Saturday, August 16, 2008

Filter Working Well

Filtering using previous tags is up from approximately 1/2 to 3/4 being filtered out. Meaning either the spammers have a fixed number to deal with or some spammers are not sending right now. Notable the .cn domains have been lacking since the Olympics began.

tc

Monday, August 11, 2008

creative non-sense

Today someone decide to hide the letter of their payload in a HTML table. I predicite failure on their end. I give it 3 weeks at most.

Another spammer decided the person receiving the spam should remove some stars, such as:

http://sa*****vemake.com Remove all the *****

I'm sure this will be equally successful.

tc

Tuesday, July 29, 2008

Swish (flash) stored on images sites really spam

This blew my mind.

img137.imageshack.us/img137/5418/30096901zt5.swf

tc

Fake News on the horizon

Slight twist on an oldie. They are using the following domains to send out fake news leads like:

"The FBI can watch you on facebook"

Once you get there you can download the supposed storied. Of course, it is a trojan horse.

BestValueNews.com
CompanyNewsNetwork.com
FedNewsWorld.com
GoodNewsGames.com

Here are a few more
StockLowNews.com
ToplessDailyNews.com
ToplessNewsRadio.com
WapDailyNews.com
SmartNewsRadio.com

tc

An Anynomizer becomes a shill

I guess it was always out there.

hiderefer.com/ohyZAlil.htm

tc

Tuesday, July 22, 2008

Late Notes

I did not note a few weeks ago they seemed to be buying and using .eu domains like crazy. They have since just stopped. Dead cold. At very least, a dry tickle.

The latest phishbait includes msvideoc.exe

Before that they seemed to be dumping IP numbers. After that they went to zero on that scheme. That said, they have started dumping again.

Currently, they are dumping .cn (china) domains like crazy. Perhaps, china is cracking down on them.

TC

Friday, June 20, 2008

Increase in hijacked sites.

There has been a large increase in hijacked websites, especially those that have the video.exe and video1.exe. The same goes for redirected websites and hijacked php websites.