Archive for June, 2008
Spam in Chinese is problematic for traditional content-filtering anti-spam engines for several reasons:
Chinese characters are “double-byte”, as opposed to “single-byte” like non-Asian languages. The second byte is due to the fact that one byte isn’t enough to transmit all the necessary information since the alphabet is so much larger than western languages like, for example, [...]
Commtouch detection team informed me that a new blended threat outbreak of Chinese Earthquake messages began earlier today, with a similar modus operandi to the previous outbreak, the main difference being that the URL hyperlinks within the messages are to zombie IP addresses (the X’s in the sample below), rather than fast flux domains in [...]
For some people, hearing about China digging itself out of one of the worst earthquakes in recent memory inspires them to do good works, donate money, join the Peace Corps…. For spammers it is merely inspiration for the next wave of social engineering to attempt to recruit a new army of zombies. Building on human [...]
I just returned from Madrid, where I represented Commtouch at 3Com’s TechConnect EMEA event, which was a great time. Together with 3Com’s Sean Newman, Product Manager, I presented the new messaging security in 3Com’s X-Family Unified Security Platforms to eager attendees comprised of their extended sales force. People are excited about the new GlobalView Mail [...]
I guess I should be happy spammers are still sending pump & dump spam, since of course blocking this garbage provides Commtouch’s bread & butter, but still, as a human being (not a marketer for an anti-spam company), sometimes I just throw up my hands and ask “WHY??!!!!!” I mean, do people really fall for [...]
Trying to log in to your Chinese Gmail or Yahoo! webmail? Check carefully…. over the past few days phishers have spread a broad attack trying to entice users to give up their credentials to a fake login page for Google and Yahoo-reminiscent addresses, with a .cn (China) domain. Examples include (and there are dozens of [...]
Commtouch detection team identified a new email-borne malware outbreak yesterday, another in the “love” themed attacks. It is a blended threat, with simple love-oriented subjects, and within the body of the email message a hyperlink to a site that downloads a malware file - a Storm worm variant known as Zhelatin or Nuwar. Our lab [...]
What do you get when a scammer scams a scammer? I guess you could call that scam squared. Perhaps there used to be honor among thieves, but not anymore. Check out this spam message targeted at, no, not unsuspecting purchasers of fake meds, but at those people who are selling the stuff!
Now, it’s not so [...]
Blogspot has been a popular hosting site for spammers, and even malware distributors, but Arik from the detection team informs me that we are now starting to see outbreaks using hyperlinks to a different, less popular blog site, known as blogdrive.
This particular outbreak uses misspelled pornographic subject lines of around four words each; it seems [...]