Tuesday, April 28, 2009

Pre-mature call on images

The images are sill coming... the same 7 images

tc

Monday, April 27, 2009

Image Downdraft

Those images being sent as half of all spam over the weekend is now winding down. Tuesday am we will likely see the last of them. At this point they continue to find new domains by web-shills.

tc

Saturday, April 25, 2009

Stuborn or Stupid: Us or them?

This morning I check the incoming mail. 1140 of 2020 (56.4%) was of previously known images from spammers. The signature file identifying these images only contains 7 signatures.

tc

Spiked Email

blogspot report some blogs making into the spam pile that should not have. I am also reporting that they are using legitimate websites to spike incoming mail. These spikes turn out to be the only URL or payload. Apparently, someone besides me is on to them.

Even though this is old, it is apparent what is going on:
http://buzz.blogger.com/2008/08/spam-fridays.html

tc

Friday, April 24, 2009

Spam PNG Crashes with known SPAM payload

As hard as it was for me to image, it happened. I noticed a very high filter trapping number. 75% of the email was being trapped and deleted. It should have gone down, but it did not. A review of the logs indicated that it was likely another domain marked incorrectly. As such, I decide to download by hand and then review it.

To my shock, the match was a line from a base64 attachment. I then looked in the email itself. It had a spoofed email address, a spoofed email header, no text payload at all (no href, www, or email). It did have an attachment. I check the attachment header against known spam payload headers, it was on my list of known spam images.

The offending payload domain was xf.cz, which turns out to be a free-web-shill for webzdarma.cz, which offers free webpages/websites.

My job is getting easier daily.

tc

Thursday, April 23, 2009

Cleaned up at Interia.pl

It appears that spammers were found on interia.pl. The spam slowed drastically Weds morning, then ramped down throughout the day. It is a trickle now with less than 5 per hour being generated.

In the meantime, the incoming mail was swamped with previously known PNG images. I think the domain being something like 123123.com.

They also found another sling at shac.pdx.edu/redirect.php

tc

Wednesday, April 15, 2009

Another payload slinger

In past spammers have used the cgi from various commerical website to redirect the payload. Today is another example with log.go.com

http ://log.go.com/log?srvc=wczl&goto=http: //idknxn.konpafus.cn

I should note this start over the weekend.

tc

Tuesday, April 14, 2009

Massive breakdown at interia.pl

A few days ago I note my filter working too well. As a matter of fact, they were working correctly. It appears that interia.pl (a polish website) is the latest. I had registered it early but since it was polish, or at least foreign to me, I paid it no attention. It appears to be just another blogging site that will work well as a shill. The only issue is that I missed most of the subdomains they have been using.

tc

Today, 04-15-2009, I'm adding that I have a list of over 700 sub-domains in less than 24 hours.

tc

found filter bug

Somehow google.com had made it into filter. Which accounted for my 90+% trappings. Temporarily fixed it by removing it.

tc

Monday, April 13, 2009

add livejournal.com

It appears they have captcha on livejournal.com broken. It was a creeping start, but late last night they cranked up the subdomains coming my way. I have not reviewed their system. I'll take a look later.

tc

Sunday, April 12, 2009

Filters working too well.

Since late last night my filters are capturing 90% of the spam. It is hard to believe. In any case, I expect them (the spammers) back by Sunday - late.

tc

Friday, April 10, 2009

geocities tumbles & china is abandoned

In what appears to be the biggest break through of the year for spammers, the geocities Captcha is broken. Broken to the extend that they have abandoned chinese domains, and are now using in-place -- geocities.

I have reviewed the Captcha they are using and it appears they could have the repair in hand by the end of the weekend. It is now Friday. The question is: Will they? This is a cat and mouse game, and one has to wonder what Yahoo is up to. (Yahoo being the owner of geocities.)

In any case, it appears the spammers are on the run and will likely try a new tactic within three (3) weeks.

tc

Thursday, April 9, 2009

Geocities falls

It appears that the Captcha has been broken at geocities and groups.yahoo as they been flooding my inbox with those URLs.