Sunday, January 24, 2010

Spammers abandon China?

Hardly. It's worth noting that the use of chinese domains has fallen off. Dot ru (.ru) has taken its place. Yipe!

Is this related to google's threat to leave China? We'll see.

tc

Wednesday, October 14, 2009

Bogus security update

The latest round of spam is a bogus security update. Just for good measure they take down your DNS servers. No doubt, this is intended to cause confusion in the ranks of large institutions. The sample below is just one of many similar spams.

tc




Attention!

On October 16, 2009 server upgrade will take place. Due to this the system may be offline for approximately half an hour. The changes will concern security, reliability and performance of mail service and the system as a whole. For compatibility of your browsers and mail clients with upgraded server software you should run SSl certificates update procedure. This procedure is quite simple. All you have to do is just to click the link provided, to save the patch file and then to run it from your computer location. That's all.

http://updates.YOURDOMAINNAMEHERE.com.secure.admindatacenter.com/mail/id=741248762-harjaicv@AGAIN.com-patch55129.exe

Thank you in advance for your attention to this matter and sorry for possible inconveniences.

System Administrator

Saturday, October 3, 2009

Domain names of the day

the.last.version.norton-antivirus.sk

ccbfgsafaq.tk

Bold or Desperate

If I had read the rendered html version is would look like this:


You have just received for your computer the best antivirus from someone who cares about you...

Just click here
to receive your version norton !

Thank you for using www.norton.com services !!!

Please take this opportunity to take your ultimatum version of norton antivirus

Of course, click here would be our nafarious link. OUCH!! (an icon!!)

http://the.last.version.norton-antivirus.sk/icons/norton.exe


tc

Friday, October 2, 2009

ASCII Art and eee




ee ee ee ee ee ee eeeee ee ee eeeee ee ee ee eeeee eeeeee eeeee ee ee
ee ee ee ee ee ee ee ee ee ee ee ee eee ee ee ee ee ee ee ee eee eee
ee e ee ee e ee ee e ee ee ee ee ee ee ee ee ee ee ee ee ee ee ee ee e e ee
ee eee ee ee eee ee ee eee ee eeeeee eeeeeee eeeee ee eeeeeee eeeee ee ee ee ee e ee
eeee eeee eeee eeee eeee eeee ee ee ee ee ee ee ee ee ee ee ee ee ee
eee eee eee eee eee eee ee ee ee ee ee ee ee ee ee ee ee ee ee ee ee ee
e e e e e e ee eeeee ee eeeee ee ee eeeee ee eeeeee eeeee ee ee





If you don't see it, it is www.948148.com
It was also in 3px font-size.

Monday, September 28, 2009

Smoke, but no gun

Often we here the phrase "smoking gun". In that, we usually mean, "indisputable evidence ". But unless delve deeper into this smoke, the exact meaning is unclear. To be clear, the following HTML fragments provides some clues, but no real evidence.

<a href=3D"http://{oemredir}">
<a href=3D"http://{repredir}">


What may not be clear is that "oemredir" is a shorthand for OEM (Original Equipment Manufacture) RED (redirect), and "repredir" is a shorthand for REP (REPresentative) RED (redirect).

So, yes, the spam is about computer software, and they do use generic text for the spam-ad. A third party is possibley involved sending the spam. The question is the "shorthand" indicates what? Is it important or just a red herring.

Given the odds and frequency of these types of errors, this is significant, but not important.

tc

Wednesday, September 23, 2009

Always have a spammer plan

Spammer has over the last two (2) days latched on to google docs as a webshill page. Luckily, they use 16 digit numbers to ID the page. The sad part is they are generating thousands of pages.

tc