« Spybot Search and Destroy Definitions Updated on 11/12/2008 | Blog Home | My Spam analysis for Nov 10 - 16, 2008 »

Spam volume drops after McColo servers forced offline

My incoming volume of Spam email has dwindled this week, steadily, since Tuesday, November 11. I have waited a few days to write about this in order to see how matters played out. Interestingly, Tuesday was also Veterans' Day in the USA and Armistice Day around the World. Coincidentally, there was a temporary armistice between the senders of spam and the targets of their spam messages. This armistice occurred around 1:30 PST in San Jose, California, USA.

Something major happened on Tuesday, November 11, 2008, that resulted in the huge drop in the volume of spam hitting my MailWasher Pro spam filtering program. It was on Tuesday afternoon, November 11, 2008, that Internet Backbone and Colocation Provider Hurricane Electric and global IP-based network Global Crossing terminated their Internet peering connections to the web server colocation hosting company known as McColo Corporation, located in San Jose, California. They did this after being presented with irrefutable evidence of long-term extreme badness being conducted by the hosting customers of McColo. It is estimated that up to 75% of the spam sent out on a daily basis is run by Command and Control servers hosted on machines at McColo's facilities. Without being commanded to receive new spam templates and then send out spam runs, the zombie PCs in numerous Botnets fell silent over the last few days.

This badness conducted by the McColo customers includes various unfriendly and illegal activities, including, but not limited to the following:


  • Hosting distribution machines for malware executables and browser exploits, to be served to innocent web surfers drawn there by trickery, to infect their computers with Trojans and make them members of botnets.

  • Command and Control over the World's most prolific Botnets, the members of which are remotely controlled to send spam, host malware laden web pages, or launch denial of service attacks on behalf of the Bot Masters.

  • Hosting fake anti virus and rogue anti spyware scanners, used to scam victims into paying for useless removal programs. The so-called removal programs in fact only remove the pop-up notices, or balloon messages, or phony screensavers or desktop backgrounds that are made to resemble a Windows BSOD. They operate in collusion as a tandem infection.

  • Hosting Phishing web sites that steal login credentials from banking customers, then empty their bank accounts, or make unauthorized purchases with their stolen credit card accounts.

  • Hosting of illegal child pornography.

  • Hosting of payment portals and systems by means of which cyber criminals receive payments.

  • Hosting servers that are used to store information stolen by means of Phishing or Dictionary attacks against innocent parties.

  • Databases containing the names and locations of Bot Masters, cyber criminals, pornographers and spammers.

  • The hosting of fake pharmacy websites and payment systems.

  • Launching DDoS attacks against the Republic of Georgia infrastructure and Government websites, and against other legitimate governments and companies.


McColo hosted the so-called command-and-control servers for botnets that are used to instruct PCs to send spam. The botnets included Rustock, Srizbi, Pushdo/Cutwail, Ozdok/Mega-D and Gheg, according to this report. If you are troubled by the sheer volume of spam that you must fight off everyday, take the time to read the report and you will gain a better understanding of how the cyber criminals behind these operations are able to conduct their illegal activities and where many of them are actually located.

The cyber criminals whose servers were taken offline when McColo went dark will eventually find other places to operate their servers and will rebuild their illegal businesses. In the meantime, you and I can enjoy a few days relief from the constant onslaught of spam that paralyzes our inboxes everyday. I can only hope that this shutdown will be a major inconvenience to them and will cost them a lot of time and money to rebuild. You and your friends can do your part by deleting all spam messages and by never ever buying anything that is spamvertised!

If you are in need of an effective spam filtering program that sits ahead of your email client, I use and recommend MailWasher Pro. MailWasher Pro intercepts your incoming POP3 email and filters out spam before you download it to your desktop email application.

Get Norton 360

Get Norton 360 Version 4.0 - All-In-One Security. If you have a non-current version of a Symantec security program and wish to renew your definition updates subscription, or upgrade to a new version at a discount, go to the Norton Product Upgrades & Renewals page.

About the author
Wiz FeinbergWiz's Blog is written by Bob "Wiz" Feinberg, an experienced freelance computer consultant, troubleshooter and webmaster. Wiz's specialty is in computer and website security. Wizcrafts Computer Services was established in 1996.

I produce this blog and website at my own expense. If you find this information valuable please consider making a donation via PayPal.


Malwarebytes' Anti-Malware is the most frequently recommended malware removal tool in malware removal forums, like Bleeping Computers. It is extremely effective for removing fake/rogue security alerts, Bots, Spyware and the most prevalent and current malware threats in the wild. Learn about Malwarebytes Anti-Malware.


MailWasher Pro is an effective spam filter that protects your desktop email client. Using a combination of blacklists and built-in and user configurable filters, MailWasher Pro recognizes and deletes spam before you download it. MailWasher Pro reveals the actual URL of any links in a message, which protects you from most Phishing scams. Try it free for 30 days. Pay $39.95 US once, for a lifetime license, with free upgrades.


Get Reliable Web Hosting

BlueHost Web Hosting $6.95

Do you want reliable, yet affordable shared website hosting, with US based phone, email and live chat tech support? If so, you should consider signing up with BlueHost. You can host Unlimited Domains and sub-domains on one account, each complete with their own FTP and Email Accounts. You get unlimited disk space, data transfer & databases, plus dozens of free secured scripts that are easy to install with a few clicks. cPanel Pro control panels support all current web technologies, logs and scripts. All new and transfer accounts are entitled to 1 free domain name and a $50 Google AdWords credit. Pay just $6.95/month, for 2 or 3 years, prepaid. No setup fee and a 30-day money back guarantee. Sign-up with BlueHost Here

Creative Commons License This weblog is licensed under a Creative Commons License.
The content on this blog may be reprinted provided you do not modify the content and that you give credit to Wizcrafts and provide a link back to the blog home page, or individual blog articles you wish to reprint. Commercial use, or derivative work requires written permission from the author.

Start your blog today