Monday, January 26, 2009

Trojan Alert

Last night I noted the first direct link to an "exe" file in months. Tonight, I am noting one of the standard (human engineering) tricks. It starts with some basic nonsense about wire transfers and then says go to a website for more information.

Here is an example from one of the spams:


FEDERAL RESERVE BANK

Important:
You're getting this letter in connection with new directions issued by U.S. Treasury Department. The directions concern U.S. Federal Wire online payments.

On January 21, 2009 a large-scaled phishing attack started and has been still lasting. A great number of banks and credit unions is affected by this attack and quantity of illegal wire transfers has reached an extremely high level.

U.S. Treasury Department, Federal Reserve and Federal Deposit Insurance Corporation (FDIC) in common worked out a complex of immediate actions for the highest possible reduction of fraudulent operations. We regret to inform you that definite restrictions will be applied to all Federal Wire transfers from January 26 till February 6.

Here you can get more detailed information regarding the affected banks and U.S. Treasury Department restrictions:

http : \/\/ fedwire.ustreasdept.net/********/wire/


Federal Reserve Bank System Administration

Saturday, January 10, 2009

The tricks are back.

Yestereday I did not check the incoming mail. Today I note a return to alot of the old tricks. Namely, hijacking websites running php. In addition, a few peppered spam did not have the http:// with URL.

tc

Thursday, January 8, 2009

Mining the bounce may produce upto 30+% more

Since the spammer are not throwing anything new, I decided to try a test. I took several hundred bounced emails and looked for a URL (http://etc). After the usual clean up, I got about 75 domain names. Of that, 50 names were already in my database. This means that possibly 30+% are have not made it to my filters. I say 30+% because a few of the domain names look legit.

I should note that I have additional sets of old spam, some going back 4 years.

tc

Tuesday, January 6, 2009

Back to the oldies

The return of spammers might be marked with the oldie, but goodie.

It is:
"Look out for spam, follow this URL for more information."

Of course, this URL belongs to a spammer.

tc

Saturday, January 3, 2009

w3.org trap

Well aware of this issue, it just went past me recently. Since I am mining for the URL payload, sometimes the software gets confused (or should i say the operator gets confused) and errors happen. In this case, the URL is http://www.w3.org/. Since a few spammers use this in the HTML header, it is easy to get it in the blacklist of payoff domains. That is, if you forget to delete it when you see it. (Which I did)

tc

Thursday, December 25, 2008

Unmanned Spam?

The mail run at 12:00 (noon) and 14:00 had a 100% trapping, indicating an error in the first filter. The sole word "com" had made it in. The, perhaps, unseen enlightenment is the "100% trapping". "com" was in 100% of the mail. That is to say, which "com"? My domain, or their spam? If so, can I do something with this. If so, it is not clear.

21:18 - Noting: the last two mailruns are of low volume (161 & 170)

tc

Wednesday, December 17, 2008

Small correction

While the volume is large, it appears the spammers are working through their stockpile of old domainnames. Maybe they are on vaction.

tc