Since the spammer are not throwing anything new, I decided to try a test. I took several hundred bounced emails and looked for a URL (http://etc). After the usual clean up, I got about 75 domain names. Of that, 50 names were already in my database. This means that possibly 30+% are have not made it to my filters. I say 30+% because a few of the domain names look legit.
I should note that I have additional sets of old spam, some going back 4 years.
tc
Thursday, January 8, 2009
Tuesday, January 6, 2009
Back to the oldies
The return of spammers might be marked with the oldie, but goodie.
It is:
"Look out for spam, follow this URL for more information."
Of course, this URL belongs to a spammer.
tc
It is:
"Look out for spam, follow this URL for more information."
Of course, this URL belongs to a spammer.
tc
Saturday, January 3, 2009
w3.org trap
Well aware of this issue, it just went past me recently. Since I am mining for the URL payload, sometimes the software gets confused (or should i say the operator gets confused) and errors happen. In this case, the URL is http://www.w3.org/. Since a few spammers use this in the HTML header, it is easy to get it in the blacklist of payoff domains. That is, if you forget to delete it when you see it. (Which I did)
tc
tc
Thursday, December 25, 2008
Unmanned Spam?
The mail run at 12:00 (noon) and 14:00 had a 100% trapping, indicating an error in the first filter. The sole word "com" had made it in. The, perhaps, unseen enlightenment is the "100% trapping". "com" was in 100% of the mail. That is to say, which "com"? My domain, or their spam? If so, can I do something with this. If so, it is not clear.
21:18 - Noting: the last two mailruns are of low volume (161 & 170)
tc
21:18 - Noting: the last two mailruns are of low volume (161 & 170)
tc
Wednesday, December 17, 2008
Small correction
While the volume is large, it appears the spammers are working through their stockpile of old domainnames. Maybe they are on vaction.
tc
tc
Tuesday, December 16, 2008
Volume up, but no tricks
It's not clear what is going on. Currently, spam volume is normal, but the pace is erratic. (As an example, one batch may have 300, the next 125.) In addition, it looks like domain names are being thrown out. There is no evidence of hiding the payload by any kind of encoding; just straight plain HTML in most cases. Even URL wrapping has been abandoned.
tc
tc
Thursday, December 11, 2008
First note on back to normal
I've noted over the last few days many reports that things have reverted with spam and all things have return to normal (so to speak). The break was nice, but now I can report the volume is back and the tricks remain the same. Just enough to be out of the range of automation.
tc
tc
Subscribe to:
Posts (Atom)