Spam ISP McColo Cut Off From the Internet

Outsmart Malicious Hackers


You might recall we reported a while ago about ‘spam friendly’ ISP Intercage coming back online after having their plug pulled by upstream provider UnitedLayer.

They pledged to clean up their act though and drop their biggest client who was an Eastern European malware and phishing host.

This time another ISP has been suspected of hosting sites that partake in online crime, child pornography and phishing scams.

A U.S. Internet service provider suspected of aiding cybercriminals in online scams and hosting child pornography was at least partially cut off from the Internet on Tuesday night.

The ISP (Internet service provider), McColo, had been under the watchful eye of computer security analysts for years. It is one of a handful of so-called “bulletproof” hosting providers that provide safe haven online for cybercriminals selling Viagra and fake security software.

ISPs can connect with each other to exchange Internet traffic, a practice known as “peering.” Hurricane Electric, an ISP that carried a portion of McColo’s traffic, disconnected with McColo on Tuesday night. Global Crossing, an IP (Internet Protocol) network services provider also connected to McColo would not comment.

Any hosting provider that offers ‘bulletproof’ services rings alarm bells for me as that usually means they are willing to hide spammers/scammers and malware propagation as long as you keep paying the bills.

2 of their Internet peers have already disconnected them, you can see an interesting freemind map of some of the sites and activity they were linked to here.

The whole article can be found here: A Closer Look at McColo

The shutdown coincides with a damming new report authored by several computer security researchers who detail how McColo and other questionable service providers are linked to spam and cybercrime.

McColo’s shutdown “demonstrates that when presented with appropriate evidence of criminal activity, the Internet community can bring about the positive forces necessary to purge it,” the analysts wrote.

McColo, whose servers were located within the U.S., at one time hosted up to 40 Web sites with child pornography, the report said.

McColo also played a big role in spam distribution, said Richard Cox, CIO of Spamhaus, which tracks spamming operations. It hosted Web sites that could infect people’s computers with malicious software used for sending spam, he said.

Apparently there has been a noticeable drop in spam after McColo has been partially cut off from the Internet. There have been reports that a 60-75% reduction in overall spam has been measured after 2 of the McColo peers dropped them meaning the majority of their sites are unreachable.

That’s a huge amount coming from 1 ISP! I hope the other culprits in hosting such sites can be found and disconnected dropping the spam percentage to something that is easy for everyone to deal with.

Source: Network World

Posted in: Legal Issues, Spammers & Scammers

, , , , ,


Latest Posts:


OWASP ZSC - Obfuscated Code Generator Tool OWASP ZSC – Obfuscated Code Generator Tool
OWASP ZSC is an open source obfuscated code generator tool in Python which lets you generate customized shellcodes and convert scripts to an obfuscated script.
A Look Back At 2017 – Tools & News Highlights A Look Back At 2017 – Tools & News Highlights
So here we are in 2018, taking a look back at 2017, quite a year it was. Here is a quick rundown of some of the best hacking/security tools released in 2017, the biggest news stories and the 10 most viewed posts on Darknet as a bonus.
Spectre & Meltdown Checker - Vulnerability Mitigation Tool For Linux Spectre & Meltdown Checker – Vulnerability Mitigation Tool For Linux
Spectre & Meltdown Checker is a simple shell script to tell if your Linux installation is vulnerable against the 3 "speculative execution" CVEs that were made public early 2018.
Hijacker - Reaver For Android Wifi Hacker App Hijacker – Reaver For Android Wifi Hacker App
Hijacker is a native GUI which provides Reaver for Android along with Aircrack-ng, Airodump-ng and MDK3 making it a powerful Wifi hacker app.
Sublist3r - Fast Python Subdomain Enumeration Tool Sublist3r – Fast Python Subdomain Enumeration Tool
Sublist3r is a Python-based tool designed to enumerate subdomains of websites using OSINT. It helps penetration testers and bug hunters collect and gather subdomains for the domain they are targeting.
coWPAtty Download - Audit Pre-shared WPA Keys coWPAtty Download – Audit Pre-shared WPA Keys
coWPAtty is a C-based tool for running a brute-force dictionary attack against WPA-PSK and audit pre-shared WPA keys.


3 Responses to Spam ISP McColo Cut Off From the Internet

  1. ethicalhack3r November 17, 2008 at 5:18 pm #

    I have recently finished a presentation on Phishing attacks for university. I may mention this as a form of defence/protection. I have also included user awarness, administrator action and spam filtering. I never even thought of the fact that the administrators encoraged it.

  2. navin November 18, 2008 at 7:30 am #

    spam will be back up to speed by christmas……however it feels nice to hear, even if temporarily, tht the good guys won!!

  3. Greg November 19, 2008 at 10:15 am #

    Slashdot had a short info about McColo resurrected for short to hand on their CC to other Russian pals