Friday, April 24, 2009

Spam PNG Crashes with known SPAM payload

As hard as it was for me to image, it happened. I noticed a very high filter trapping number. 75% of the email was being trapped and deleted. It should have gone down, but it did not. A review of the logs indicated that it was likely another domain marked incorrectly. As such, I decide to download by hand and then review it.

To my shock, the match was a line from a base64 attachment. I then looked in the email itself. It had a spoofed email address, a spoofed email header, no text payload at all (no href, www, or email). It did have an attachment. I check the attachment header against known spam payload headers, it was on my list of known spam images.

The offending payload domain was xf.cz, which turns out to be a free-web-shill for webzdarma.cz, which offers free webpages/websites.

My job is getting easier daily.

tc

No comments: