Archive for February, 2008

Spammer uses Flickr to host spam images

February 18th, 2008 by Rebecca Herson | Category: Email Security, Spam Favorites | Leave a comment »

The original image-based spam embedded images in email messages, however it’s even simpler, and easier to fool anti-spam engines, to embed references to images in the HTML code of a message. What this means is that the source code of the message will pull an image from a remote server, assuming the reader is connected [...]

Russian Postcard Spam is Back

February 17th, 2008 by Rebecca Herson | Category: Email Security | 1 Comment »

A new, massive outbreak of Russian postcard spam is underway, similar to the previous outbreak I wrote about a few weeks back. We know why spammers were sending Valentines’ spam this past week, but why Russian postcards? I checked with one of our resident experts, and it turns out that in less than a week, [...]

Valentines Malware with Lovely Artwork

February 12th, 2008 by Rebecca Herson | Category: Data & Research, Email Security | Leave a comment »

It was a given that malware writers would roll out a new Valentine’s Day campaign, with the holiday of love just two days away. But who knew that they could be such creative artists with the pictures they choose to deliver their malicious software? OK, they probably stole the valentine’s pics from a legitimate site, [...]

Fraudsters Already Working on Microsoft/Yahoo Acquisition

February 10th, 2008 by Rebecca Herson | Category: Miscellaneous | Leave a comment »

Here’s a cute one our Detection Center just sent over - a traditional 419 scam in the guise of a lottery prize, sent from a scammer pretending to be… none other than Yahoo/MSN. Haven’t they heard that the deal isn’t finalized yet?!

Google redirects to porn malware site

February 4th, 2008 by Rebecca Herson | Category: Email Security | Leave a comment »

A message promising Paris Hilton topless includes a hyperlink that appears innocent - the words “download it now” link to a page that begins http://www.google.com/pagead/iclk?sa=l&ai=trailhead&num=69803&adurl=http://…
[this link won't work since I've truncated it on purpose].

The site automatically downloads a Trojan malware called “trailer.exe”. Nothing new under the sun….

PDF spam back for a brief fling

February 4th, 2008 by Rebecca Herson | Category: Spam Favorites | Leave a comment »

Just in case you thought PDF spam was done for, spammers have brought it back within the last few weeks. Here is a sample Commtouch’s detection center brought to my attention:

and here’s a screenshot of the attached PDF:

What I love is the Bayesian poisoning text at the bottom of the PDF, to try to fool [...]