The images are sill coming... the same 7 images
tc
Tuesday, April 28, 2009
Monday, April 27, 2009
Image Downdraft
Those images being sent as half of all spam over the weekend is now winding down. Tuesday am we will likely see the last of them. At this point they continue to find new domains by web-shills.
tc
tc
Saturday, April 25, 2009
Stuborn or Stupid: Us or them?
This morning I check the incoming mail. 1140 of 2020 (56.4%) was of previously known images from spammers. The signature file identifying these images only contains 7 signatures.
tc
tc
Spiked Email
blogspot report some blogs making into the spam pile that should not have. I am also reporting that they are using legitimate websites to spike incoming mail. These spikes turn out to be the only URL or payload. Apparently, someone besides me is on to them.
Even though this is old, it is apparent what is going on:
http://buzz.blogger.com/2008/08/spam-fridays.html
tc
Even though this is old, it is apparent what is going on:
http://buzz.blogger.com/2008/08/spam-fridays.html
tc
Friday, April 24, 2009
Spam PNG Crashes with known SPAM payload
As hard as it was for me to image, it happened. I noticed a very high filter trapping number. 75% of the email was being trapped and deleted. It should have gone down, but it did not. A review of the logs indicated that it was likely another domain marked incorrectly. As such, I decide to download by hand and then review it.
To my shock, the match was a line from a base64 attachment. I then looked in the email itself. It had a spoofed email address, a spoofed email header, no text payload at all (no href, www, or email). It did have an attachment. I check the attachment header against known spam payload headers, it was on my list of known spam images.
The offending payload domain was xf.cz, which turns out to be a free-web-shill for webzdarma.cz, which offers free webpages/websites.
My job is getting easier daily.
tc
To my shock, the match was a line from a base64 attachment. I then looked in the email itself. It had a spoofed email address, a spoofed email header, no text payload at all (no href, www, or email). It did have an attachment. I check the attachment header against known spam payload headers, it was on my list of known spam images.
The offending payload domain was xf.cz, which turns out to be a free-web-shill for webzdarma.cz, which offers free webpages/websites.
My job is getting easier daily.
tc
Thursday, April 23, 2009
Cleaned up at Interia.pl
It appears that spammers were found on interia.pl. The spam slowed drastically Weds morning, then ramped down throughout the day. It is a trickle now with less than 5 per hour being generated.
In the meantime, the incoming mail was swamped with previously known PNG images. I think the domain being something like 123123.com.
They also found another sling at shac.pdx.edu/redirect.php
tc
In the meantime, the incoming mail was swamped with previously known PNG images. I think the domain being something like 123123.com.
They also found another sling at shac.pdx.edu/redirect.php
tc
Wednesday, April 15, 2009
Another payload slinger
In past spammers have used the cgi from various commerical website to redirect the payload. Today is another example with log.go.com
http ://log.go.com/log?srvc=wczl&goto=http: //idknxn.konpafus.cn
I should note this start over the weekend.
tc
http ://log.go.com/log?srvc=wczl&goto=http: //idknxn.konpafus.cn
I should note this start over the weekend.
tc
Subscribe to:
Posts (Atom)