Wednesday, March 25, 2009

Not an original scam, but bold

This scam, based on the infamous Nigerian scam, is worth noting. Stated in the email as follows:
I have been waiting for you to contact me for your Bank Draft worth US$600,000.00 SIX HUNDRED THOUSAND U.S DOLLARS), being compensation fund for 150 scam victims, but I did not hear from you all this while.
Yes, I saved a copy of this beauty.

tc

Wednesday, March 18, 2009

Rate blip

This may be nothing, but between 4pm and 6pm local time, the local delivery rate dropped. Whether this was a gateway issue, or a system reset, or an anomaly is difficult to way, but I have seen these blips before.

To give it some numbers the deliveries were:
448 - 418 - 164 - 366 - 514
number before that are unavailable, and numbers after that have not arrived.

tc

Monday, March 16, 2009

Chinese Domains at 20%

Currently, spammers are sending a majority of the payload in chinese domains. I estimate only about 10%, or so, being ".com". Of the 50k or so domains I have recorded, 12k are chinese. In addition, it appears the spammers may have thought that ".com" names require real english words. But for chinese domains, it appears that random letters will do just fine.

tc

Wednesday, March 11, 2009

More social network spam

Earlier this week they hit classmates, today they hit facebook. Someone will fall for it.

tc

Sunday, February 1, 2009

Some Magic Numbers

I've estimated 8-10 new domains per hour during "idle spam time", that being the time when spammer are apparently not actively sending spam, but letting the bots do the work.

Given 24 hours in a day and 365 days in a year, that is 8760 hours per year.

This means about 87,600 but my numbers indicate something much lower - about 15,000 per year.

More stats needed.

Even so, it mean between $150,000 and $876,000 per year just on domain names.

tc

Monday, January 26, 2009

Trojan Alert

Last night I noted the first direct link to an "exe" file in months. Tonight, I am noting one of the standard (human engineering) tricks. It starts with some basic nonsense about wire transfers and then says go to a website for more information.

Here is an example from one of the spams:


FEDERAL RESERVE BANK

Important:
You're getting this letter in connection with new directions issued by U.S. Treasury Department. The directions concern U.S. Federal Wire online payments.

On January 21, 2009 a large-scaled phishing attack started and has been still lasting. A great number of banks and credit unions is affected by this attack and quantity of illegal wire transfers has reached an extremely high level.

U.S. Treasury Department, Federal Reserve and Federal Deposit Insurance Corporation (FDIC) in common worked out a complex of immediate actions for the highest possible reduction of fraudulent operations. We regret to inform you that definite restrictions will be applied to all Federal Wire transfers from January 26 till February 6.

Here you can get more detailed information regarding the affected banks and U.S. Treasury Department restrictions:

http : \/\/ fedwire.ustreasdept.net/********/wire/


Federal Reserve Bank System Administration

Saturday, January 10, 2009

The tricks are back.

Yestereday I did not check the incoming mail. Today I note a return to alot of the old tricks. Namely, hijacking websites running php. In addition, a few peppered spam did not have the http:// with URL.

tc