Archive for June, 2008

Chinese spam adopts a vertical strategy

June 25th, 2008 by Rebecca Herson | Category: Spam Favorites | Leave a comment »

Spam in Chinese is problematic for traditional content-filtering anti-spam engines for several reasons:

Chinese characters are “double-byte”, as opposed to “single-byte” like non-Asian languages. The second byte is due to the fact that one byte isn’t enough to transmit all the necessary information since the alphabet is so much larger than western languages like, for example, [...]

More Chinese Earthquake Malware Blended Threat Messages

June 23rd, 2008 by Rebecca Herson | Category: Email Security, Zombies/Botnets | 1 Comment »

Commtouch detection team informed me that a new blended threat outbreak of Chinese Earthquake messages began earlier today, with a similar modus operandi to the previous outbreak, the main difference being that the URL hyperlinks within the messages are to zombie IP addresses (the X’s in the sample below), rather than fast flux domains in [...]

Malware earthquake hoax

June 19th, 2008 by Rebecca Herson | Category: Email Security, Zombies/Botnets | 1 Comment »

For some people, hearing about China digging itself out of one of the worst earthquakes in recent memory inspires them to do good works, donate money, join the Peace Corps…. For spammers it is merely inspiration for the next wave of social engineering to attempt to recruit a new army of zombies. Building on human [...]

3Com TechConnect EMEA - Madrid

I just returned from Madrid, where I represented Commtouch at 3Com’s TechConnect EMEA event, which was a great time. Together with 3Com’s Sean Newman, Product Manager, I presented the new messaging security in 3Com’s X-Family Unified Security Platforms to eager attendees comprised of their extended sales force. People are excited about the new GlobalView Mail [...]

Why Won’t Stock Pump & Dump Just Go Away

I guess I should be happy spammers are still sending pump & dump spam, since of course blocking this garbage provides Commtouch’s bread & butter, but still, as a human being (not a marketer for an anti-spam company), sometimes I just throw up my hands and ask “WHY??!!!!!” I mean, do people really fall for [...]

Fake Phishing Webmail Targets Chinese Users

Trying to log in to your Chinese Gmail or Yahoo! webmail? Check carefully…. over the past few days phishers have spread a broad attack trying to entice users to give up their credentials to a fake login page for Google and Yahoo-reminiscent addresses, with a .cn (China) domain. Examples include (and there are dozens of [...]

New Love Malware Outbreak

Commtouch detection team identified a new email-borne malware outbreak yesterday, another in the “love” themed attacks. It is a blended threat, with simple love-oriented subjects, and within the body of the email message a hyperlink to a site that downloads a malware file - a Storm worm variant known as Zhelatin or Nuwar. Our lab [...]

Scam Squared

June 2nd, 2008 by Rebecca Herson | Category: Spam Favorites | Leave a comment »

What do you get when a scammer scams a scammer? I guess you could call that scam squared. Perhaps there used to be honor among thieves, but not anymore. Check out this spam message targeted at, no, not unsuspecting purchasers of fake meds, but at those people who are selling the stuff!

Now, it’s not so [...]

Drive, Not Spot

Blogspot has been a popular hosting site for spammers, and even malware distributors, but Arik from the detection team informs me that we are now starting to see outbreaks using hyperlinks to a different, less popular blog site, known as blogdrive.
This particular outbreak uses misspelled pornographic subject lines of around four words each; it seems [...]