You should know when a website is having problem, financial or otherwise, the spammers will look for weak spots. Off and on for three (3) weeks they have been using groups.yahoo.com as a redirection point. Sometimes being bold enough to to advertise their wares on the main webpage. Bold indeed.
tc
Sunday, May 24, 2009
Tuesday, April 28, 2009
Monday, April 27, 2009
Image Downdraft
Those images being sent as half of all spam over the weekend is now winding down. Tuesday am we will likely see the last of them. At this point they continue to find new domains by web-shills.
tc
tc
Saturday, April 25, 2009
Stuborn or Stupid: Us or them?
This morning I check the incoming mail. 1140 of 2020 (56.4%) was of previously known images from spammers. The signature file identifying these images only contains 7 signatures.
tc
tc
Spiked Email
blogspot report some blogs making into the spam pile that should not have. I am also reporting that they are using legitimate websites to spike incoming mail. These spikes turn out to be the only URL or payload. Apparently, someone besides me is on to them.
Even though this is old, it is apparent what is going on:
http://buzz.blogger.com/2008/08/spam-fridays.html
tc
Even though this is old, it is apparent what is going on:
http://buzz.blogger.com/2008/08/spam-fridays.html
tc
Friday, April 24, 2009
Spam PNG Crashes with known SPAM payload
As hard as it was for me to image, it happened. I noticed a very high filter trapping number. 75% of the email was being trapped and deleted. It should have gone down, but it did not. A review of the logs indicated that it was likely another domain marked incorrectly. As such, I decide to download by hand and then review it.
To my shock, the match was a line from a base64 attachment. I then looked in the email itself. It had a spoofed email address, a spoofed email header, no text payload at all (no href, www, or email). It did have an attachment. I check the attachment header against known spam payload headers, it was on my list of known spam images.
The offending payload domain was xf.cz, which turns out to be a free-web-shill for webzdarma.cz, which offers free webpages/websites.
My job is getting easier daily.
tc
To my shock, the match was a line from a base64 attachment. I then looked in the email itself. It had a spoofed email address, a spoofed email header, no text payload at all (no href, www, or email). It did have an attachment. I check the attachment header against known spam payload headers, it was on my list of known spam images.
The offending payload domain was xf.cz, which turns out to be a free-web-shill for webzdarma.cz, which offers free webpages/websites.
My job is getting easier daily.
tc
Thursday, April 23, 2009
Cleaned up at Interia.pl
It appears that spammers were found on interia.pl. The spam slowed drastically Weds morning, then ramped down throughout the day. It is a trickle now with less than 5 per hour being generated.
In the meantime, the incoming mail was swamped with previously known PNG images. I think the domain being something like 123123.com.
They also found another sling at shac.pdx.edu/redirect.php
tc
In the meantime, the incoming mail was swamped with previously known PNG images. I think the domain being something like 123123.com.
They also found another sling at shac.pdx.edu/redirect.php
tc
Subscribe to:
Posts (Atom)