Filtering using previous tags is up from approximately 1/2 to 3/4 being filtered out. Meaning either the spammers have a fixed number to deal with or some spammers are not sending right now. Notable the .cn domains have been lacking since the Olympics began.
tc
Saturday, August 16, 2008
Monday, August 11, 2008
creative non-sense
Today someone decide to hide the letter of their payload in a HTML table. I predicite failure on their end. I give it 3 weeks at most.
Another spammer decided the person receiving the spam should remove some stars, such as:
http://sa*****vemake.com Remove all the *****
I'm sure this will be equally successful.
tc
Another spammer decided the person receiving the spam should remove some stars, such as:
http://sa*****vemake.com Remove all the *****
I'm sure this will be equally successful.
tc
Tuesday, July 29, 2008
Swish (flash) stored on images sites really spam
This blew my mind.
img137.imageshack.us/img137/5418/30096901zt5.swf
tc
img137.imageshack.us/img137/5418/30096901zt5.swf
tc
Fake News on the horizon
Slight twist on an oldie. They are using the following domains to send out fake news leads like:
"The FBI can watch you on facebook"
Once you get there you can download the supposed storied. Of course, it is a trojan horse.
BestValueNews.com
CompanyNewsNetwork.com
FedNewsWorld.com
GoodNewsGames.com
Here are a few more
StockLowNews.com
ToplessDailyNews.com
ToplessNewsRadio.com
WapDailyNews.com
SmartNewsRadio.com
tc
"The FBI can watch you on facebook"
Once you get there you can download the supposed storied. Of course, it is a trojan horse.
BestValueNews.com
CompanyNewsNetwork.com
FedNewsWorld.com
GoodNewsGames.com
Here are a few more
StockLowNews.com
ToplessDailyNews.com
ToplessNewsRadio.com
WapDailyNews.com
SmartNewsRadio.com
tc
Tuesday, July 22, 2008
Late Notes
I did not note a few weeks ago they seemed to be buying and using .eu domains like crazy. They have since just stopped. Dead cold. At very least, a dry tickle.
The latest phishbait includes msvideoc.exe
Before that they seemed to be dumping IP numbers. After that they went to zero on that scheme. That said, they have started dumping again.
Currently, they are dumping .cn (china) domains like crazy. Perhaps, china is cracking down on them.
TC
The latest phishbait includes msvideoc.exe
Before that they seemed to be dumping IP numbers. After that they went to zero on that scheme. That said, they have started dumping again.
Currently, they are dumping .cn (china) domains like crazy. Perhaps, china is cracking down on them.
TC
Friday, June 20, 2008
Increase in hijacked sites.
There has been a large increase in hijacked websites, especially those that have the video.exe and video1.exe. The same goes for redirected websites and hijacked php websites.
Subscribe to:
Posts (Atom)