Taiwan Kings of Spam from CipherTrust


Hmm Taiwan are really way ahead of everyone when it comes to being a spam hub, sadly that’s nothing to be proud of and generally it’s due to a large amount of poorly configured/unsecured servers.

Taiwan needs to start doing some vulnerability assessment! Taiwan and Korea have always had loads of open proxies/exploitable machines in my experience and when reporting such problems language is always an issue.

Almost two thirds (64 per cent) of servers controlling spam traffic are located in Taiwan, according to a survey by email security firm CipherTrust.

Such servers, used by internet low lives to relay spam and phishing emails through zombie, compromised PCs, are also commonly located in the US. The US accounts for 23 per cent of the machines identified on CipherTrust’s spam server blacklist with China in a fairly distant third place (three per cent).

Sounds like a pretty neat method they employed to get the figures.

CipherTrust obtained its figures after deploying a network of zombie-like machines across the world to gather intelligence on spamming operations. While machines in this “zombie honey pot” avoid relaying spam or phishing attacks to end-users, they collect messages from spammers trying to control them. By capturing these messages, CipherTrust is able to determine the location of the spam servers. Spammers themselves, of course, may be located somewhere completely different, such as Boca Raton, USA (for example).

Source: The Register

Posted in: Spammers & Scammers

, ,


Latest Posts:


HELK - Open Source Threat Hunting Platform HELK – Open Source Threat Hunting Platform
The Hunting ELK or simply the HELK is an Open-Source Threat Hunting Platform with advanced analytics capabilities such as SQL declarative language, graphing etc
trape - OSINT Analysis Tool For People Tracking Trape – OSINT Analysis Tool For People Tracking
Trape is an OSINT analysis tool, which allows people to track and execute intelligent social engineering attacks in real-time.
Fuzzilli - JavaScript Engine Fuzzing Library Fuzzilli – JavaScript Engine Fuzzing Library
Fuzzilii is a JavaScript engine fuzzing library, it's a coverage-guided fuzzer for dynamic language interpreters based on a custom intermediate language.
OWASP APICheck - HTTP API DevSecOps Toolset OWASP APICheck – HTTP API DevSecOps Toolset
APICheck is an HTTP API DevSecOps toolset, it integrates existing tools, creates execution chains easily and is designed for integration with 3rd parties.
trident - Automated Password Spraying Tool trident – Automated Password Spraying Tool
The Trident project is an automated password spraying tool developed to be deployed on multiple cloud providers and provides advanced options around scheduling
tko-subs - Detect & Takeover Subdomains With Dead DNS Records tko-subs – Detect & Takeover Subdomains With Dead DNS Records
tko-subs is a tool that helps you to detect & takeover subdomains with dead DNS records, this could be dangling CNAMEs point to hosting services and more.


Comments are closed.