Estonian ISP cuts off control servers for Srizbi botnet

27.11.2008

An algorithm within Srizbi would periodically generate new domain names where the malware would look for new instructions if those domains were live on the Internet. Armed with that same algorithm, the spammers had only to register the appropriate domain names and point them to their servers.

The spammers, however, needed a new ISP to host those servers, at least for a while. They found Starline Web Services, a very small ISP, but that provider has since also cut them off.

"I was satisfied that those sites were closed down," said Hillar Aarelaid, chief security officer for Estonia's Computer Emergency Response Team (CERT), on Thursday.

Attempts to contact Starline Web Services were unsuccessful. But Aarelaid said CERT has been in contact with the company, and it does appear to be responsive to complaints about abuse.

Starline Web Services buys its connectivity from Compic, another Estonian company. Compic has been flagged by Estonia's CERT as having Web sites hosting malicious software, said Tarmo Randel, an information security expert at the organization.