citibanksecurity.com
citicardupdate.com
citisecurity.com
All these domains are registered to:
Pan Wei wei
IN Bejing, China, of course.
tc
Monday, July 27, 2009
Tuesday, July 21, 2009
killlabs.com spam
The newest, and another oldie, Spam from the spammer offering free anti-spam, anti-torjan-horse, and anti-virus software.
tc
tc
Wednesday, July 15, 2009
Increased Volume
There's been a large increase in volume of spam. Almost all can be attributed to holes at Yahoo.com and some URL shortening websites, like path.to or tinyurl.com (not that either of these are involved).
tc
tc
Tuesday, July 7, 2009
Fake News Stories and blog
An oldie, but a goodie.
thebusinessnews.org
readthetimes.orgthebusinessnews.org
theonlinenews.org
I'm sure more to come.
tc
Tuesday, June 23, 2009
A Bit of Metrics
Overnight
1422 (100%) email received
760 (~50%) emails had previously seen spam domain
319 (~20%) had blog domains as spam (mostly yahoo & goggle)
441 (~30%) remained
1 other blog
75 trojan horse (ecard.exe) (NOTE: trojan horse have been few in the last 6 months.)
218 chinese domains
4 russian domains
143 (~10%) remained
78 easily id'd as spam
65 (~4%) remaining
44 tagged as character-set "koi8"
21 (~1.5%) remaining
20 tagged as "other" character-sets, direct email solicitation, dead spam, & phone numbers
1 (0.4%) remaining
1 (0.07%) legit email
What may not be apparent is the 4% labeled as "easily id'd as spam" is the only real email that got through and was readable. That is to say, it was in english and it had a URL to click on. It could be said that one had to read the email to figure out it was spam, but the domain name 99 times out of 100 makes not sense - names like rightswell.com and testfoxonline.com.
tc
1422 (100%) email received
760 (~50%) emails had previously seen spam domain
319 (~20%) had blog domains as spam (mostly yahoo & goggle)
441 (~30%) remained
1 other blog
75 trojan horse (ecard.exe) (NOTE: trojan horse have been few in the last 6 months.)
218 chinese domains
4 russian domains
143 (~10%) remained
78 easily id'd as spam
65 (~4%) remaining
44 tagged as character-set "koi8"
21 (~1.5%) remaining
20 tagged as "other" character-sets, direct email solicitation, dead spam, & phone numbers
1 (0.4%) remaining
1 (0.07%) legit email
What may not be apparent is the 4% labeled as "easily id'd as spam" is the only real email that got through and was readable. That is to say, it was in english and it had a URL to click on. It could be said that one had to read the email to figure out it was spam, but the domain name 99 times out of 100 makes not sense - names like rightswell.com and testfoxonline.com.
tc
Thursday, June 18, 2009
What do these domains have in common?
In some phish bait for Chase bank this was the real domains people were sent to. The question is why the thin characters? Why are the being use?
il1hh1l.net
il1ih1i.com
jilf11l.com
jilf11l.net
jilf1f1.com
jilf1fl.com
tc
il1hh1l.net
il1ih1i.com
jilf11l.com
jilf11l.net
jilf1f1.com
jilf1fl.com
tc
Wednesday, June 17, 2009
Volume down, but attack continues
groups.yahoo.com, profiles.yahoo.com & googlegroups.com all continue to be used as shills for the spammers. While the total volume of spam is down, the percentage of these shills remains constant, about one-third (1/3).
tc
tc
Subscribe to:
Posts (Atom)