dynamic.totbb.net
101.51.88.181 node-hit.pool-101-51.dynamic.totbb.net
101.51.97.255 node-jcv.pool-101-51.dynamic.totbb.net
101.51.99.204 node-jpo.pool-101-51.dynamic.totbb.net
101.51.120.124 node-nss.pool-101-51.dynamic.totbb.net
101.51.120.234 node-nvu.pool-101-51.dynamic.totbb.net
101.51.121.16 node-nww.pool-101-51.dynamic.totbb.net
101.51.122.170 node-o8a.pool-101-51.dynamic.totbb.net
101.51.125.60 node-oqk.pool-101-51.dynamic.totbb.net
101.51.126.67 node-oxv.pool-101-51.dynamic.totbb.net
101.51.126.248 node-p2w.pool-101-51.dynamic.totbb.net
101.51.130.83 node-pqr.pool-101-51.dynamic.totbb.net
101.51.137.142 node-r66.pool-101-51.dynamic.totbb.net
101.51.143.160 node-sdc.pool-101-51.dynamic.totbb.net
101.51.159.241 node-vld.pool-101-51.dynamic.totbb.net
101.51.176.38 node-ysm.pool-101-51.dynamic.totbb.net
101.51.176.42 node-ysq.pool-101-51.dynamic.totbb.net
101.51.176.113 node-yup.pool-101-51.dynamic.totbb.net
101.51.176.206 node-yxa.pool-101-51.dynamic.totbb.net
101.51.178.64 node-z7k.pool-101-51.dynamic.totbb.net
101.51.194.52 node-12d0.pool-101-51.dynamic.totbb.net
101.51.226.143 node-18r3.pool-101-51.dynamic.totbb.net
101.108.3.87 node-nr.pool-101-108.dynamic.totbb.net
101.108.18.182 node-3p2.pool-101-108.dynamic.totbb.net
101.108.38.177 node-7n5.pool-101-108.dynamic.totbb.net
101.108.82.176 node-gc0.pool-101-108.dynamic.totbb.net
101.108.84.244 node-gs4.pool-101-108.dynamic.totbb.net
101.108.86.91 node-h23.pool-101-108.dynamic.totbb.net
101.108.87.24 node-h7c.pool-101-108.dynamic.totbb.net
101.108.90.252 node-hz0.pool-101-108.dynamic.totbb.net
101.108.93.244 node-ik4.pool-101-108.dynamic.totbb.net
101.108.107.176 node-l9s.pool-101-108.dynamic.totbb.net
101.108.155.219 node-usb.pool-101-108.dynamic.totbb.net
101.108.248.17 node-1d01.pool-101-108.dynamic.totbb.net
118.172.42.226 node-8gy.pool-118-172.dynamic.totbb.net
118.173.86.241 node-h69.pool-118-173.dynamic.totbb.net
118.173.86.247 node-h6f.pool-118-173.dynamic.totbb.net
118.173.87.110 node-h9q.pool-118-173.dynamic.totbb.net
118.173.246.158 node-1cpq.pool-118-173.dynamic.totbb.net
118.174.62.83 node-2tv.pool-118-174.dynamic.totbb.net
118.174.68.165 node-x1.pool-118-174.dynamic.totbb.net
118.174.88.85 node-4t1.pool-118-174.dynamic.totbb.net
118.174.169.161 node-1wh.pool-118-174.dynamic.totbb.net
118.174.181.114 node-48i.pool-118-174.dynamic.totbb.net
118.174.182.165 node-4h1.pool-118-174.dynamic.totbb.net
118.174.191.0 node-64g.pool-118-174.dynamic.totbb.net
118.174.215.154 node-1i2.pool-118-174.dynamic.totbb.net
118.174.215.193 node-1j5.pool-118-174.dynamic.totbb.net

This entry was posted in Informative and tagged , , , . Bookmark the permalink.

Leave a Reply