Wednesday, March 11, 2009

More social network spam

Earlier this week they hit classmates, today they hit facebook. Someone will fall for it.

tc

Sunday, February 1, 2009

Some Magic Numbers

I've estimated 8-10 new domains per hour during "idle spam time", that being the time when spammer are apparently not actively sending spam, but letting the bots do the work.

Given 24 hours in a day and 365 days in a year, that is 8760 hours per year.

This means about 87,600 but my numbers indicate something much lower - about 15,000 per year.

More stats needed.

Even so, it mean between $150,000 and $876,000 per year just on domain names.

tc

Monday, January 26, 2009

Trojan Alert

Last night I noted the first direct link to an "exe" file in months. Tonight, I am noting one of the standard (human engineering) tricks. It starts with some basic nonsense about wire transfers and then says go to a website for more information.

Here is an example from one of the spams:


FEDERAL RESERVE BANK

Important:
You're getting this letter in connection with new directions issued by U.S. Treasury Department. The directions concern U.S. Federal Wire online payments.

On January 21, 2009 a large-scaled phishing attack started and has been still lasting. A great number of banks and credit unions is affected by this attack and quantity of illegal wire transfers has reached an extremely high level.

U.S. Treasury Department, Federal Reserve and Federal Deposit Insurance Corporation (FDIC) in common worked out a complex of immediate actions for the highest possible reduction of fraudulent operations. We regret to inform you that definite restrictions will be applied to all Federal Wire transfers from January 26 till February 6.

Here you can get more detailed information regarding the affected banks and U.S. Treasury Department restrictions:

http : \/\/ fedwire.ustreasdept.net/********/wire/


Federal Reserve Bank System Administration

Saturday, January 10, 2009

The tricks are back.

Yestereday I did not check the incoming mail. Today I note a return to alot of the old tricks. Namely, hijacking websites running php. In addition, a few peppered spam did not have the http:// with URL.

tc

Thursday, January 8, 2009

Mining the bounce may produce upto 30+% more

Since the spammer are not throwing anything new, I decided to try a test. I took several hundred bounced emails and looked for a URL (http://etc). After the usual clean up, I got about 75 domain names. Of that, 50 names were already in my database. This means that possibly 30+% are have not made it to my filters. I say 30+% because a few of the domain names look legit.

I should note that I have additional sets of old spam, some going back 4 years.

tc

Tuesday, January 6, 2009

Back to the oldies

The return of spammers might be marked with the oldie, but goodie.

It is:
"Look out for spam, follow this URL for more information."

Of course, this URL belongs to a spammer.

tc

Saturday, January 3, 2009

w3.org trap

Well aware of this issue, it just went past me recently. Since I am mining for the URL payload, sometimes the software gets confused (or should i say the operator gets confused) and errors happen. In this case, the URL is http://www.w3.org/. Since a few spammers use this in the HTML header, it is easy to get it in the blacklist of payoff domains. That is, if you forget to delete it when you see it. (Which I did)

tc