UPDATE:  Although the below is still interesting data, Telia has withdrawn the routes for McColo’s net blocks

As we were monitoring Srizbi and Rustock in our labs today, all of a sudden a sample from the lab started connecting to a routable  McColo C&C server. This McColo hosted C&C server, with an IP of, was again fully responding to Rustock.  It appears they’re back!  The best part about this story is that they haven’t physically moved their servers… they’re still in Market Post Tower in sunny San Jose.  Telia (whom I contacted) appears to have low enough standards that they are providing McColo a new cross-connect.

This was the Rustock’s initial communication just recorded a few minutes ago:

In order to see which ISP started to provide route McColo again, I did a simple traceroute.  Here are the results:

If I were McColo, I would try to get my IPs routed as quickly as possible, if only for a few days before they are down again.  This would be to push out a global update to my Botnets to either change the C&C server, or to create a proper fallback Command and Control channel.

  1. I also contacted Telia yesterday and heard back from Jimmy Arvidsson, head of TeliaSoneraCERT, who said they’re taking action to revoke the peering (indeed, as of right now they seem to be unroutable again). Was great to get such a quick response. Hopefully they’ll stay that way a bit longer this time, though as you noted it’s already too late to stop the Rustock migration.

  2. Great work guys!
    Keep up the pressure. This is the easiest way to keep these f***ers down: kick them while they’re down.
    I once chased another (Russian) rogue spam network off about a dozen providers until they gave up. ISPs seem to be much more responsive when you alert them proactively about potential problem customers with evidence to back it up, rather than if you contact them six months afterwards when the client has already established a relationship (with checks…) with the ISP.

